Jump to content

GEICO Third Party Data Leak Impacts 40000 employees, Could Your Data Be Next?

Summary

GEICO the second largest auto insurer in the united states, recently announced a third party data leak that has effected its 40,000 employees. The company notified employees that the MOVEit system was compromised "outside of GEICO's internal systems". GEICO uses MOVEit to send data via API to Delta Dental, Cinigia, and many other companies for employee benefits. Several employees have come forward saying that personal information such as Social Security Numbers, Address, Phone, Email, and Address have been found from credit searches on the Dark Web. 

 

Several individuals in the r/geico subreddit have claimed that GEICO neglected to protect the data in transit. The company has advised employees to freeze credit. 

 

Quotes

Quote

"We were recently made aware of a security issue involving MOVEit, a popular outside software program GEICO and many other businesses use to transfer data to third party vendors. We immediately implemented measures to address the issue and at this time, we have no indication that any compromises have accrued in GEICO systems. Our Cyber security team has been in close contact with outside vendors who also use this data transfer software and are closely monitoring with our partners to find out if any data they have from GEICO has been compromised, we will work to ensure they are sending out proper notification. Out of an abundance of caution, we recommend associates take action to prevent bad actors from attempting to use their personal information. One way to protect your personal information is by freezing your credit". 

 

My thoughts

This raises several questions about data security in the industry.

  1. Does this matter? In todays age 1 in 4 people will have some kind of identity theft happen. Is it reasonable to assume that all data is already compromised, if so should a company be held responsible at all? 
  2. Is a company responsible for ensuring the partners they share data with are following proper security standards? Should GEICO be held responsible for sharing employee data with a company not following proper standards?
  3. What rights/say should employees have when it comes to who a company shares data with? If a data is compromised in anyway, should employees be able to sue an employer for compensation? 
  4. Lets talk about the complexity for an individual maintaining their data, GEICO employees need to go through three different credit monitoring services and freeze accounts, what about SSN and other information. Who is responsible for ensuring that individuals have the tools to protect their own data. 

 

Sources

  • r/GEICO reddit
  • Current GEICO Employees
  • Experian Monitoring Report

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

So that means other users of MOVEit are also comprimised?

Specs: Motherboard: Asus X470-PLUS TUF gaming (Yes I know it's poor but I wasn't informed) RAM: Corsair VENGEANCE® LPX DDR4 3200Mhz CL16-18-18-36 2x8GB

            CPU: Ryzen 9 5900X          Case: Antec P8     PSU: Corsair RM850x                        Cooler: Antec K240 with two Noctura Industrial PPC 3000 PWM

            Drives: Samsung 970 EVO plus 250GB, Micron 1100 2TB, Seagate ST4000DM000/1F2168 GPU: EVGA RTX 2080 ti Black edition

Link to comment
Share on other sites

Link to post
Share on other sites

Obviously concerning but at this point 40k affected by a data breach is fairly unimpressive as these things go. The bigger concern is about MoveIt as a whole, since the potential this attack could be used against other customers if not patched quickly is obviously worrying

CPU: Core i9 12900K || CPU COOLER : Corsair H100i Pro XT || MOBO : ASUS Prime Z690 PLUS D4 || GPU: PowerColor RX 6800XT Red Dragon || RAM: 4x8GB Corsair Vengeance (3200) || SSDs: Samsung 970 Evo 250GB (Boot), Crucial P2 1TB, Crucial MX500 1TB (x2), Samsung 850 EVO 1TB || PSU: Corsair RM850 || CASE: Fractal Design Meshify C Mini || MONITOR: Acer Predator X34A (1440p 100hz), HP 27yh (1080p 60hz) || KEYBOARD: GameSir GK300 || MOUSE: Logitech G502 Hero || AUDIO: Bose QC35 II || CASE FANS : 2x Corsair ML140, 1x BeQuiet SilentWings 3 120 ||

 

LAPTOP: Dell XPS 15 7590

TABLET: iPad Pro

PHONE: Galaxy S9

She/they 

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, Spoon1998 said:

Does this matter? In todays age 1 in 4 people will have some kind of identity theft happen. Is it reasonable to assume that all data is already compromised, if so should a company be held responsible at all? 

Honestly the best thing for everyone to do is put a credit freeze in at all the credit bureaus. This prevents shit from being opened in your name. Prevents credit reports from being ran by 3rd parties, as long as you dont already do business with them. This is what I did after Equifax leaked my info. Another thing to consider is that Equifax did leak like 50% of the Social Security numbers in the US, so......... at least half the country was compromised. Personally I think its time that the "Social Security numbers" stop being used as an identity, we need a better system. 

I just want to sit back and watch the world burn. 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Donut417 said:

Honestly the best thing for everyone to do is put a credit freeze in at all the credit bureaus. This prevents shit from being opened in your name. Prevents credit reports from being ran by 3rd parties, as long as you dont already do business with them. This is what I did after Equifax leaked my info. Another thing to consider is that Equifax did leak like 50% of the Social Security numbers in the US, so......... at least half the country was compromised. Personally I think its time that the "Social Security numbers" stop being used as an identity, we need a better system. 

But since there is o “new” system to replace the Social Security Numbers system, then wouldn’t the employees be subject to identity fraud?

I like computers. And watching them blow up while playing GTA 5. Remember to update to Windows 11! 😁 

Forum Member

Spoiler

Brroooooo spiders are the only web developers that enjoy finding bugs.

Forum Member Definition:

 

A person who participates on an internet forum. Also called a forumite. So why does the word forumite remind me of a species of mites?

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, EllieCat said:

But since there is o “new” system to replace the Social Security Numbers system, then wouldn’t the employees be subject to identity fraud?

To an extent. If people are smart like me they have their credit frozen. Which makes it harder to do things for both a criminal and for the person itself. 

I just want to sit back and watch the world burn. 

Link to comment
Share on other sites

Link to post
Share on other sites

6 hours ago, Donut417 said:

To an extent. If people are smart like me they have their credit frozen. Which makes it harder to do things for both a criminal and for the person itself. 

What happens if they don’t freeze their credit? Also, can’t they just get a new credit card?

I like computers. And watching them blow up while playing GTA 5. Remember to update to Windows 11! 😁 

Forum Member

Spoiler

Brroooooo spiders are the only web developers that enjoy finding bugs.

Forum Member Definition:

 

A person who participates on an internet forum. Also called a forumite. So why does the word forumite remind me of a species of mites?

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, EllieCat said:

What happens if they don’t freeze their credit? Also, can’t they just get a new credit card?

A credit freeze prevents companies who you haven't done business with from running a credit report, which is needed to open any type of accounts and such. So if you dont freeze it and they get your social security number and have your name and a few details which are easy to find they can open all kinds of accounts in your name. 

I just want to sit back and watch the world burn. 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×