HackingVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Hagerty Insurance Agency, LLC
bd_b1562bb773105c26 · schema v1 · pii pii-v1
Full breach record for Hagerty Insurance Agency, LLC →Hagerty Insurance Agency, LLC disclosed that automated bots exploited a vulnerability in its public-facing 'Instant Quote' feature to access personal information, including names, driver's license numbers, and dates of birth, embedded in the webpage source code. The incident was detected on February 2, 2021, when suspicious quote activity was observed. Hagerty immediately deployed mechanisms to block bot activity and contained the incident. Affected individuals were offered 12 months of complimentary identity theft protection through Experian.
California clockDiscovered Feb 2, 2021 → Notified Mar 23, 202149d ✓ CA 60-day OK7 weeks discovery → filing
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b16e684014a06129Maine State AGfiled 2021-03-26(3d gap)Candidate
- bd_083cd91b97919bf7Montana State AGfiled 2021-04-13(21d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-539374
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 23, 2021
- Raw hash
- 6dc28ac7714bf9ed57d71ab7901bf0958c64edc55a4be9144b52dc2379629d4a
Reporting entity
- Name
- Hagerty Insurance Agency, LLCnorm: hagerty insurance agency
Victim entity
- Name
- Hagerty Insurance Agency, LLCnorm: hagerty insurance agency
Incident
- Discovered
- Feb 2, 2021
- Materiality determined
- —
- Notification sent
- Mar 23, 2021
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 49d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 2, 2021→ Notified: Mar 23, 202149d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.