HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICPIIMediumContained
Root Insurance Company
bd_85acd966d160016f · schema v1 · pii pii-v1
Full breach record for Root Insurance Company →Root Insurance Company experienced a data breach between January 21 and 28, 2021, where unauthorized actors created fake insurance accounts using stolen names and driver's license numbers. The breach exposed driver's license numbers, dates of birth, and vehicle information for individuals who attempted to get quotes. Root notified law enforcement, engaged Experian for credit monitoring, and secured its application process.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_879e103d75031888Oregon State AGfiled 2021-02-25(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-538890
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 4, 2021
- Raw hash
- 44d8c88490b6bfa6387d53e3d1ad7639f4d6aea082b429cb9170d9d90324a4a2
Reporting entity
- Name
- Root Insurance Companynorm: root insurance
Victim entity
- Name
- Root Insurance Companynorm: root insurance
Incident
- Discovered
- Jan 28, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICPII
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.