STATE AUTOMOBILE MUTUAL INSURANCE COMPANY
bd_bcf0a02dc0fed2cc · schema v1 · pii pii-v1
Full breach record for STATE AUTOMOBILE MUTUAL INSURANCE COMPANY →3 incidents on fileState Automobile Mutual Insurance Company experienced an incident between March 11 and March 31, 2021, where an unknown actor abused the company's auto insurance quote application process. By initiating quotes using addresses not obtained from State Auto, the actor triggered a prefill process that exposed personal information including names, driver's license numbers, dates of birth, and gender. The company engaged a cybersecurity firm, notified law enforcement, and offered one year of identity monitoring via Kroll. No malware or ransomware was involved; the breach resulted from the exploitation of a public-facing application feature.
J jump to incidentP pin to compareR raw source
Incident timeline
Mar 11, 2021
Begins
Mar 31, 2021
Discovered
May 11, 2021
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Indiana State AGbd_063145b1e7120cc52021-05-11Verified
- New Hampshire State AGbd_9f3fb01b2b22ea642021-05-11Verified
- Massachusetts State AGbd_cba70427b2a6afb92021-05-11Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.