New York Attorney General Letitia James and Department of Financial Services Superintendent Adrienne Harris announced on Nov. 25, 2024, that GEICO would pay $9.75 million and Travelers $1.55 million over the theft of driver’s license numbers through their auto insurance quoting systems in 2020 and 2021. The numbers had been used to file fraudulent unemployment claims during the pandemic. About 116,000 New Yorkers were affected at GEICO and about 4,000 at Travelers.
The GEICO order split $5 million to the department and $4.75 million to the attorney general. Travelers paid $1.2 million and $350,000. Both carriers agreed to remediation programs covering data inventories, authentication, logging and monitoring.
What The GEICO Order Found
Three events. The customer quoting application had returned full license numbers to the browser in its responses. A claims flow exposed numbers after fraudulent policy purchases. An open API used by the agent sales portal, its address visible in public page source, had been exploited from as early as November 2020, about 75 times by Jan. 22, 2021, and then by automation at 10,000 to 25,000 queries a day from Feb. 24 until March 1, 2021. GEICO discovered the third event through messages from the attackers offering to sell the data back, and from a tip by someone who had fallen out with them. The department had sent an informal alert on Jan. 28 and an industry-wide fraud alert on Feb. 16.
The department found violations of the cybersecurity regulation’s requirements for a program, policies, penetration testing, risk assessment, application security and access controls, and deemed the company’s compliance certifications for 2017 through 2021 improper. The 2021 incident itself is filed at 21-0419.
What The Travelers Order Found
The independent-agent quoting portal was protected by a password and nothing else. The department had warned the industry about agent portals and credential stuffing on March 30, 2021. On Nov. 11, 2021, a pre-fill data provider flagged a spike from one California agency; two compromised agent accounts had pulled about 40,000 household driver reports with license numbers, birth dates and insurance history. Suspicious activity ran back to April 7. Travelers had begun deploying multifactor authentication in September and had not finished.
The First Enforcement Of The Quote-Form Problem
The quote form as a data source for fraud had been in the record since Nationwide, filed at 12-1206, and had produced the Elephant breach at 22-0527b. The November 2024 orders are the first time a regulator priced it. The penalties fell on two carriers; the design is industry-wide, and the department’s February 2021 alert had said so.
Compiled from the department’s and attorney general’s announcements and the two consent orders, listed below. Query volumes, dates and violation findings are the orders’. The press release describes the Travelers activity as undetected for more than seven months; the order’s dates are used here. Graded high. Corrections: corrections@forensicpost.com.
- Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto InsurersNew York Department of Financial Services
- Consent order, GEICONew York Department of Financial Services
- Consent order, The Travelers Indemnity CompanyNew York Department of Financial Services
- New York fines GEICO, Travelers over data breaches, Nov. 25, 2024Insurance Journal