Skip to content
DiSanto Propane (Banner)
Home » News » New York State » AG James secures $500,000 settlement with auto insurer Noblr over data breach affecting 80,000 New Yorkers

AG James secures $500,000 settlement with auto insurer Noblr over data breach affecting 80,000 New Yorkers

AG James secures 0,000 settlement with auto insurer Noblr over data breach affecting 80,000 New Yorkers

New York Attorney General Letitia James announced Thursday a $500,000 settlement with auto insurance company Noblr for failing to protect the personal information of more than 80,000 New Yorkers. The data breach exposed sensitive information, including driver’s license numbers, which scammers used to file fraudulent unemployment claims during the height of the COVID-19 pandemic.

The settlement brings the total amount secured by Attorney General James from auto insurance companies over cybersecurity failures to $5.6 million, including previous settlements with GEICO and Travelers.

“Auto insurance companies offer drivers protection during emergencies, but they must also protect their personal information from hackers and scammers,” Attorney General James said in a statement. “Noblr failed to secure its data systems, making it easy for scammers to steal New Yorkers’ information and use it to fraudulently obtain unemployment benefits. Today, we are holding Noblr accountable for being reckless with New Yorkers’ personal data and reminding all companies that they must prioritize cybersecurity.”

Noblr’s breach stemmed from vulnerabilities in its online insurance quoting tool, which exposed full driver’s license numbers in plaintext through backend website features and PDFs generated during transactions. Additionally, the company did not block users from entering data of New York residents, despite not offering insurance products in the state.

Finger Lakes Partners (Billboard)

The breach occurred in January 2021, but Noblr’s failure to monitor site traffic in real time delayed detection and hindered efforts to distinguish between malicious activity and legitimate inquiries. As a result, scammers exploited the vulnerability, compromising the data of thousands of New Yorkers.

The Office of the Attorney General’s investigation found Noblr did not implement reasonable safeguards to protect sensitive data. Under the settlement, Noblr must pay $500,000 in penalties and improve its cybersecurity measures by:

  • Enhancing web application defenses
  • Developing a comprehensive information security program
  • Maintaining a data inventory and implementing safeguards for private information
  • Enforcing authentication procedures for data access
  • Establishing a logging and monitoring system for suspicious activity

The settlement with Noblr is part of a broader effort by Attorney General James to strengthen data security practices and hold companies accountable for cybersecurity lapses. In November, she secured $11.3 million from GEICO and Travelers for similar failures. Earlier this year, her office reached settlements with a Capital Region health care provider, a biotech company, and issued multiple guides to help businesses and consumers improve data security and privacy practices.

The investigation into Noblr was conducted by Assistant Attorneys General Gena Feist and Laura Mumm, with support from Deputy Bureau Chief Clark Russell and Bureau Chief Kim Berger of the Bureau of Internet and Technology. The Bureau is part of the Division for Economic Justice, led by Chief Deputy Attorney General Chris D’Angelo and overseen by First Deputy Attorney General Jennifer Levy.



Categories: NewsNew York State