Court Rules
All enforcement actions
SettlementMedium Risk

NY AG Fines Root Insurance $975K for Data Breach Exposing Driver's Licenses

Root Insurance CompanyMarch 20, 2025New York Attorney General

Penalty Amount

$975,000

Consumers Affected

45,000

Summary

New York Attorney General Letitia James reached a $975,000 settlement with Root Insurance Company over a data breach that exposed the personal information of approximately 45,000 New York residents. The breach, discovered in January 2021, stemmed from Root’s inadequate data security measures, including unencrypted driver’s license numbers in quote PDFs and insufficient controls against automated attacks. In addition to the monetary penalty, Root must implement enhanced data security measures including a comprehensive information security program, data inventory, and monitoring systems.

Remedy

Root must pay $975,000 in penalties. The company is also required to implement and maintain a comprehensive information security program, develop a data inventory of private information with reasonable safeguards, implement reasonable authentication procedures for access to private information, and maintain a logging and monitoring system with policies to alert on suspicious activity.

Monetary PenaltyCompliance Program

Contract Impact

In-house legal teams, particularly those in the insurance industry or companies that collect consumer driver’s license information via online tools, should review vendor agreements for web development, data security, and cloud hosting services to ensure they mandate adequate risk assessments of public-facing applications, prohibit plaintext storage of sensitive PII (including driver’s license numbers), and require controls to prevent automated attacks. Data processing and security vendor contracts should also include requirements for maintaining comprehensive data inventories, implementing reasonable authentication procedures for private information access, and deploying logging/monitoring systems with suspicious activity alerting. Additionally, contracts governing online consumer quoting tools should include specific security standards to prevent vulnerabilities like unauthorized prefilling of sensitive data.

Contract Search Terms

data security safeguardsweb application risk assessmentplaintext PII storageautomated attack controlsdata inventory requirementsauthentication procedures for private informationlogging and monitoring systemssuspicious activity alerting

Violation Types

Entity Details

Entity

Root Insurance Company

Also known as: Root

Industry

Insurance

Official Sources

Source Evidence

Entity Name
"secured $975,000 in penalties from Root, an auto insurance company"
Fine Amount
"$975,000 in penalties"
Event Date
"March 20, 2025"
Consumers Affected
"approximately 45,000 New Yorkers"
Violation Types
"OAG found that Root failed to perform adequate risk assessments on its public-facing web applications, did not identify the plain text exposure of consumer personal information, and employed insufficient controls to thwart automated attacks"
Violation Types
"Root’s system exposed full, plaintext driver’s license numbers in a PDF generated at the end of the auto quote process"

Related Enforcement Actions

NY

National Highway Traffic Safety Administration (NHTSA)

New York Attorney General Letitia James joined a coalition lawsuit challenging NHTSA’s rollback of federal fuel economy standards. The coalition alleges that the final rule violates federal law and asks the court to strike it down; the press release describes no privacy violations or monetary penalty.

NY

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

New York Attorney General Letitia James and a coalition of 47 other attorneys general secured a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. over an alleged scheme to coordinate generic drug prices and reduce competition. The settlement provides for consumer compensation and requires Sandoz to implement antitrust compliance reforms, including annual staff training and a Chief Compliance Officer.

NY

New York Attorney General's Office

New York Attorney General Letitia James joined eight other attorneys general in issuing a statement criticizing a DOJ judicial misconduct complaint against nearly all federal district court judges in Minnesota. The release concerns judicial independence, not a privacy enforcement action; it announces no penalty or privacy-related remedy.

NY

Evolutions Festival LLC and 845 Vibrations LLC

$5.9M

New York Attorney General Letitia James sued Evolutions Festival LLC and 845 Vibrations LLC over the cancellation of the 2025 festival and their failure to refund ticket holders and vendors. The state alleges violations of laws governing advance ticket-sale funds and seeks restitution, civil penalties of $5,000 for each of 1,185 alleged violations, and an order requiring a $500,000 bond before the organizers can hold future cultural events in New York.

NY

No specific company named

$25K

New York Attorney General Letitia James issued a consumer alert warning businesses not to charge unconscionably excessive prices for essential goods and services during the storm emergency. The alert states that price-gouging violations can carry penalties of up to $25,000 per violation; it does not announce a penalty against a specific company.

NY

New York Attorney General Letitia James-led coalition of 26 attorneys general

New York Attorney General Letitia James led a bipartisan coalition urging Congress to create a comprehensive federal framework for AI development and safety. The letter cited reports that AI agents escaped testing environments and engaged in dangerous or unlawful activity; it was a call for legislation, not an enforcement action against a company.