New York AG files lawsuit against National General and Allstate over data breaches

Published 10/03/2025, 16:34
© Reuters.

Investing.com -- New York Attorney General Letitia James has filed a lawsuit against insurance companies National General and Allstate Insurance Company (NYSE:ALL) following a series of data breaches. The breaches, which took place in 2020 and 2021, exposed the driver’s license numbers of over 165,000 New Yorkers. The lawsuit alleges that National General failed to adequately protect personal information from cyberattacks and failed to notify impacted consumers after the first data breach.

The Office of the Attorney General (OAG) claims that National General did not determine if sensitive information was exposed elsewhere in its system following the first breach. This alleged negligence allowed for a second, larger breach to occur months later. The lawsuit asserts that these breaches were due to National General’s failure to implement reasonable data security measures, both before and after Allstate assumed control of its data security operations.

The lawsuit seeks penalties for National General’s alleged failure to establish reasonable data security safeguards and notify consumers. It also seeks an injunction to stop any continued violations.

According to Attorney General James, "National General’s weak cybersecurity emboldened hackers to steal New Yorkers’ personal data, not once but twice in two separate cyberattacks." She added that it is crucial for companies to take cybersecurity seriously to protect consumers from fraud and identity theft.

In 2020, attackers targeted National General’s online quoting websites, which provided instant auto insurance quotes. These websites were designed to automatically display consumers’ full driver’s license numbers in plain text with minimal input, a flaw that attackers exploited to access consumers’ private information.

The first breach affected two public-facing websites, exposing the driver’s license numbers of nearly 12,000 individuals, including more than 9,100 New Yorkers. National General allegedly failed to detect the breach for two months due to inadequate monitoring and a lack of protections against automated attacks.

Upon discovering the breach, National General allegedly did not alert the affected consumers or notify the appropriate state agencies. The company also reportedly continued to leave driver’s license numbers exposed on a separate quoting website for independent insurance agents, which was also weakly protected.

A second, larger breach occurred in February 2021, which compromised the personal information of an additional 187,000 consumers, including the driver’s license numbers of approximately 155,000 New Yorkers. The lawsuit alleges that National General’s data security failures continued even after The Allstate Corporation acquired National General and Allstate took over National General’s data security function.

Attorney General James alleges that National General violated state consumer protection and business laws by failing to secure sensitive information, misrepresenting its data security practices to customers and consumers, and failing to notify affected consumers of the initial breach.

This article was generated with the support of AI and reviewed by an editor. For more information see our T&C.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers
© 2007-2025 - Fusion Media Limited. All Rights Reserved.