Incident & Breach Response , Managed Detection & Response (MDR) , Security Operations
Retirees Hit by Website Breach
22,000 Social Security Numbers Posted on Delaware SiteAon Consulting, Chicago, says it advertently posted the information on the procurement section of a state website along with a request for proposals it had prepared to solicit bids from insurance companies interested in providing vision benefits for retirees. The company is a consultant to the Office of Management and Budget's Division of Statewide Benefits.
The information was posted Aug. 16 and removed Aug. 20 when the personal information was discovered, Aon says.
Aon is notifying those affected, as required under the HITECH Act breach notification rule, and offering them one year's worth of free credit monitoring from Experian.
The state's Office of Management and Budget, Department of Technology and Information, Office of the Attorney General and Pension Office are overseeing the steps Aon is taking to alert those affected and to prevent future incidents.