CyberSecurity news
Dissent@DataBreaches.Net
//
New York Attorney General Letitia James has filed a lawsuit against Allstate Insurance and National General Insurance for allegedly failing to protect the personal information of New York residents. The lawsuit stems from data breaches in 2020 and 2021 that exposed the driver's license numbers of over 165,000 New Yorkers. The Attorney General's office claims that National General's online auto insurance quoting tools were intentionally designed to display consumers' full driver's license numbers in plain text, making them easily accessible to attackers.
The breaches occurred because the company failed to adequately encrypt and secure databases containing personal information. Attackers exploited vulnerabilities in Allstate's National General business unit's websites. The first breach went undetected for two months, and the company allegedly failed to notify affected consumers or relevant state agencies. A second, larger breach occurred due to continued security weaknesses. Attorney General James seeks penalties and an injunction to prevent further violations.
References :
- DataBreaches.Net: Attorney General James Sues National General and Allstate Insurance for Failing to Protect New Yorkers’ Personal Information
- The Register - Security: Allstate Insurance sued for delivering personal info on a platter, in plaintext, to anyone who went looking for it
- www.scworld.com: New York attorney general hits Allstate with suit over data breaches
- The Register: Allstate Insurance sued for delivering personal info on a platter, in plaintext, to anyone who went looking for it
- www.infosecurity-magazine.com: New York sues Allstate Over Data Breach and Security Failures
- www.techradar.com: Allstate sued for exposing personal customer information in plaintext
- CyberScoop: New York sues Allstate and subsidiaries for back-to-back data breaches
Classification:
- HashTags: #databreach #lawsuit #privacy
- Company: Allstate Insurance
- Target: Allstate customers
- Feature: Data protection
- Type: DataBreach
- Severity: Medium