Desk live·
ForensicPost
Insurance/Enforcement/File 24-1125b

New York Fined GEICO and Travelers $11.3 Million for Quote Tools That Leaked License Numbers

The consent orders of Nov. 25, 2024, described an open API queried 25,000 times a day and an agent portal with no multifactor authentication. The stolen numbers fed pandemic unemployment fraud. GEICO paid $9.75 million; Travelers $1.55 million.

Constructed geometry · not a chart of case data
JurisdictionUSANew Yorkthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetGEICO and Travelers
ActorUnattributed
D. Kennedy9 min readConfidence: high4 sources reviewed

New York Attorney General Letitia James and Department of Financial Services Superintendent Adrienne Harris announced on Nov. 25, 2024, that GEICO would pay $9.75 million and Travelers $1.55 million over the theft of driver’s license numbers through their auto insurance quoting systems in 2020 and 2021. The numbers had been used to file fraudulent unemployment claims during the pandemic. About 116,000 New Yorkers were affected at GEICO and about 4,000 at Travelers.

The GEICO order split $5 million to the department and $4.75 million to the attorney general. Travelers paid $1.2 million and $350,000. Both carriers agreed to remediation programs covering data inventories, authentication, logging and monitoring.

What The GEICO Order Found

Three events. The customer quoting application had returned full license numbers to the browser in its responses. A claims flow exposed numbers after fraudulent policy purchases. An open API used by the agent sales portal, its address visible in public page source, had been exploited from as early as November 2020, about 75 times by Jan. 22, 2021, and then by automation at 10,000 to 25,000 queries a day from Feb. 24 until March 1, 2021. GEICO discovered the third event through messages from the attackers offering to sell the data back, and from a tip by someone who had fallen out with them. The department had sent an informal alert on Jan. 28 and an industry-wide fraud alert on Feb. 16.

The department found violations of the cybersecurity regulation’s requirements for a program, policies, penetration testing, risk assessment, application security and access controls, and deemed the company’s compliance certifications for 2017 through 2021 improper. The 2021 incident itself is filed at 21-0419.

What The Travelers Order Found

The independent-agent quoting portal was protected by a password and nothing else. The department had warned the industry about agent portals and credential stuffing on March 30, 2021. On Nov. 11, 2021, a pre-fill data provider flagged a spike from one California agency; two compromised agent accounts had pulled about 40,000 household driver reports with license numbers, birth dates and insurance history. Suspicious activity ran back to April 7. Travelers had begun deploying multifactor authentication in September and had not finished.

The First Enforcement Of The Quote-Form Problem

The quote form as a data source for fraud had been in the record since Nationwide, filed at 12-1206, and had produced the Elephant breach at 22-0527b. The November 2024 orders are the first time a regulator priced it. The penalties fell on two carriers; the design is industry-wide, and the department’s February 2021 alert had said so.

How we reported this

Compiled from the department’s and attorney general’s announcements and the two consent orders, listed below. Query volumes, dates and violation findings are the orders’. The press release describes the Travelers activity as undetected for more than seven months; the order’s dates are used here. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto InsurersNew York Department of Financial Services
  2. Consent order, GEICONew York Department of Financial Services
  3. Consent order, The Travelers Indemnity CompanyNew York Department of Financial Services
  4. New York fines GEICO, Travelers over data breaches, Nov. 25, 2024Insurance Journal
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary