Nationwide Mutual Insurance and its Allied Insurance subsidiary began notifying consumers on Dec. 6, 2012, that attackers had broken into a network on Oct. 3 and taken personal data. The initial count was 1.1 million. State attorneys general later put it at 1.27 million. The fields included names, Social Security numbers, driver’s license numbers, birth dates, marital status, occupation, employer details and internal credit-related scores.
Much of the data belonged to people who were not customers. They had requested an insurance quote, supplied the details a quote required and never bought a policy. The company kept the records anyway.
A 2009 Patch, Unapplied In 2012
The attackers exploited a vulnerability in third-party web application hosting software. The vendor had released a critical patch in 2009. Nationwide had not applied it. The attorney general releases do not name the software, and no attribution was ever made.
The settlement’s remedies say what regulators concluded. Nationwide agreed to appoint a technology officer responsible for patch management, keep regular inventories of patches and their status, run a security program for three years with annual independent audits, and tell consumers that it retains data from people who only requested quotes.
The Quote Form As A Data-Collection Point
An auto insurance quote requires a driver’s license number and a birth date, and a good quote requires more. The form is the sector’s most efficient collector of identity data from people who owe it nothing, and this file is the first in the corpus to record what happens when that pool is breached. The same form, used deliberately by fraudsters rather than accidentally by an unpatched host, produced the driver’s license thefts filed at 21-0419 and 22-0527b.
The $5.5 million settlement, announced Aug. 9, 2017, went to 32 states and the District of Columbia. Connecticut, which led it, received $256,559. Nationwide is not a health insurer and no federal health-privacy action applied.
Compiled from the Connecticut, New Jersey and Nevada attorney general releases on the 2017 settlement and from contemporaneous reporting of the 2012 notification, listed below. The 1.27 million figure is the regulators’; 1.1 million was the company’s initial figure. The vulnerable software was not named by any source. Graded high. Corrections: corrections@forensicpost.com.
- Conn. Leads $5.5M Multistate Settlement with Nationwide Insurance Company over 2012 Data BreachConnecticut Attorney General
- Nationwide multistate settlement announcement, Aug. 9, 2017New Jersey Attorney General
- Nationwide Insurance Data Breach Affects 1.1 Million PeopleNBC News