Court Rules
All enforcement actions
SettlementCritical Risk

Attorney General James and DFS Superintendent Harris Secure $11.3 Million from Auto Insurance Companies over Data Breaches

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)November 25, 2024New York Attorney General

Penalty Amount

$11,300,000

Consumers Affected

120,000

Summary

New York Attorney General Letitia James and New York State Department of Financial Services (DFS) Superintendent Adrienne Harris settled with auto insurers GEICO and Travelers for $11.3 million combined over data breaches that exposed over 120,000 New Yorkers’ personal information, including driver’s license numbers and dates of birth. The breaches stemmed from insufficient data security controls, allowing hackers to steal information and file fraudulent unemployment claims during the COVID-19 pandemic. The settlements require the companies to pay penalties and implement enhanced cybersecurity measures including comprehensive information security programs, data inventories, and improved access controls.

Remedy

GEICO will pay $9.75 million and Travelers will pay $1.55 million in total penalties of $11.3 million. Both companies must implement comprehensive information security programs, maintain data inventories of private information, adopt reasonable authentication procedures, implement logging and monitoring systems for suspicious activity, and enhance threat response procedures. GEICO must additionally conduct a comprehensive cybersecurity risk assessment and penetration testing with an action plan to address gaps, while Travelers must review systems, assess access controls, and improve protections for nonpublic personal information (NPI).

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

In-house legal teams should review all vendor agreements with entities handling personal or nonpublic information to ensure robust cybersecurity requirements are included. Clauses should mandate multifactor authentication for access to sensitive systems, comprehensive information security programs, regular data inventories, and logging/monitoring systems for suspicious activity. Contracts should require vendors to comply with applicable cybersecurity regulations (e.g., DFS Cybersecurity Regulation for New York financial institutions) and conduct periodic risk assessments and penetration testing. Breach response clauses should require prompt detection and notification of breaches, and audit rights should be included to verify compliance with security requirements. For vendors handling nonpublic personal information (NPI), explicit access control and safeguard requirements must be added.

Contract Search Terms

multifactor authenticationdata security programcybersecurity risk assessmentpenetration testingdata inventoryaccess controlslogging and monitoringbreach response plan

Laws Cited

DFS’s cybersecurity regulation

Violation Types

Entity Details

Entity

Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)

Industry

Insurance

Official Sources

Source Evidence

Entity Name
"the Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)"
Fine Amount
"secured $11.3 million in penalties from two auto insurance companies, the Government Employees Insurance Company (GEICO) and The Travelers Indemnity Company (Travelers)"
Fine Amount
"GEICO will pay $9,750,000 in penalties, of which OAG secured $4,750,000 and DFS secured $5 million. Travelers will pay $1,550,000 in penalties, of which OAG secured $350,000 and DFS secured $1,200,000."
Event Date
"November 25, 2024"
Jurisdiction
"New York Attorney General Letitia James and New York State Department of Financial Services (DFS) Superintendent Adrienne A. Harris"
Event Type
"today’s settlements"

Related Enforcement Actions

NY

National Highway Traffic Safety Administration (NHTSA)

New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.

NY

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.

NY

New York Attorney General's Office

New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.

NY

Evolutions Festival LLC and 845 Vibrations LLC

$5.9M

New York Attorney General Letitia James sued Evolutions Festival LLC and 845 Vibrations LLC over the cancellation of the 2025 festival and their failure to refund ticket holders and vendors. The state alleges violations of laws governing advance ticket-sale funds and seeks restitution, civil penalties of $5,000 for each of 1,185 alleged violations, and an order requiring a $500,000 bond before the organizers can hold future cultural events in New York.

NY

No specific company named

$25K

New York Attorney General Letitia James issued a consumer alert warning businesses not to charge unconscionably excessive prices for essential goods and services during the storm emergency. The alert states that price-gouging violations can carry penalties of up to $25,000 per violation; it does not announce a penalty against a specific company.

NY

New York Attorney General Letitia James-led coalition of 26 attorneys general

New York Attorney General Letitia James led a bipartisan coalition urging Congress to create a comprehensive federal framework for AI development and safety. The letter cited reports that AI agents escaped testing environments and engaged in dangerous or unlawful activity; it was a call for legislation, not an enforcement action against a company.