Aon disclosed on February 28, 2022, that it had identified a cyber incident affecting a limited number of systems three days earlier. The insurance broker said it was investigating and that, based on information available at the time, the incident had not significantly affected operations and was not expected to have a material impact. That was a preliminary assessment, not a current update.
What happened in Aon’s 2022 cyber incident?
Aon plc said it identified the incident on February 25, 2022, and that a limited number of its systems were affected. In a Form 8-K filed with the U.S. Securities and Exchange Commission on February 28, the company said it had launched an investigation and engaged third-party advisors, incident response professionals, and counsel. Aon’s February 2022 SEC filing is the primary source for those details.
Aon described the impact in the filing as preliminary: “The incident has not had a significant impact on the Company’s operations.” The company also said it did not expect a material impact based on information then available, while noting that its assessment was at an early stage.
What did Aon disclose about the impact?
The filing did not provide a count of affected systems, customers, or individuals, or quantify any data involved or financial loss. It also did not establish whether data was accessed, stolen, or exposed. The description “limited number of systems” is qualitative; it should not be read as a confirmed finding about the incident’s ultimate scope.
Recommended Free Tools
#1 Best Overall
Accordingly, the operational and financial impact statements should be understood as Aon’s view when it filed in February 2022—not as a final forensic conclusion or a guarantee about later developments.
Is this a new Aon incident?
The documented disclosure concerns an event Aon identified in February 2022. The available company filings cited here do not establish a separate 2026 incident matching the headline, so the 2022 event should not be presented as breaking news.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
Aon’s 2025 Form 10-K, filed February 13, 2026, says the company has experienced cyber incidents from time to time and describes its cybersecurity governance and response processes. It is general company-level context, not a specific update on the 2022 incident. Aon’s 2025 Form 10-K also says past incidents to date had not materially affected its strategy, operating results, or financial condition.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How does Aon describe its cybersecurity response program?
In its 2025 annual filing, Aon says its Global Emergency Operations Center triages incidents involving customer data, monitors threat intelligence and alerts, and coordinates with privacy and cybersecurity teams. The company says significant incidents are escalated to a Cyber Incident Governance Committee, which reviews them and coordinates mitigation and remediation.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #3
Aon says its controls are designed to align with the NIST Cybersecurity Framework, while cautioning that this does not mean it meets any particular technical standard at all times. It also says it maintains insurance for certain cyber or privacy losses, which may not cover every loss. These disclosures explain the company’s general program; they do not establish which processes were used in the 2022 response.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




