Threat actors are stealing information by taking advantage of the application design and code of websites that provide instant quotes for auto insurance rates, the New York Department of Financial Services (NYDFS) reported in March. This personal information theft was first announced on Feb. 16 and is ongoing, they said.

Read on to learn about what these techniques entail and how this campaign continues to evolve.

Two Tactics of Personal Information Theft

NYDFS received reports of two new attack techniques. In the first, threat actors used web debugging tools to steal private personal information. They were able to grab it as it traveled from a data service provider to the instant quote website.

Those tools enabled the attackers to do two things. First, they could inspect web pages and sessions on those websites, as well as monitor data service providers’ application programming interface (API) calls for customer data. Next, attackers could carry out the personal information theft in XML and/or JSON file formats. These included a requester’s driver’s license number along with the state that issued it.

As for the second tactic, threat actors used credential stuffing to gain access to insurance agents’ accounts. They used those accounts to enter the web portals of instant quote websites. From there, they made API calls to data service providers. This way, they gained access to New Yorkers’ driver’s license numbers and other nonpublic information.

Part of a Broader Financial Services Cybersecurity Threat

According to an alert released by the department in mid-February, auto insurers first noticed the personal information theft around the beginning of the year when they observed a large number of abandoned auto insurance quotes.

The attackers had entered a person’s name, date of birth and address into the required fields on an instant quote website. From there, they received an instant quote that contained partial or redacted personal information, including the driver’s license number. The attackers stole the number without proceeding any further with the quote.

In some cases, the attackers used ‘vishing’ to trick insurance agents into providing sensitive information over the phone. Other times, they used eChecks or stolen payment card numbers to purchase insurance policies in other people’s names. From there, they could view the policyholders’ driver’s license numbers and commit other personal information theft.

This also enabled the attackers to commit identity theft. For at least some of the cases reported to NYDFS, the attackers conducted benefits fraud, submitting fake claims for pandemic and/or unemployment benefits.

How to Defend Against Personal Information Theft

This attack campaign highlights the need for financial services groups and other entities to protect their customers from personal information theft. One of the ways they can do this is by improving access controls for insurance agent portals. They can implement the principle of least privilege to limit which network assets their insurance agents can access, for example. When combined with network segmentation, this security measure can help prevent attackers from moving to parts of the network that contain users’ sensitive information.

Businesses should also make sure their insurance agents and employees are familiar with scams. A security awareness training program can educate the workforce about credential stuffing attacks, vishing attempts and some of the other techniques used in personal information theft.

More from News

More School Closings Coast-to-Coast Due to Ransomware

Instead of snow days, students now get cyber days off. Cyberattacks are affecting school districts of all sizes from coast-to-coast. Some schools even completely shut down due to the attacks. The federal government recently warned that K-12 schools face a growing threat from cyber groups. According to the FBI, school districts often have limited cybersecurity protections, which makes them even more vulnerable. The FBI also says it anticipates the number of threats to increase. In a recent warning, the nation’s…

Hackers are Increasingly Targeting Auto Dealers

Auto dealerships are increasingly concerned with cybersecurity in the face of new regulations and an alarming rise in cyberattacks. The Second Annual Global State of Cybersecurity Report by CDK Global found that 85% of dealerships say cybersecurity is very or extremely important relative to other operational areas. Additionally, 89% say cybersecurity is more important than last year, a 12% increase. Not surprisingly, only 37% of auto retailers are confident in the current protection, which is a 21% decrease from 2021.…

LastPass Breaches Cast Doubt on Password Manager Safety

In 2022, LastPass suffered a string of security breaches which sparked concern among cyber professionals and those impacted by the intrusions. Some called into question the way LastPass handled and responded to the incident. In addition, the situation ignited a wider conversation about the risks linked to utilizing password managers. A password manager helps users generate strong passwords and safeguards them within a digital locker. A master password secures all data, which enables users to conveniently access all their passwords…

Good Guys Decrypt Ransomware Targeting Charitable Groups

Imagine you’re an IT manager amid a ransomware attack. While your team scrambles for solutions, the intruders demand a ransom. Of course, you don’t want to pay; you just want your files back. But as time ticks by and the extortionists turn up the heat, your bosses are about to give in and pay the ransom. But then, the FBI calls. “Don’t pay,” the agent says. “We’ve found someone who can crack the encryption.” Sound too good to be true?…