Court Rules
All enforcement actions
SettlementCritical Risk

NY AG and DFS Fine GEICO, Travelers $11.3M for Data Breaches

Government Employees Insurance Company (GEICO) and The Travelers Indemnity CompanyNovember 25, 2024New York Attorney General

Penalty Amount

$11,300,000

Summary

GEICO and Travelers were fined $11.3 million for data breaches that exposed personal information of over 120,000 New Yorkers due to inadequate cybersecurity. The breaches involved driver's license numbers being stolen and used in fraudulent unemployment claims. The settlements mandate enhanced security measures and penalties.

Remedy

GEICO must pay $9.75 million and Travelers $1.55 million in penalties. Both companies must implement comprehensive information security programs, maintain data inventories, improve authentication, enhance logging and monitoring, and conduct cybersecurity risk assessments and penetration testing.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review all agreements related to online insurance quoting applications, including vendor contracts with software providers, customer privacy policies, and data processing agreements. Focus on clauses governing data security standards (e.g., encryption, access controls), incident response and breach notification timelines, audit rights, and third-party vendor oversight. Given the failure to protect driver's license numbers, contracts must be updated to mandate specific technical safeguards like multi-factor authentication, regular penetration testing, and strict data minimization/retention limits. Vendor agreements should include enforceable security requirements, right-to-audit provisions, and liability for breaches caused by vendor negligence.

Contract Search Terms

data security controlsencryption standardsmulti-factor authenticationvulnerability assessmentsincident response plandata retention policythird-party vendor managementaccess controlssecurity audit requirementsbreach notification procedures

Laws Cited

DFS Cybersecurity Regulation

Violation Types

Entity Details

Entity

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company

Also known as: GEICO, Travelers

Industry

Financial Services

Official Sources

Related Enforcement Actions

NY

VGW Holdings Pty. Ltd.

$8.0M

New York Attorney General Letitia James secured an $8 million settlement from VGW Holdings Pty. Ltd. and its affiliates for unlawfully operating online sweepstakes casinos — Chumba Casino, Global Poker, and Luckyland Slots — that allowed New Yorkers to play casino games with virtual coins exchangeable for cash or prizes. The OAG's June 2025 cease and desist letter stopped the company from offering virtual coin gambling in New York, and Governor Hochul signed a formal ban on sweepstakes casinos into law in December 2025. Under the settlement, VGW will pay $8 million in disgorgement, penalties, and costs; note this is an illegal-gambling enforcement action rather than a privacy matter, so no privacy violation taxonomy categories apply.

NY

425 Marcy, LLC

$824K

New York Attorney General Letitia James secured a settlement with 425 Marcy, LLC and its principal Ezra Unger over the unlawful pre-sale of condominium units at 427 Marcy Avenue in Williamsburg before the required Martin Act offering plan was accepted for filing, and the misuse of $6.715 million in buyer down payments that were never placed in escrow. Unger agreed to repay residential buyers their down payments with interest or provide purchase credits, pay up to $824,000 in penalties, and is barred from selling securities in New York for six years. Note: this is a real estate offering-plan/escrow enforcement action rather than a data privacy matter; 'notice_failure' is the closest available taxonomy mapping (selling without the required offering plan disclosures).

NY

N/A (no company named - general consumer alert about unidentified scammers)

New York Attorney General Letitia James issued a consumer alert (not an enforcement action) warning New Yorkers about scammers exploiting confusion from recent federal changes to student loan repayment programs, including the elimination of the SAVE plan and phase-out of income-driven repayment plans. The alert describes common scam tactics — upfront fees, false guarantees of loan forgiveness, manufactured urgency, demands for powers of attorney, and requests for federal student aid (FSA) credentials — and urges consumers to report scams to the OAG. No company was named, no violation was alleged against a specific entity, and no penalty was imposed.

NY

Unidentified student loan scammers (no specific entity named)

New York Attorney General Letitia James issued a consumer alert warning borrowers about scammers exploiting recent federal changes to student loan repayment programs, including the elimination of the SAVE plan and phase-out of income-based plans. The alert provides tips for borrowers, including refusing upfront fees, never granting powers of attorney to unknown parties, and never sharing Federal Student Aid login credentials. No specific company was named and no penalties or remedies were imposed; this is an advisory alert, not an enforcement action.

NY

Amazon.com, Inc.

New York Attorney General Letitia James, joined by 21 other states and the FTC, sued Amazon for secretly overcharging its advertising customers more than $20 billion by submitting fake second-place bids to inflate ad auction prices since 2018. More than 1.2 million advertisers, including hundreds of thousands of small businesses, were allegedly overcharged. The coalition seeks a court order stopping the scheme plus penalties, restitution, and damages.

NY

Meta Platforms, Inc.

$17.1B

Attorney General James and a bipartisan coalition of 50 other attorneys general secured a landmark settlement with Meta Platforms, Inc. (Meta) worth up to $17.1 billion to address the company's harmful and addictive features targeting minors on Facebook and Instagram. The settlement requires Meta to implement significant changes, including age verification, time limits for minors, restrictions on notifications, and options to opt out of algorithmic feeds, along with monetary payments to states for mental health and education programs.