New York state sued Allstate accusing the insurer’s National General unit of failing to report a data breach that exposed drivers’ license numbers, and lacking reasonable safeguards to protect drivers’ private information. From Reuters:
The lawsuit by New York Attorney General Letitia James was filed in a state court in Manhattan.
James said National General’s poor data security led to back-to-back breaches in 2020 and 2021, when hackers targeting its online auto insurance quoting tools accessed license numbers of more than 165,000 New Yorkers and 199,000 people overall.
National General allegedly did not notify drivers or New York state agencies about the first breach, which occurred between August and November 2020, and needed three months to uncover the much larger second breach in January 2021.
James said National General violated the state’s Stop Hacks and Improve Electronic Data Security Act for failing to protect customer information, and violated state consumer protection laws by misleading customers about its data security practices.
The lawsuit seeks civil fines of $5,000 per violation, plus other remedies.
“National General’s weak cybersecurity emboldened hackers to steal New Yorkers’ personal data, not once but twice,” James said. “It is crucial that companies take cybersecurity seriously to protect consumers from fraud and identity theft.”
Erich Kron, security awareness advocate at cybersecurity company KnowBe4, commented:
“As organizations gather more and more information about individuals, the risk of data breaches continues to grow. For many people it feels as if every week contains some sort of news about a significant data breach, and in many cases these people are getting a bit of breach fatigue. Unfortunately, it seems that the amount of data around each person that is being lost in these breaches continues to grow, so it’s no longer just a name, address, and maybe a credit card number or phone number, but now a lot more personal information is included.
“Insurance organizations are well known for collecting and using credit information to influence rates, and to check credit they need to collect some rather sensitive data such as Social Security numbers. In addition, insurers are asking customers to install telemetry devices in their vehicles, or through their phone apps, to track their location, speed, time of driving, braking and acceleration data, and a laundry list of other bits of data that most people would probably prefer remains private.
“Given the amount of information collected, it is extremely discouraging to see organizations try to cover up breaches or fail to notify victims of breaches in a timely manner. By failing to notify the victims, bad actors can use the stolen data against the customers in a number of ways. One easy way a bad actor could use this against a customer is to contact them while pretending to be from the insurance company, then convincing them that they need to pay a bill, or that their bill has gone up due to their driving behaviors. If the scammer can reference a time and date when that person was actually driving the vehicle, it could have the effect of convincing the victim that this really is the insurance company contacting them, and that they need to pay this additional fee or have their insurance dropped.
“While we still seem to concern ourselves when Social Security numbers and other information like that is stolen, organizations seem not to value this other information in the same way, however it can be used against their customers easily. When a data breach occurs, organizations should contact the victims whose data has been stolen and provide them advice in a timely and actionable way. If
I have one word to say on this.
Good!
The thing is that some companies will only take cybersecurity seriously if the financial penalties and reputational damage are greater than covering up an incident. This is something that is proven to work in the EU. And it’s about time that that this approach is seen here in North America.


MeetingTV lawsuit highlights growing risks around AI-assisted threat intelligence
Posted in Commentary with tags Lawsuit on June 29, 2026 by itnerdThe MeetingTV lawsuit highlights a difficult reality in cybersecurity: once a domain or service is flagged as malicious, that designation can quickly spread across dozens of security products and become incredibly hard to undo. Whether AI was involved or not, the case shows the need for security vendors to have clear processes for validating findings, correcting mistakes, and ensuring legitimate organizations aren’t caught in the fallout.
You can catch up here: MeetingTV lawsuit
Eljan Mahammadli, Head of AI Provenance, Polygraf AI
“What stands out to me here isn’t the hallucination accusation, because the filings don’t actually prove a model wrote that finding, and that uncertainty is the whole problem. When threat intelligence ships without a record of how each conclusion was reached, nobody can audit it afterward, not the researchers and definitely not the company on the receiving end. A bad attribution takes seconds to publish and spreads across hundreds of blocklists almost immediately, but reversing it takes months, if it happens at all. That asymmetry is what the industry should be worried about, whether or not AI touched the report. If we’re going to let models do attribution work, the output has to carry its own evidence chain, so a finding can be contested on the record instead of in court.”
Gidi Cohen, CEO & Co-founder, Bonfy.AI
“The MeetingTV lawsuit should be a wake-up call: when threat intelligence is generated or enriched by AI, the stakes are no longer just about technical accuracy—they’re about business continuity and reputational harm for real companies caught in the blast radius.
This case highlights three responsibilities that security leaders and researchers can’t ignore:
Regardless of the legal outcome, the lesson is straightforward: if we use AI in security research, we must pair it with rigorous review, transparent methodology, and fast, industry-wide remediation when we get it wrong. Without that, AI doesn’t just help us find threats—it risks becoming one.”
Consider this a warning for organizations. Review everything that and AI does or end up in court. It truly is that simple when it come to either doing the review, or defending it in court.
Leave a comment »