IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Geico data breach leads to stolen driver’s license numbers

Monthslong hack meant fraudsters could apply for unemployment benefits in victims’ names

Geico buiding

Geico has admitted to a data breach that gave fraudsters the data they needed to file for unemployment benefits using a victim’s name.

In a notification to customers on April 9, the firm said "fraudsters used information about you — which they acquired elsewhere — to obtain unauthorized access to your driver's license number through the online sales system on [Geico's] website."

The notice was filed with the California attorney general’s office. It added that the data obtained by fraudsters was limited to customers’ driver’s license number.

The breach happened between January 12 and March 1. The insurance company said its website had been secured and “worked to identify the root cause of the incident.” It didn’t divulge how many customers the breach might have affected, but California law states that “any person or business that is required to issue a security breach notification to more than 500 California residents as a result of a single breach” must file a copy of the notice with the state attorney general’s office.

“While we regularly maintain high security and privacy standards, we have also implemented—and continue to implement—additional security enhancements to help prevent future fraud and illegal activities on our website,” the firm said in a statement.

Related Resource

The business guide to ransomware

Everything you need to know to keep your company afloat

The business guide to ransomware - whitepaper from DattoFree download

America’s second-largest auto insurance provider cautioned that fraudsters could use the driver’s license numbers to fraudulently apply for unemployment benefits.

“If you receive any mailings from your state’s unemployment agency/department, please review them carefully and contact that agency/department if there is any chance fraud is being committed,” the firm warned.

Geico admitted it didn’t know if any driver’s license number has been fraudulently used and added that it would offer affected customers a one-year subscription to IdentityForce to help protect against identity theft.

In addition to using the identity theft service, the firm urged customers to be vigilant for incidents of fraud or identity theft by reviewing account statements and credit reports for any unauthorized activity. If someone has received correspondence from a state government and hasn't filed for benefits, their data has likely been used illegally.

Last month, Chicago-based CNA Financial — another insurance firm — was hit by a cyber attack that left its website out of action and many network systems disrupted.

Featured Resources

Four strategies for building a hybrid workplace that works

All indications are that the future of work is hybrid, if it's not here already

Free webinar

The digital marketer’s guide to contextual insights and trends

How to use contextual intelligence to uncover new insights and inform strategies

Free Download

Ransomware and Microsoft 365 for business

What you need to know about reducing ransomware risk

Free Download

Building a modern strategy for analytics and machine learning success

Turning into business value

Free Download

Recommended

Dell Technologies World 2022: Dell unveils fastest storage architecture in company history
Server & storage

Dell Technologies World 2022: Dell unveils fastest storage architecture in company history

4 May 2022
Dell Technologies World 2022: Dell unveils security offerings for major cloud providers
public cloud

Dell Technologies World 2022: Dell unveils security offerings for major cloud providers

3 May 2022
How do you become an ethical hacker?
ethical hacking

How do you become an ethical hacker?

29 Apr 2022
What is phishing?
phishing

What is phishing?

29 Apr 2022

Most Popular

Windows Server admins say latest Patch Tuesday broke authentication policies
Server & storage

Windows Server admins say latest Patch Tuesday broke authentication policies

12 May 2022
16 ways to speed up your laptop
Laptops

16 ways to speed up your laptop

13 May 2022
How full-stack observability can accelerate IT innovation
Sponsored

How full-stack observability can accelerate IT innovation

3 May 2022