New York regulators have taken action against an auto insurance company after investigators found cybersecurity weaknesses that exposed thousands of consumers’ personal information to fraudsters. According to the New York Attorney General’s Office, attackers exploited vulnerabilities in online insurance quote systems to obtain sensitive driver information later used in identity theft and fraudulent unemployment claims.
The investigation centered on online quoting tools designed to simplify the insurance shopping process. Consumers entering limited information could receive quotes quickly, but investigators found that system flaws allowed bad actors to access driver’s license numbers and other personally identifiable information. Thousands of New Yorkers were affected.
Authorities determined that automated attacks targeted the company’s public-facing systems. In some cases, criminals were able to harvest information at scale, collecting data later linked to fraudulent benefit applications during the pandemic. Regulators concluded that inadequate security controls, insufficient monitoring, and poor risk management practices contributed to the exposure.
The resulting enforcement action required significant financial penalties and security improvements. Investigators emphasized that while cybercriminals carried out the attacks, companies handling sensitive data have a responsibility to implement safeguards that reduce the likelihood of successful exploitation.
“When companies have poor data security practices, they put individuals at risk of identity theft and other fraud,” New York Attorney General Letitia James said when announcing the enforcement action.
The case highlights the growing connection between cybersecurity failures and downstream fraud. Increasingly, criminals do not need to steal identities directly from consumers. Instead, they target organizations that aggregate large volumes of personal information. Driver’s license numbers, dates of birth, and contact information can fuel identity theft, unemployment fraud, synthetic identity schemes, and account takeover attacks for years after a breach occurs.
For agencies and organizations alike, fraud prevention begins with protecting data at the source. Strong authentication, proactive vulnerability testing, automated attack detection, and continuous monitoring remain among the most effective defenses against identity-based fraud.
Today’s Fraud of the Day is based on reporting from the New York Attorney General’s Office regarding data security enforcement actions announced in March 2025.

13 hours ago
7
_Andriy_Popov_Alamy.png?width=720&quality=80&disable=upscale)





_ber1a_Alamy.png?width=720&quality=80&disable=upscale)

.png)
