Lockton, an insurance brokerage firm that provides employee benefit services to its clients, has notified certain individuals that it discovered suspicious activity on one of its computers on November 20, 2024. After starting an investigation and bringing in outside cybersecurity experts, Lockton determined that an unauthorized party had gained access to a single employee’s account and computer within Lockton’s network, and had obtained certain files from that account. This is a case of hacking or system intrusion rather than a broader network-wide compromise, but Lockton still conducted a detailed review of the accessed files to identify whose personal information was contained within them.
Based on that review, Lockton determined that your name, along with certain other personal information, was included in the affected files. The notification letter does not spell out the exact category of that additional information in the copy provided to us, so if you’re unsure what was involved, it’s worth calling the number listed in your specific letter to ask directly.
What information was exposed?
- Full name
- Additional personal information tied to you in the accessed files (the specific type is not detailed in the letter text available to us)
As a precaution, Lockton is offering a complimentary 24-month membership to Experian IdentityWorksSM, which includes credit monitoring, identity restoration assistance, and $1 million in identity theft insurance. To activate it, enroll by June 30, 2025 at https://www.experianidworks.com/credit using the activation code included in your letter — the code stops working after that date. You can also reach Experian’s customer care team by phone before June 30, 2025 and provide your engagement number as proof of eligibility.
What should you do now?
- Enroll in the free Experian IdentityWorksSM membership before the June 30, 2025 deadline using the activation code in your letter.
- Review your credit card and bank statements regularly for any charges or activity you don’t recognize.
- Request your free annual credit reports at www.annualcreditreport.com and check them for accounts you didn’t open.
- Consider placing a free security freeze on your credit file with Equifax, Experian, and TransUnion, which makes it harder for anyone to open new accounts in your name.
- You may also place a fraud alert with any one of the three credit bureaus — they’re required to notify the other two.
- For ongoing peace of mind, consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere.
- If you notice signs of identity theft, report it to the FTC at www.ftc.gov/bcp/edu/microsites/idtheft/ or by calling 1-877-438-4338.
If similar cases interest you, you can read about another recent incident involving a data breach at Idealab, which followed a comparable notification pattern.