Listen to this Post
In a significant legal move, New York State has filed a lawsuit against Allstate and its subsidiaries, accusing them of inadequate security practices that resulted in major data breaches in 2020 and 2021. These breaches exposed sensitive information about nearly 200,000 individuals, leading to widespread concerns over data privacy and security. The lawsuit specifically targets National General, an insurance company acquired by Allstate in 2021 for $4 billion, for mishandling customer data and failing to notify those affected in a timely manner.
the Incident:
The legal action stems from two major data breaches that occurred under Allstate’s watch, starting with National General, a subsidiary that failed to protect the sensitive data of nearly 12,000 individuals. These people had their driver’s license numbers compromised in a cyberattack that went unnoticed for more than two months in late 2020. The breach was only discovered after a significant delay, raising serious questions about National General’s cybersecurity practices.
Just months later, in the midst of Allstate’s acquisition of National General, another cyberattack targeted the company’s auto insurance quoting tool, exposing the personal data of 187,000 people. The breach involved the theft of driver’s license numbers, once again drawing attention to the poor security measures taken by the company. The state’s attorney general, Letitia James, criticized National General for its lax security and failure to notify those affected, calling the repeated breaches “remarkable in scale.”
The lawsuit specifically accuses National General of building its online quote tool in a manner that made it easier for hackers to steal driver’s license numbers. Despite addressing the issue after the first breach, the company allegedly failed to make adequate changes to its quoting system, leaving it vulnerable to another attack.
In response, Allstate’s communications manager, Ben Corey, stated that the company had resolved the issue by securing its systems and notifying regulators and affected customers. He added that free credit monitoring was offered as a precautionary measure. This case represents New York’s continued efforts to hold insurance companies accountable for poor cybersecurity practices. Just a month earlier, the state secured settlements with Geico and Travelers for similar breaches involving the exposure of driver’s license numbers.
What Undercode Says:
From a cybersecurity perspective, the lawsuit against Allstate and National General underscores critical lessons about the importance of data protection in the digital age. The fact that two separate breaches took place at the same company, exposing sensitive information, highlights serious gaps in the cybersecurity framework of National General. Despite initial remediation efforts following the first breach, the company failed to address the root cause of its vulnerability—the exposure of driver’s license numbers in plain text on its online quoting tool.
What stands out is the lack of proactive measures taken by National General, even after the first breach. This speaks to a broader issue within many organizations, particularly in sectors like insurance, where the protection of personal and financial data is paramount. Building systems without considering potential security threats or overlooking basic protections such as data encryption can lead to catastrophic breaches, as seen in this case.
Moreover, the two-month delay in identifying and reporting the initial breach is another alarming red flag. In today’s fast-paced cyber threat environment, response times are crucial. Companies are expected to have real-time monitoring and incident response systems in place, yet National General failed to detect the breach for over two months. This delay could have led to the further compromise of sensitive data, exacerbating the damage to those affected.
Allstate’s response to the lawsuit, while claiming to have fixed the issues, raises questions about how deep the company’s commitment to cybersecurity really is. Offering free credit monitoring is a standard, but somewhat reactive, measure. A more robust approach would involve continuously testing and improving systems to prevent future attacks and ensure that no sensitive data is exposed.
Additionally, New York State’s legal actions against other companies like Geico and Travelers indicate a growing trend of holding corporations accountable for cyber negligence. Insurance companies, more than most, should be at the forefront of data security due to the sensitive nature of the information they collect. The state’s active involvement in enforcing cybersecurity regulations could push more companies to prioritize robust security frameworks, not just as a legal requirement but as an ethical responsibility to their customers.
Fact Checker Results:
- The data breach incidents and the timeline of events align with public reports and statements from both New York State and Allstate.
- National General’s failure to notify those affected by the breach in a timely manner is documented in the lawsuit filed by the New York Attorney General’s office.
3.
References:
Reported By: https://cyberscoop.com/new-york-lawsuit-allstate-national-general-data-privacy/
Extra Source Hub:
https://www.github.com
Wikipedia
Undercode AI
Image Source:
Pexels
Undercode AI DI v2





