Court Rules
All enforcement actions
SettlementCritical Risk

NY AG and DFS Fine GEICO, Travelers $11.3M for Data Breaches

Government Employees Insurance Company (GEICO) and The Travelers Indemnity CompanyNovember 25, 2024New York Attorney General

Penalty Amount

$11,300,000

Summary

GEICO and Travelers were fined $11.3 million for data breaches that exposed personal information of over 120,000 New Yorkers due to inadequate cybersecurity. The breaches involved driver's license numbers being stolen and used in fraudulent unemployment claims. The settlements mandate enhanced security measures and penalties.

Remedy

GEICO must pay $9.75 million and Travelers $1.55 million in penalties. Both companies must implement comprehensive information security programs, maintain data inventories, improve authentication, enhance logging and monitoring, and conduct cybersecurity risk assessments and penetration testing.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review all agreements related to online insurance quoting applications, including vendor contracts with software providers, customer privacy policies, and data processing agreements. Focus on clauses governing data security standards (e.g., encryption, access controls), incident response and breach notification timelines, audit rights, and third-party vendor oversight. Given the failure to protect driver's license numbers, contracts must be updated to mandate specific technical safeguards like multi-factor authentication, regular penetration testing, and strict data minimization/retention limits. Vendor agreements should include enforceable security requirements, right-to-audit provisions, and liability for breaches caused by vendor negligence.

Contract Search Terms

data security controlsencryption standardsmulti-factor authenticationvulnerability assessmentsincident response plandata retention policythird-party vendor managementaccess controlssecurity audit requirementsbreach notification procedures

Laws Cited

DFS Cybersecurity Regulation

Violation Types

Entity Details

Entity

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company

Also known as: GEICO, Travelers

Industry

Financial Services

Official Sources