Eight major car insurance companies, including American Family Mutual Insurance, State Auto Mutual Insurance, Metromile, Liberty Mutual, Hagerty Insurance Agency, Farmers Insurance, The Hartford Insurance Group, and Infinity Insurance, have been fined a total of $14.2 million by New York state regulators following significant data breaches. The breaches exposed the personal information of over 825,000 individuals, with data such as driver’s license numbers, vehicle identification numbers, and dates of birth being compromised. Hackers exploited online quote tools that were designed to auto-populate sensitive information when provided with minimal personal details, such as names or addresses. This vulnerability allowed cybercriminals to easily harvest large volumes of personal data, which was subsequently used to file fraudulent unemployment claims during the COVID-19 pandemic. Investigations by the New York Attorney General’s office revealed that the affected insurers had inadequate cybersecurity measures, failing to implement proper data security controls and monitoring systems to detect unusual access patterns. The companies were criticized for not having multifactor authentication and for lacking comprehensive data inventories. As part of the settlement, all eight insurers are required to upgrade their cybersecurity programs, install advanced monitoring systems, and implement multifactor authentication to better protect customer data. Impacted individuals are being offered one year of credit report monitoring to mitigate potential harm from the breaches. The fines and mandated improvements are intended to set a precedent for stronger cybersecurity practices within the insurance industry. The incident follows a similar enforcement action nearly a year earlier, when Geico and Travelers were fined over $11 million for comparable security failures involving auto-filled driver’s license numbers. New York officials emphasized that consumers should not have to risk their personal information when seeking insurance quotes online. The breaches highlight the risks associated with automated data population features in web applications, especially when not properly secured. Regulators have urged all insurers to review and strengthen their cybersecurity defenses to prevent future incidents. The case underscores the growing regulatory scrutiny on data protection in the financial and insurance sectors. The exposure of sensitive data on such a large scale has raised concerns about the potential for identity theft and further fraud. The enforcement action demonstrates New York’s commitment to holding companies accountable for lapses in cybersecurity that put residents at risk. Insurers are now under pressure to not only comply with regulatory requirements but also to proactively safeguard customer information against evolving cyber threats.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
Alongside the fines, New York required the affected insurers to improve their cybersecurity programs, including comprehensive information security measures, stronger authentication, and better logging and monitoring. These remediation requirements were part of the state's enforcement action.
New York state announced $14.2 million in fines against eight car insurance companies after finding that quote pre-fill tool abuses exposed the personal information of more than 825,000 people. Investigators said the insurers lacked basic controls such as multifactor authentication, attack detection, and monitoring for suspicious request patterns.
In November, New York issued penalties against Geico and Travelers for similar abuses of insurance quote systems affecting about 120,000 New Yorkers in 2020. The action established an earlier enforcement step in the broader investigation into insurer pre-fill tool weaknesses.
During the COVID-19 pandemic, investigators said the data obtained through the quote-system abuse was used to submit fraudulent unemployment claims. This connected the insurer data exposures to downstream financial fraud.
In 2020, cybercriminals exploited auto-insurance quote pre-fill features by submitting minimal personal information to retrieve sensitive data such as driver's license numbers, VINs, and dates of birth. The activity exposed the personal information of hundreds of thousands of people, including about 120,000 New Yorkers in related cases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.