HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Government Employees Insurance Company
bd_af2081ccb7c13d31 · schema v1 · pii pii-v1
Full breach record for Government Employees Insurance Company →Government Employees Insurance Company (GEICO) reported a data breach occurring between January 21, 2021, and March 1, 2021. Fraudsters used information acquired elsewhere to gain unauthorized access to victims' driver's license numbers through GEICO's online sales system. The data obtained was limited to driver's license numbers, which could be used to fraudulently apply for unemployment benefits. GEICO secured the website, identified the root cause, and offered one year of IdentityForce identity-theft protection to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_1312497476f416bcMaine State AGfiled 2021-04-13(2d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539989
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 15, 2021
- Raw hash
- 9d914240e164b3162f88d2243299bd24d4544c1062226a652b7e8445193d9248
Reporting entity
- Name
- Government Employees Insurance Companynorm: government employees insurance
Victim entity
- Name
- Government Employees Insurance Companynorm: government employees insurance
Incident
- Discovered
- Mar 1, 2021
- Materiality determined
- Apr 9, 2021
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(45 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.