Court Rules
All enforcement actions
SettlementCritical Risk

Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto Insurance Companies over Data Breaches

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)November 25, 2024New York Attorney General

Penalty Amount

$11,300,000

Consumers Affected

120,000

Summary

New York Attorney General Letitia James and New York State Department of Financial Services (DFS) Superintendent Adrienne Harris settled with auto insurers GEICO and Travelers for $11.3 million combined over data breaches that exposed over 120,000 New Yorkers’ personal information, including driver’s license numbers and dates of birth. The breaches stemmed from insufficient data security controls, allowing hackers to steal information and file fraudulent unemployment claims during the COVID-19 pandemic. The settlements require the companies to pay penalties and implement enhanced cybersecurity measures including comprehensive information security programs, data inventories, and improved access controls.

Remedy

GEICO will pay $9.75 million and Travelers will pay $1.55 million in total penalties of $11.3 million. Both companies must implement comprehensive information security programs, maintain data inventories of private information, adopt reasonable authentication procedures, implement logging and monitoring systems for suspicious activity, and enhance threat response procedures. GEICO must additionally conduct a comprehensive cybersecurity risk assessment and penetration testing with an action plan to address gaps, while Travelers must review systems, assess access controls, and improve protections for nonpublic personal information (NPI).

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review all vendor agreements with entities handling personal or nonpublic information to ensure robust cybersecurity requirements are included. Clauses should mandate multifactor authentication for access to sensitive systems, comprehensive information security programs, regular data inventories, and logging/monitoring systems for suspicious activity. Contracts should require vendors to comply with applicable cybersecurity regulations (e.g., DFS Cybersecurity Regulation for New York financial institutions) and conduct periodic risk assessments and penetration testing. Breach response clauses should require prompt detection and notification of breaches, and audit rights should be included to verify compliance with security requirements. For vendors handling nonpublic personal information (NPI), explicit access control and safeguard requirements must be added.

Contract Search Terms

multifactor authenticationdata security programcybersecurity risk assessmentpenetration testingdata inventoryaccess controlslogging and monitoringbreach response plan

Laws Cited

DFS’s cybersecurity regulation

Violation Types

Entity Details

Entity

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)

Industry

Insurance

Official Sources

Source Evidence

Entity Name
"the Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)"
Fine Amount
"secured $11.3 million in penalties from two auto insurance companies, the Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)"
Fine Amount
"GEICO will pay $9,750,000 in penalties, of which OAG secured $4,750,000 and DFS secured $5 million. Travelers will pay $1,550,000 in penalties, of which OAG secured $350,000 and DFS secured $1,200,000."
Event Date
"November 25, 2024"
Jurisdiction
"New York Attorney General Letitia James and New York State Department of Financial Services (DFS) Superintendent Adrienne A. Harris"
Event Type
"today’s settlements"

Related Enforcement Actions

NY

U.S. Department of the Interior

New York and a coalition of other state attorneys general sued the federal government, challenging agreements that paid Bluepoint Wind and Invenergy to cancel offshore wind leases and redirect funds to other energy projects. The coalition asks the courts to declare the agreements unlawful, void the lease cancellations, and block further action to carry them out; the release does not report a penalty or court ruling.

NY

Generic drug manufacturers, including Apotex, Heritage, Bausch, Lannett, and Glenmark Pharmaceuticals USA, Inc.

$96.0M

New York Attorney General Letitia James and a bipartisan multistate coalition secured more than $96 million in settlements with generic drug manufacturers accused of conspiring to raise prices and limit competition. The settlement proceeds are being distributed to eligible consumers, and settling defendants agreed to cooperate in ongoing cases and make reforms to prevent future misconduct.

NY

Paramount Skydance Corp. and Warner Bros. Discovery, Inc.

New York Attorney General Letitia James and a coalition of 11 other attorneys general secured enforceable commitments from Paramount Skydance Corp. and Warner Bros. Discovery, Inc. to protect entertainment industry workers during their merger. Paramount must release at least 30 films per year, invest $1.5 billion in domestic film production, and create an independent editorial board for CNN and CBS. The consent decree also requires Paramount to sell Miramax and pay penalties if it fails to meet production requirements.

NY

Brooklyn High Rise LLC

$352K

New York Attorney General Letitia James settled with Brooklyn High Rise LLC for illegally denying housing to prospective tenants based on housing court records, a practice known as tenant blacklisting. The company also charged non-refundable 'good faith' deposits. Brooklyn High Rise will pay $352,250 in penalties and restitution and must end its unlawful tenant screening practices.

NY

Various AI developers (no specific entity named)

New York Attorney General Letitia James issued an industry alert urging workers with knowledge of unsafe or illegal conduct in AI development to file confidential complaints through the OAG's secure whistleblower portal. The alert cites the OAG's monitoring of cybersecurity, economic, and other safety risks from emerging AI, and highlights the RAISE Act (effective January 1, 2027), which will require large AI developers to publicly disclose safety measures and report security incidents, as well as the SHIELD Act's data security requirements. No company was named, charged, or penalized; the alert signals impending OAG enforcement authority over AI developers.

NY

Credit Acceptance Corporation

$700.0M

New York Attorney General Letitia James, leading a bipartisan coalition of 39 other states, the District of Columbia, and Hawaii's Office of Consumer Protection, secured a $700 million settlement from Credit Acceptance Corporation (CAC), a subprime auto lender, resolving allegations of deceptive and abusive lending. The lawsuit alleged CAC pushed tens of thousands of consumers into unaffordable loans with average interest rates above 38 percent, bundled with expensive add-on products consumers were told were mandatory or never told about, causing widespread defaults and vehicle repossessions. Note: this is a consumer-lending enforcement action rather than a privacy matter, so no privacy violation categories from the taxonomy apply.