DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Attorney General James Secures $975,000 from Auto Insurance Company over Data Breach

Posted on March 23, 2025March 22, 2025 by Dissent

From a March 20 press release from NY Attorney General Letitia James:

NEW YORK – New York Attorney General Letitia James today secured $975,000 in penalties from Root, an auto insurance company, for failing to protect the personal information of approximately 45,000 New Yorkers. The data breach was part of an industry-wide campaign to steal consumers’ personal information, including driver’s license numbers and dates of birth, from online automobile insurance quoting applications. The data thieves then used some of the stolen driver’s license information to file fraudulent unemployment claims at the height of the COVID-19 pandemic. Root does not offer insurance in New York, but the company’s security failures allowed scammers to gain access to New Yorkers’ driver’s license numbers and personal information. Attorney General James recently secured $5.1 million from GEICO and Travelers, as well as $500,000 from Noblr, for also failing to protect New Yorkers’ data. Today’s settlement brings the total amount secured from auto insurance companies for their failure to protect New Yorkers’ data to $6.57 million.

“When companies have poor data security practices, they put individuals at risk of identity theft and other fraud,” said Attorney General James. “Auto insurance companies need to make sure that the systems they use to store people’s data are protected to prevent cybercriminals from stealing driver’s license numbers, Social Security numbers, and other private information. Today’s settlement should send a message to companies in the auto insurance industry that my office will take action to protect New Yorkers’ private information.”

Root is an insurance company that allows consumers to obtain a price quote through its website. After limited personal information was entered, the online quoting tool “pre-filled” personal information such as driver’s license numbers. Root’s system exposed full, plaintext driver’s license numbers in a PDF generated at the end of the auto quote process.

In January 2021, Root discovered bad actors exploiting the prefill vulnerability. The Office of the Attorney General (OAG) found that Root failed to perform adequate risk assessments on its public-facing web applications, did not identify the plain text exposure of consumer personal information, and employed insufficient controls to thwart automated attacks. Approximately 45,000 New Yorkers were impacted by the Root attack.

The OAG investigation determined that the insurance company failed to adopt reasonable safeguards to protect private information. In addition to paying $975,000 in penalties, Root is required to enhance its data security, including by:

  • Maintaining a comprehensive information security program designed to protect the security, confidentiality, and integrity of private information;
  • Developing and maintaining a data inventory of private information and ensuring such information is protected by reasonable safeguards;
  • Maintaining reasonable authentication procedures for access to private information; and
  • Maintaining a logging and monitoring system as well as reasonable policies and procedures designed to properly configure the system to alert of suspicious activity.

Attorney General James is a leader in holding companies accountable for having poor cybersecurity. In March 2025, Attorney General James sued Allstate Insurance for failing to protect New Yorkers’ information, causing more than 165,000 New Yorkers’ information to be exposed. In December 2024, Attorney General James announced a $500,000 settlement with Noblr auto insurance for inadequate data security. In November 2024, Attorney General James and Department of Financial Services Superintendent Adrienne Harris secured $11.3 million from GEICO and Travelers for having poor data security. In October 2024, Attorney General James secured $2.25 million from a Capital Region health care provider for failing to protect the private information and medical data of New Yorkers. In August 2024, Attorney General James and a multistate coalition secured $4.5 from a biotech company for failing to protect patient data. In July 2024, Attorney General James launched two privacy guides, a Business Guide to Website Privacy Controls and a Consumer Guide to Tracking on the Web, to help businesses and consumers protect themselves. In April 2023, Attorney General James released a comprehensive data security guide to help companies strengthen their data security practices.

This matter was led by Assistant Attorneys General Gena Feist and Laura Mumm, and former Assistant Attorneys General Hanna Baek and Ezra Sternstein, Data Security Analyst Nishaant Goswamy, and former Internet and Technology Analyst Joe Graham, under the supervision of Deputy Bureau Chief Clark Russell and Bureau Chief Kim Berger of the Bureau of Internet and Technology. Data analysis was provided by Data Analyst Casey Marescot and Data Scientist Blythe Davis, under the supervision of Deputy Director Gautam Sisodia, Director Victoria Khan, former Deputy Director Megan Thorsfeldt, and former Director Jonathan Werberg of the Research and Analytics Department. The Bureau of Internet and Technology is a part of the Division for Economic Justice, which is led by Chief Deputy Attorney General Chris D’Angelo and overseen by First Deputy Attorney General Jennifer Levy.

Related posts:

  • 200+ Sites hacked by PCP in retaliation attack
  • Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto Insurance Companies over Data Breaches
  • Attorney General James Secures $500,000 from Auto Insurance Company Over Data Breach
  • Attorney General James Secures $450,000 from US Radiology Specialists for failing to protect patient data
Category: Breach IncidentsCommentaries and Analyses

Post navigation

← Indiana health systems unite to help smaller providers tackle cybersecurity
Union County’s computer network breached, personal information accessed →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught
  • International Criminal Court hit with cyber attack during NATO summit
  • Pembroke Regional Hospital reported canceling appointments due to service delays from “an incident”
  • Iran-linked hackers threaten to release emails allegedly stolen from Trump associates
  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.