provider Geico suffered a data breach in which malicious actors stole customers’ driver’s license numbers . Geico is the second-largest company auto insurance, with more than 17 million policies covering more than 28 million vehicles.
In a data breach notification filed with the California Attorney General's office, Geico says that, for over a month, malicious actors abused an online sales portal to gain access to its customers' driver's license numbers.
Read also: Booking.com: Fined €475,000 for failing to report data breach in a timely manner

Specifically, the breach notification first published on “TechCrunch” states the following: “We recently discovered that between January 21, 2021, and March 1, 2021, fraudsters used your information – which they obtained from elsewhere – to gain unauthorized access to your driver’s license number through the online sales system on our website.”
Geico also noted that malicious actors used customer information to gather information about policyholders, without specifying what information was needed to access the online sales portal.
Geico believes that malicious actors intend to use the stolen driver's license numbers to apply for unemployment benefits in their owners' names.
See also: SitePoint: The site providing web development tutorials suffered a data breach!

Specifically, the company said: "We have reason to believe that this information could be used by malicious actors to fraudulently apply for unemployment benefits in your name. If you receive emails from your state's unemployment agency, review them carefully and contact that agency to learn if there is a possibility of fraud."
Proposal: Apple sues former employee for leaking trade secrets to the media
Upon learning of the incident, Geico strengthened its site security and added additional safeguards to prevent future incidents of fraud or illegal activity. For those affected, the company is offering a free one-year subscription to an identity protection service.
Finally, Geico warns that affected users should be vigilant for any unexpected emails they receive from their state's unemployment agency. If they receive such emails, they should contact the agency immediately and report the potential fraud.
Information source: bleepingcomputer.com
