Cyber & AI intelligence
Wasteland.
Briefs indexed3035
Issues31
Published Mondays07:30 CT
█ Ransomware AON-TERMITE-RANSOM 2026-10-07

Aon: Termite Ransomware Leak Site Claim (Unverified)

"The Termite ransomware group has listed Aon plc, the global insurance, reinsurance and risk-management broker, on its data leak site. Threat-monitoring service Kalir Pulse detected the listing at 01:07 UTC on 7 October…"

The Termite ransomware group has listed Aon plc, the global insurance, reinsurance and risk-management broker, on its data leak site. Threat-monitoring service Kalir Pulse detected the listing at 01:07 UTC on 7 October 2026. The claim is unverified. Aon has not confirmed an incident, no regulator filing or national CERT advisory has appeared, and none of the sources available at publication include a proof-of-compromise sample, a stated data volume or a ransom deadline. We are publishing because of how large Aon is and what it holds. A brokerage of this size has client risk, financial and HR data on a very large number of corporate and public-sector clients. Kalir rates the listing high severity, with a priority score of 55.

What Happened

These facts are established:

These things are unknown: the date of intrusion, whether any systems were encrypted, whether the listing relates to Aon's corporate network or to a third party or subsidiary, and whether Termite has published samples.

The listing comes during a busy few weeks for Termite. Aggregator trackers record recent claims against wholesale mortgage lender theLender and cable-management manufacturer Sealcon (both 22 September 2026), and against petroleum transporter Crossett (26 September 2026, with an estimated attack date of 25 September). All three are U.S.-based or have major U.S. operations. The Aon claim fits a pattern of high-volume posting across unrelated sectors.

What Was Taken

Nothing has been confirmed. No source gives a data volume, a file count or a list of data categories for Aon.

Kalir's assessment is that Aon "handles large volumes of sensitive client risk, financial and HR data". Based on Aon's business model, the categories most likely to be at risk if exfiltration occurred are:

These categories are inferences from Aon's line of business, not claims Termite has made. For comparison, the Sealcon tracker profile credits Termite with 680 GB of exfiltrated data in its November 2024 Blue Yonder attack. That shows the group can take large volumes, but it says nothing about this case.

Why It Matters

The risk would reach Aon's clients. Aon's own September 2026 South Africa advisory makes this point. Jenny Jooste, Principal Broker for Cyber Solutions at Aon South Africa, warns that "a third-party incident does not necessarily mean a third-party liability". Organisations whose data is compromised at a provider may still have their own notification duties, for example under South Africa's Protection of Personal Information Act (POPIA). If the Termite claim is accurate, Aon's clients would face exactly that "single point of failure" scenario.

Broker data is valuable to attackers. A brokerage's records show which organisations carry cyber cover, their policy limits, and their security controls as disclosed during underwriting. Aon's October 2026 professional-services briefing notes that underwriting increasingly focuses on "security controls, governance, incident preparedness". The same data that helps underwriters could help an extortion crew choose targets and set ransom demands.

Termite's profile is unclear. The tracker sources disagree on the basics:

The Attack Technique

How Termite got into Aon, if it did, is unknown. No source describes initial access, dwell time or the tooling used against Aon. Reporting on Termite's recent operations points to two access patterns. Each comes from a single OTHER-tier source, so treat both as indicative rather than confirmed:

Aon's own 1 October analysis of Luna Moth (Silent Ransom Group) describes a related trend: extortion crews increasingly use impersonation and remote-access abuse rather than software exploits. That analysis concerns a different actor and should not be read as describing this incident.

What Organizations Should Do

  1. Aon clients: prepare now rather than wait for confirmation. List what risk, financial, claims and HR data you have shared with Aon. Check your contracts for breach-notification clauses, and work out what notification duties you would have (POPIA, GDPR, U.S. state laws) if data held by your broker is exposed.
  2. Expect targeted phishing that uses Aon's name. Real or not, a public leak claim invites impersonation. Warn finance, HR and risk teams about unexpected messages about Aon policies, renewals, invoices or "breach updates", and confirm any change of payment details through a known channel.
  3. Block ClickFix execution. Restrict or monitor use of the Windows Run dialog and of PowerShell started from explorer.exe. Enforce PowerShell execution policy and Constrained Language Mode for standard users. Train staff that legitimate sites never ask them to paste commands.
  4. Hunt for infostealer exposure. Watch dark-web and stealer-log feeds for corporate credentials, especially for VPN, SSO and remote access. Reset and revoke sessions for any exposed accounts, and require phishing-resistant MFA on all remote access.
  5. Detect Babuk-family behaviour. Termite uses modified Babuk code. Alert on shadow-copy deletion, mass file renaming, and bulk outbound transfers to unfamiliar cloud storage, all common to double-extortion operations.
  6. Test immutable, offline backups and an extortion playbook. Double extortion means backups solve encryption but not data leaks. Rehearse legal, regulatory and client-communication decisions before a leak deadline forces them.

Sources: Termite ransomware publishes U.S. insurance broker Aon · Kalir Brie... | Aon Professional Services - Cyber October 2026 – Professional Serv... | Aon Professional Services - When Trust Becomes the Attack Surface:... | Termite Ransomware Attack on theLender - Malware News | Sealcon Ransomware Attack by Termite (2026) Cyber Threat Intelligence | When Your IT Provider Gets Hacked, Your Balance Sheet Could Be Next | Termite Ransomware Uses ClickFix Phishing to Target US Sectors | Termite Ransomware Group Claims Attack on Petroleum Transporter Cro...