state has sued insurance company Allstate, accusing its National General subsidiary of failing to disclose a data breach that exposed users' driver's license numbers and failing to have reasonable safeguards in place to personal information drivers'

Allstate bought National General for about $4 billion in January 2021.
See also: Healthcare data breaches affect 560,000 people
The lawsuit, filed in state court in Manhattan by New York Attorney General Letitia James , alleges that National General's inadequate data security led to breaches in 2020 and 2021. Hackers gained access to license numbers for more than 165,000 New Yorkers and 199,000 people overall.
The lawsuit against Allstate was filed because National General did not notify drivers or New York state authorities about the first breach, which occurred between August and November 2020. Also, at least three months passed before the second, much larger breach was disclosed in January 2021.
The prosecutor said National General violated the Stop Hacks and Improve Electronic Data Security Actby failing to protect customer information . At the same time, it violated state consumer protection laws by misleading consumers about its data security practices.
See also: NTT: Data breach affects 18,000 customers
The lawsuit seeks civil penalties of $5,000 per violation, as well as other remedies.
“National General’s weak cybersecurity allowed hackers to steal New Yorkers’ personal data, not once but twice,” James said. “It’s vital that companies take cybersecurity to protect consumers from fraud and identity theft.”

The security breaches at Allstate National General serve as a reminder of the importance of implementing strong cybersecurity measures. Companies should regularly update security protocols , run vulnerability scans , and provide employee training to prevent similar incidents in the future. Users should also take preventative measures, such as using unique passwords and regularly monitoring account activity.
See also: Multiple schools report breaches after ransomware attack on CCC
In today’s digital age, trust and transparency are crucial to maintaining customer loyalty. Companies must be transparent about data breaches and communicate with affected individuals in a timely manner. This not only helps mitigate potential damage, but also demonstrates responsibility and commitment to protecting user data.
Source: finance.yahoo.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
