Root Insurance Company
bd_85acd966d160016f · schema v1 · pii pii-v1
Full breach record for Root Insurance Company →Root Insurance Company identified unusual account creation patterns on January 28, 2021, with activity believed to have started in the preceding week. Attackers created accounts for individuals with no prior relationship to Root using names and dates of birth not obtained from Root to generate insurance quotes. This triggered an application prefill process that populated driver's license numbers, dates of birth, and vehicle information (VIN, year, make, model) in the accounts. Root notified law enforcement, stopped suspicious quote/purchase activity, and implemented additional security measures. Affected individuals were offered one year of Experian IdentityWorks.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 21, 2021
Begins
Jan 28, 2021
Discovered
Mar 4, 2021
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Massachusetts State AGbd_108945293c4ba47e2021-02-25 · +7dVerified
- Oregon State AGbd_879e103d750318882021-02-25 · +7dCandidate
- Indiana State AGbd_924ef0a67e8395ec2021-02-25 · +7dVerified
- Illinois State AGbd_b0cc160cb1beb7572021-01-01 · +62dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Mar 4 (CA) — a 62-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.