DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Attorney General James Secures $975,000 from Auto Insurance Company over Data Breach

Posted on March 23, 2025March 22, 2025 by Dissent

From a March 20 press release from NY Attorney General Letitia James:

NEW YORK – New York Attorney General Letitia James today secured $975,000 in penalties from Root, an auto insurance company, for failing to protect the personal information of approximately 45,000 New Yorkers. The data breach was part of an industry-wide campaign to steal consumers’ personal information, including driver’s license numbers and dates of birth, from online automobile insurance quoting applications. The data thieves then used some of the stolen driver’s license information to file fraudulent unemployment claims at the height of the COVID-19 pandemic. Root does not offer insurance in New York, but the company’s security failures allowed scammers to gain access to New Yorkers’ driver’s license numbers and personal information. Attorney General James recently secured $5.1 million from GEICO and Travelers, as well as $500,000 from Noblr, for also failing to protect New Yorkers’ data. Today’s settlement brings the total amount secured from auto insurance companies for their failure to protect New Yorkers’ data to $6.57 million.

“When companies have poor data security practices, they put individuals at risk of identity theft and other fraud,” said Attorney General James. “Auto insurance companies need to make sure that the systems they use to store people’s data are protected to prevent cybercriminals from stealing driver’s license numbers, Social Security numbers, and other private information. Today’s settlement should send a message to companies in the auto insurance industry that my office will take action to protect New Yorkers’ private information.”

Root is an insurance company that allows consumers to obtain a price quote through its website. After limited personal information was entered, the online quoting tool “pre-filled” personal information such as driver’s license numbers. Root’s system exposed full, plaintext driver’s license numbers in a PDF generated at the end of the auto quote process.

In January 2021, Root discovered bad actors exploiting the prefill vulnerability. The Office of the Attorney General (OAG) found that Root failed to perform adequate risk assessments on its public-facing web applications, did not identify the plain text exposure of consumer personal information, and employed insufficient controls to thwart automated attacks. Approximately 45,000 New Yorkers were impacted by the Root attack.

The OAG investigation determined that the insurance company failed to adopt reasonable safeguards to protect private information. In addition to paying $975,000 in penalties, Root is required to enhance its data security, including by:

  • Maintaining a comprehensive information security program designed to protect the security, confidentiality, and integrity of private information;
  • Developing and maintaining a data inventory of private information and ensuring such information is protected by reasonable safeguards;
  • Maintaining reasonable authentication procedures for access to private information; and
  • Maintaining a logging and monitoring system as well as reasonable policies and procedures designed to properly configure the system to alert of suspicious activity.

Attorney General James is a leader in holding companies accountable for having poor cybersecurity. In March 2025, Attorney General James sued Allstate Insurance for failing to protect New Yorkers’ information, causing more than 165,000 New Yorkers’ information to be exposed. In December 2024, Attorney General James announced a $500,000 settlement with Noblr auto insurance for inadequate data security. In November 2024, Attorney General James and Department of Financial Services Superintendent Adrienne Harris secured $11.3 million from GEICO and Travelers for having poor data security. In October 2024, Attorney General James secured $2.25 million from a Capital Region health care provider for failing to protect the private information and medical data of New Yorkers. In August 2024, Attorney General James and a multistate coalition secured $4.5 from a biotech company for failing to protect patient data. In July 2024, Attorney General James launched two privacy guides, a Business Guide to Website Privacy Controls and a Consumer Guide to Tracking on the Web, to help businesses and consumers protect themselves. In April 2023, Attorney General James released a comprehensive data security guide to help companies strengthen their data security practices.

This matter was led by Assistant Attorneys General Gena Feist and Laura Mumm, and former Assistant Attorneys General Hanna Baek and Ezra Sternstein, Data Security Analyst Nishaant Goswamy, and former Internet and Technology Analyst Joe Graham, under the supervision of Deputy Bureau Chief Clark Russell and Bureau Chief Kim Berger of the Bureau of Internet and Technology. Data analysis was provided by Data Analyst Casey Marescot and Data Scientist Blythe Davis, under the supervision of Deputy Director Gautam Sisodia, Director Victoria Khan, former Deputy Director Megan Thorsfeldt, and former Director Jonathan Werberg of the Research and Analytics Department. The Bureau of Internet and Technology is a part of the Division for Economic Justice, which is led by Chief Deputy Attorney General Chris D’Angelo and overseen by First Deputy Attorney General Jennifer Levy.

Category: Breach IncidentsCommentaries and Analyses

Post navigation

← Indiana health systems unite to help smaller providers tackle cybersecurity
Union County’s computer network breached, personal information accessed →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Banks Want SEC to Rescind Cyberattack Disclosure Requirements
  • MathWorks, Creator of MATLAB, Confirms Ransomware Attack
  • Russian hospital programmer gets 14 years for leaking soldier data to Ukraine
  • MSCS board renews contract with PowerSchool while suing them
  • Iranian Man Pleaded Guilty to Role in Robbinhood Ransomware
  • Developments surrounding data breach at Dutch police
  • Estonia launches international search for Moroccan citizen wanted over data theft
  • Now it’s Tiffany: Another LVMH luxury brand hit by hackers
  • Dutch Government: More forms of espionage to be a criminal offence from 15 May onwards
  • B.C. health authority faces class-action lawsuit over 2009 data breach (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The CCPA emerges as a new legal battleground for web tracking litigation
  • U.S. Spy Agencies Are Getting a One-Stop Shop to Buy Your Most Sensitive Personal Data
  • Period Tracking App Users Win Class Status in Google, Meta Suit
  • AI: the Italian Supervisory Authority fines Luka, the U.S. company behind chatbot “Replika,” 5 Million €
  • D.C. Federal Court Rules Termination of Democrat PCLOB Members Is Unlawful
  • Meta may continue to train AI with user data, German court says
  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.