Skip to content
Back to Blog
low severity March 20, 2025 · 4 min read

Southeast Series of Lockton Companies, LLC (“Lockton”) Data Breach Notice (Oregon Attorney General)

If you received a notice from Lockton Companies, here’s what the filing says was exposed, and what to do about it.

Southeast Series of Lockton Companies, LLC (“Lockton”) notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 20, 2025. The filing puts the incident itself on November 20, 2024.

Southeast Series of Lockton Companies, LLC (“Lockton”) Data Breach Notice (Oregon Attorney General)

The filing from Southeast Series of Lockton Companies, LLC shows that personal information belonging to 112,702 people was exposed in an incident on November 20, 2024. The company submitted its formal notice to Oregon authorities on March 20, 2025 — an interval of 120 days.

If you received a letter from Lockton, your records were part of this group. The organisation is required to notify affected individuals directly, usually by post. Absence of a letter usually means you were not included, but anyone who has moved since November 20, 2024 should contact Lockton directly to confirm their status.

What the Exposed Personal Information Actually Means for You

The record lists personal information as the category involved. In practice this almost always includes name combined with Social Security number, date of birth, address, and in many insurance-related cases driver’s license or other government identifiers. These pieces of data do not expire. Once they leave an organisation’s control they remain valuable to identity thieves for years.

With your name and SSN, someone can file fraudulent tax returns, open accounts in your name, or apply for government benefits. The combination of name, address, and date of birth makes it easier to answer knowledge-based security questions used by banks and credit card issuers. These risks are permanent because none of those identifiers can be reissued the way a compromised credit card can.

No passwords or login credentials were exposed in this incident. That is genuinely good news. You do not need to change any Lockton-related password because the filing establishes that none was taken. The threat here is identity fraud built on static personal data, not account takeover.

Why the 120-Day Gap Matters

The breach occurred on November 20, 2024 and the notice reached regulators exactly four months later. Notification timelines vary by state law and by when an internal investigation concludes. The record does not disclose when Lockton first discovered the incident, so it is impossible to know how long the data may have been accessible before they contained it. What is certain is that 112,702 individuals’ records were eventually included in the filing.

During those months the exposed information could have been used, sold, or stored by whoever gained access. The long gap between the incident date and the filing date is the single most concrete detail this notice provides.

The Limits of What This Filing Tells Us

The Oregon Attorney General’s record does not name the attack method, whether data was copied or simply viewed, or the precise fields taken for every person. It simply states that personal information was exposed. Anything beyond that is not in the official notice and cannot be asserted as fact.

Lockton, like many insurance and risk-management firms, holds detailed client files that include the exact data thieves prize for long-term fraud. The scale of 112,702 affected individuals reflects the breadth of their customer base rather than offering any judgment on how the incident occurred.

What You Can Still Control

Even though some of the exposed data cannot be changed, you retain strong ways to limit the damage. The most effective steps focus on monitoring and blocking the specific types of fraud this breach enables.

  • Place a freeze on your credit files at Equifax, Experian, and TransUnion. This stops new accounts from being opened in your name even if someone has your SSN and date of birth. It is free, reversible, and the single most powerful action available after this type of exposure.
  • Monitor your tax filings closely. Set up an IRS online account and watch for any unexpected tax returns filed under your SSN. Consider filing Form 14039, an Identity Theft Affidavit, if you see suspicious activity.
  • Review Explanation of Benefits statements from every health insurer you use. Fraudulent claims can appear months later. Catching them early prevents medical identity theft that can damage your insurance record.
  • Check your credit reports every four months on an rotating schedule so you see new activity quickly. Look specifically for accounts or inquiries you do not recognise.
  • Contact Lockton directly if you moved after November 2024 or have not received a notice but believe you should have. Their customer service can confirm whether your specific file was in the affected group.

The exposure of personal information on this scale creates a long-term risk rather than an immediate crisis. The absence of credential exposure means your existing Lockton accounts themselves are not at direct risk of takeover. Focus your attention on freezing credit access and watching for the slower-moving forms of identity fraud that typically follow this kind of incident. The letter you may or may not have received remains the clearest indicator of whether you were personally included.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed March 20, 2025
Last reviewed July 22, 2026
Affected 112702
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email