Insurance Cybersecurity Failures Result in More Than $21 Million in Penalties
- John C. Blackshire, Jr.

- 5 hours ago
- 3 min read
Recent enforcement actions demonstrate that cybersecurity compliance is a serious financial and regulatory concern for insurance organizations.
Between October 2025 and April 2026, the New York State Department of Financial Services imposed more than $21 million in penalties against ten insurance entities for cybersecurity control failures.
Eight Insurance Organizations Fined More Than $19 Million
On October 14, 2025, the Department announced settlements with eight automobile insurance organizations:
Farmers Insurance Exchange — $2.775 million
Hagerty Insurance Agency, LLC — $1.85 million
Hartford Fire Insurance Company — $3 million
Infinity Insurance Company — $2.25 million
Liberty Mutual Insurance Company — $2.7 million
Metromile Insurance Company — $2.05 million
Midvale Indemnity Company — $2 million
State Automobile Mutual Insurance Company — $2.5 million
According to the Department, weaknesses in the organizations’ cybersecurity controls allowed attackers to obtain driver’s-license numbers, dates of birth, and other consumer information through public-facing automobile insurance quoting applications and agent portals.
Farmers and Infinity were also cited for failing to report their cybersecurity events promptly.
In addition to paying approximately $19.125 million in penalties, the organizations agreed to take corrective actions, including reviewing how consumer nonpublic information could be accessed through their systems.
Delta Dental Assessed a $2.25 Million Penalty
On April 30, 2026, the Department announced a separate $2.25 million settlement with
Delta Dental Insurance Company and Delta Dental of New York.
Attackers exploited a vulnerability in the companies’ MOVEit Transfer software and obtained access to files containing:
Social Security numbers
Driver’s-license numbers
Financial-account information
Patient health information
Names and addresses
The Department identified deficiencies involving incident-response policies, data-retention settings, security controls, and regulatory reporting. The companies were also cited for failing to report their cybersecurity events promptly.
What These Enforcement Actions Mean for Insurance Organizations
These cases were enforced under New York’s cybersecurity regulation, 23 NYCRR Part 500, rather than a state law specifically identified as an adoption of the NAIC Insurance Data Security Model Law. However, the regulatory expectations overlap significantly.
Insurance organizations are expected to:
Maintain a risk-based information security program.
Protect consumer nonpublic information.
Conduct periodic cybersecurity risk assessments.
Implement effective administrative, technical, and physical controls.
Manage third-party cybersecurity risks.
Maintain and test an incident-response plan.
Investigate and report cybersecurity events promptly.
Provide meaningful board and senior-management oversight.
Support annual compliance certifications with reliable evidence.
Cybersecurity cannot be treated solely as an IT responsibility. It is also a governance, compliance, risk-management, and internal-control responsibility.
Questions Management and the Board Should Ask
Insurance executives, board members, audit committees, and internal auditors should consider the following questions:
What nonpublic information does the organization collect and retain?
Which public-facing applications provide access to that information?
When was the last cybersecurity risk assessment completed?
Have all significant vulnerabilities been corrected?
Which third-party providers have access to sensitive information?
Has the incident-response plan been tested?
Are state notification requirements documented?
Can management support its annual cybersecurity certification?
Has internal audit evaluated the design and operating effectiveness of the cybersecurity controls?
The absence of a known breach does not prove that an information security program is effective.
Learn How to Strengthen Your Cybersecurity Compliance Program
Corporate Compliance Seminars will present the NAIC Cybersecurity Model Law Academy on Wednesday and Thursday, September 30–October 1, 2026.
This live, interactive webinar provides 12 CPE credits and addresses:
NAIC Insurance Data Security Model Law requirements
Cybersecurity risk assessments
Information security programs
Protection of nonpublic information
Board oversight responsibilities
Third-party service-provider controls
Incident-response planning
Cybersecurity-event reporting
Continuous monitoring
Annual certification requirements
Cybersecurity maturity assessments
Comparison with New York’s cybersecurity regulation
SOC for Cybersecurity concepts
The academy is designed for insurance executives, auditors, compliance officers, risk managers, cybersecurity professionals, information technology managers, board members, and other professionals responsible for protecting insurance information.
The recent penalties send a direct message: cybersecurity policies are not enough. Insurance organizations must be able to demonstrate that their controls are properly designed, consistently performed, monitored, tested, and improved.
Comments