The Termite ransomware group has listed Aon plc, the global insurance, reinsurance and risk-management broker, on its data leak site. Threat-monitoring service Kalir Pulse detected the listing at 01:07 UTC on 7 October 2026. The claim is unverified. Aon has not confirmed an incident, no regulator filing or national CERT advisory has appeared, and none of the sources available at publication include a proof-of-compromise sample, a stated data volume or a ransom deadline. We are publishing because of how large Aon is and what it holds. A brokerage of this size has client risk, financial and HR data on a very large number of corporate and public-sector clients. Kalir rates the listing high severity, with a priority score of 55.
What Happened
These facts are established:
- The listing: Kalir Pulse reports that Termite posted Aon plc to its leak site and detected the post on 7 October 2026. This is the only source that directly reports the Aon claim. All eight sources used here are third-party aggregators, vendor marketing or Aon's own thought-leadership content. None is a primary incident source.
- No confirmation from Aon: As of publication, Aon has published no breach statement. The three Aon-authored pages among our sources (published 22 September, 1 October and 3 October 2026) are cyber-risk advisory content for clients. They make no reference to any incident affecting Aon.
- Victim description: Kalir's headline calls Aon a "U.S. insurance broker", but Aon plc operates globally. Which Aon entity, region or subsidiary the listing refers to has not been established.
These things are unknown: the date of intrusion, whether any systems were encrypted, whether the listing relates to Aon's corporate network or to a third party or subsidiary, and whether Termite has published samples.
The listing comes during a busy few weeks for Termite. Aggregator trackers record recent claims against wholesale mortgage lender theLender and cable-management manufacturer Sealcon (both 22 September 2026), and against petroleum transporter Crossett (26 September 2026, with an estimated attack date of 25 September). All three are U.S.-based or have major U.S. operations. The Aon claim fits a pattern of high-volume posting across unrelated sectors.
What Was Taken
Nothing has been confirmed. No source gives a data volume, a file count or a list of data categories for Aon.
Kalir's assessment is that Aon "handles large volumes of sensitive client risk, financial and HR data". Based on Aon's business model, the categories most likely to be at risk if exfiltration occurred are:
- Client risk assessments, exposure models and underwriting submissions
- Policy, claims and placement data across the insurer and reinsurer markets
- Client financial information supplied for coverage and pricing
- Employee and client-employee HR and benefits data, given Aon's health and benefits consulting work
These categories are inferences from Aon's line of business, not claims Termite has made. For comparison, the Sealcon tracker profile credits Termite with 680 GB of exfiltrated data in its November 2024 Blue Yonder attack. That shows the group can take large volumes, but it says nothing about this case.
Why It Matters
The risk would reach Aon's clients. Aon's own September 2026 South Africa advisory makes this point. Jenny Jooste, Principal Broker for Cyber Solutions at Aon South Africa, warns that "a third-party incident does not necessarily mean a third-party liability". Organisations whose data is compromised at a provider may still have their own notification duties, for example under South Africa's Protection of Personal Information Act (POPIA). If the Termite claim is accurate, Aon's clients would face exactly that "single point of failure" scenario.
Broker data is valuable to attackers. A brokerage's records show which organisations carry cyber cover, their policy limits, and their security controls as disclosed during underwriting. Aon's October 2026 professional-services briefing notes that underwriting increasingly focuses on "security controls, governance, incident preparedness". The same data that helps underwriters could help an extortion crew choose targets and set ransom demands.
Termite's profile is unclear. The tracker sources disagree on the basics:
- Active since: the Sealcon profile says Termite was "first identified in late 2024" but has "listed 49 victims since May 2023".
- Victim count: the same page cites both 49 and 55 victims.
- Lineage and method: sources agree that Termite uses modified Babuk ransomware code and runs double extortion, meaning it steals data before encrypting.
- Most notable attack: its best-known claim is still Blue Yonder in November 2024, which disrupted downstream customers including Starbucks.
The Attack Technique
How Termite got into Aon, if it did, is unknown. No source describes initial access, dwell time or the tooling used against Aon. Reporting on Termite's recent operations points to two access patterns. Each comes from a single OTHER-tier source, so treat both as indicative rather than confirmed:
- ClickFix social engineering: Ctrl Alt Nod (21 September 2026) reports that Termite intrusions are linked to ClickFix phishing campaigns. Payment- or invoice-themed lures trick users into pasting and running commands through the Windows Run dialog, which gets past controls that inspect file downloads. The report says these campaigns delivered LummaStealer and AsyncRAT, and that they hit healthcare, education and federal contractor targets. The article carries two different dates, so its timeline should be read with caution.
- Infostealer-harvested credentials: QPulse, citing a ParanoidLab exposure report, says 33 passwords linked to Crossett, one rated critical, were circulating before that company was listed, and connects them to the "Cavalier" stealer family. That points to bought or harvested credentials as an entry route. It is not evidence about Aon.
Aon's own 1 October analysis of Luna Moth (Silent Ransom Group) describes a related trend: extortion crews increasingly use impersonation and remote-access abuse rather than software exploits. That analysis concerns a different actor and should not be read as describing this incident.
What Organizations Should Do
- Aon clients: prepare now rather than wait for confirmation. List what risk, financial, claims and HR data you have shared with Aon. Check your contracts for breach-notification clauses, and work out what notification duties you would have (POPIA, GDPR, U.S. state laws) if data held by your broker is exposed.
- Expect targeted phishing that uses Aon's name. Real or not, a public leak claim invites impersonation. Warn finance, HR and risk teams about unexpected messages about Aon policies, renewals, invoices or "breach updates", and confirm any change of payment details through a known channel.
- Block ClickFix execution. Restrict or monitor use of the Windows Run dialog and of PowerShell started from explorer.exe. Enforce PowerShell execution policy and Constrained Language Mode for standard users. Train staff that legitimate sites never ask them to paste commands.
- Hunt for infostealer exposure. Watch dark-web and stealer-log feeds for corporate credentials, especially for VPN, SSO and remote access. Reset and revoke sessions for any exposed accounts, and require phishing-resistant MFA on all remote access.
- Detect Babuk-family behaviour. Termite uses modified Babuk code. Alert on shadow-copy deletion, mass file renaming, and bulk outbound transfers to unfamiliar cloud storage, all common to double-extortion operations.
- Test immutable, offline backups and an extortion playbook. Double extortion means backups solve encryption but not data leaks. Rehearse legal, regulatory and client-communication decisions before a leak deadline forces them.
Sources: Termite ransomware publishes U.S. insurance broker Aon · Kalir Brie... | Aon Professional Services - Cyber October 2026 – Professional Serv... | Aon Professional Services - When Trust Becomes the Attack Surface:... | Termite Ransomware Attack on theLender - Malware News | Sealcon Ransomware Attack by Termite (2026) Cyber Threat Intelligence | When Your IT Provider Gets Hacked, Your Balance Sheet Could Be Next | Termite Ransomware Uses ClickFix Phishing to Target US Sectors | Termite Ransomware Group Claims Attack on Petroleum Transporter Cro...