Reported to the OR Attorney General on March 20, 2025.
OR residents may qualify for compensation. Free attorney review — no obligation, no upfront cost.
Check My Rights →Southeast Series of Lockton Companies, LLC (“Lockton”) was the subject of a data breach notification filed with the OR Attorney General. The AG filing was recorded on March 20, 2025. The breach or discovery date reported in the filing is November 20, 2024.
Southeast Series of Lockton Companies, LLC ("Lockton") operates as a prominent part of the broader Lockton organization, functioning as a specialized insurance brokerage, risk management, and employee benefits consulting firm. In the course of delivering complex commercial insurance placements, employee benefits administration, and risk advisory services, Lockton routinely collects, processes, and stores vast quantities of highly sensitive personal and financial data. This information typically includes comprehensive employee census data, detailed benefit plan elections, payroll figures, Social Security numbers, banking details for premium and claim transactions, and sensitive personal health information required for underwriting and health plan administration. Because the firm acts as an essential nexus between employers, employees, and insurance carriers, its digital environment represents an extraordinarily rich repository of personally identifiable information (PII) and protected health information (PHI). In 2025, Southeast Series of Lockton Companies, LLC ("Lockton") reported a significant data security incident to the Oregon Attorney General, joining a growing number of professional services and insurance entities targeted by sophisticated cyber threats. While the exact vector of the compromise continues to be analyzed, cyberattacks against insurance brokerages and employee benefits consultants commonly involve unauthorized access to corporate networks, sophisticated ransomware deployments, or the exploitation of vulnerabilities in third-party software and file-transfer utilities. Because insurance and brokerage networks frequently share massive data files containing sensitive client lists, underwriting files, and employee records with various carrier partners, any lapse in perimeter security or credential management can expose extensive downstream data pools to malicious threat actors. The data compromised in incidents involving insurance brokerages and employee benefits administrators typically includes full names, dates of birth, Social Security numbers, financial account details, policy numbers, and detailed compensation or medical underwriting records. The exposure of this information creates severe, immediate risks of identity theft, financial account takeover, and targeted phishing schemes. When identifiers like Social Security numbers and dates of birth are combined with employer and insurance details, bad actors can easily open fraudulent credit lines, file unauthorized tax returns, or compromise other accounts belonging to the victim. Furthermore, the inclusion of benefits and health-related data exposes victims to specialized medical fraud, where bad actors attempt to exploit healthcare coverage or access prescription benefits using stolen identities. Under state data security statutes, common law negligence principles, and federal frameworks such as the Gramm-Leach-Bliley Act (GLBA) where applicable to financial and insurance services, entities like Southeast Series of Lockton Companies, LLC ("Lockton") have an affirmative legal duty to implement and maintain robust administrative, technical, and physical safeguards to protect sensitive client and employee data. This obligation requires maintaining up-to-date encryption standards, rigorous access controls, continuous network monitoring, and comprehensive vendor risk management protocols. The occurrence of a data breach compromising sensitive PII and financial records strongly indicates a failure in these mandatory security protocols, leaving the organization vulnerable to claims of negligence, breach of implied contract, and statutory violations for failing to reasonably secure private consumer data. Receiving a data breach notification letter from Southeast Series of Lockton Companies, LLC ("Lockton") serves as a formal legal admission that your confidential data was exposed to unauthorized third parties due to inadequate security measures. Under established consumer privacy law, this notification provides affected individuals with the immediate legal standing necessary to participate in a class action lawsuit aimed at holding the company accountable. Importantly, victims do not need to show evidence of actual financial loss or fraudulent activity to join a class action; the increased risk of future identity theft and the time and expense required to mitigate that risk are recognized injuries. Our firm investigates these cases on a strict contingency fee basis, meaning you pay absolutely nothing out of pocket, and we only collect a fee if we successfully recover compensation on your behalf.
Based on the data types reported in this filing, affected individuals face the following specific risks:
Your SSN is the master key to your identity. Once exposed, criminals can open new lines of credit, take out loans, or file taxes in your name.
Combined with a name and other leaked data, date of birth helps criminals pass identity verification questions at banks and government agencies.
Under the Oregon Consumer Information Protection Act, you may have a legal claim against Southeast Series of Lockton Companies, LLC (“Lockton”) if any of the following apply:
Applicable law: This breach was reported under the Oregon Consumer Information Protection Act, which establishes your right to seek damages from Southeast Series of Lockton Companies, LLC (“Lockton”).
The hours spent responding to a data breach — canceling accounts, contacting credit bureaus, updating passwords, and investigating fraud — represent compensable economic harm in data breach litigation.
Once your SSN is exposed, protection becomes an ongoing expense. Plaintiffs in data breach settlements have recovered costs for credit freezes, identity protection subscriptions, and time spent dealing with fraudulent accounts — sometimes covering multiple years of exposure.
HIPAA violations carry civil penalties between $100 and $50,000 per violation. Where a healthcare organization's negligence led to the exposure of protected health information, class members may recover statutory damages in addition to actual losses.
Fees charged to close and reopen accounts, issue replacement cards, or dispute fraudulent transactions are recoverable in data breach litigation. So are the costs of overdrafts, late payments, and credit damage caused by unauthorized activity.
Data breach victims regularly report anxiety, loss of sleep, and ongoing fear of identity theft. These non-economic harms are cognizable injuries in data breach litigation, particularly in cases involving SSN or medical record exposure.
Note: an attorney general breach filing does not by itself establish a settlement fund, a payment amount, or a claim deadline. If an official settlement notice is later issued, rely on that notice for payment details and deadlines.
No. Under Oregon Consumer Information Protection Act and federal law, the unauthorized exposure of your personal data — regardless of whether it has been actively misused — can be sufficient grounds for a claim. The breach itself is the injury.
Nothing. The Law Office of David S. Harris handles data breach cases on contingency — you pay zero upfront and owe nothing unless compensation is recovered.
Immediately place a free credit freeze at all three bureaus (Equifax, Experian, TransUnion). A freeze blocks new accounts from being opened in your name. Then file a complaint with the FTC at IdentityTheft.gov and contact our office — SSN exposure is one of the most serious breach types.
If Southeast Series of Lockton Companies, LLC (“Lockton”) is a covered healthcare entity or business associate under HIPAA, affected patients have additional rights — including the right to an HHS complaint. These HIPAA violations also strengthen civil damages claims. Consult an attorney to understand your full remedies.
Banks may reverse fraudulent charges, but they are not obligated to compensate you for time lost, stress, or indirect damages. A class action claim against the breached company can recover those additional categories of harm.
Statutes of limitations for data breach claims vary by state but typically run 2–4 years. Depending on when you learned of the breach, you may still have time. Contact our office for a free eligibility review — there is no cost to find out.
Accepting free credit monitoring from Southeast Series of Lockton Companies, LLC (“Lockton”) does not waive your right to pursue legal action unless you signed a specific release waiving claims. In most cases, victims who accepted monitoring can still file.
Received a notification letter from Southeast Series of Lockton Companies, LLC (“Lockton”)?
Read our dedicated guide — what the letter means and exactly what to do.
If you were affected by the Southeast Series of Lockton Companies, LLC (“Lockton”) data breach, you may be entitled to compensation. Submit your information below for a free attorney review — no obligation, no upfront cost.
Source: State Attorney General filing, OR
View Official AG Filing →Southeast Series of Lockton Companies, LLC (“Lockton”) breach?
Free case review · No fee unless you win