Unum And Paul Revere Life Insurance Cos. To Pay $1.8M Penalty For Cybersecurity Violations
New York Superintendent of Financial Services Linda A. Lacewell announced that First Unum Life Insurance Company of America and Paul Revere Life Insurance Company will pay a $1.8 million penalty to New York State for violations of DFS’s Cybersecurity Regulation that caused the exposure of a substantial amount of sensitive, non-public, personal data belonging to its customers, including thousands of consumers nationally and hundreds in New York.
“The Department requires all regulated licensees to prioritize cybersecurity and safeguard consumer personal, non-public data,” said Superintendent Lacewell. "The cornerstone of our Cybersecurity Regulation is ensuring that all private data is protected, and this is not just an aspirational goal. We remain committed to ensuring that cybersecurity is treated with the urgency it requires so as to best protect New York consumer data.”
The Companies, licensed life insurance companies, collect private data during their day-to-day operations. The Department’s investigation found that the Companies had been the subject of two phishing attacks in 2018 and 2019.
These cyberattacks, which involved phishing e-mails designed to harvest employee e-mail account credentials, compromised the email accounts of several First Unum and Paul Revere employees, who have access to a significant amount of sensitive and personal data of the Companies’ customers.
The investigation uncovered, among other things, that First Unum and Paul Revere violated the DFS Cybersecurity Regulation by failing to implement Multi-Factor Authentication (“MFA”) without implementing reasonably equivalent or more secure access controls approved in writing by the Company’s Chief Information Security Officer. Further, both First Unum and Paul Revere falsely certified compliance with the Cybersecurity Regulation for the calendar year 2018 because MFA was not fully implemented.
As part of the settlement, the Companies agreed to pay a $1.8 million monetary penalty and to implement further improvements to their existing cybersecurity program to ensure that their cybersecurity controls are fully compliant with the Cybersecurity Regulation.
DFS’s Cybersecurity Regulation became effective in March 2017. The Cybersecurity Regulation was drafted with substantial industry input: DFS surveyed nearly 200 regulated banking institutions and insurance companies, met with a cross-section of those surveyed and cybersecurity experts during the drafting period, and granted two rounds of notice and comment. Additional implementation time was granted for multiple provisions, and the regulation was not fully in effect until March 2019.
DFS’s Cybersecurity Regulation has served as a model for other regulators, including the Federal Trade Commission, multiple states, the National Association of Insurance Commissioners, and the Conference of State Bank Supervisors.


Consumer Reps: Insurers Use ‘Bad Faith’ On Underwriting Definitions
Investors Want More Comp Clarity, But 3 of 4 Don’t Get It
Advisor News
- A hybrid approach outperforms the 4% Rule, researchers find
- The missing piece in most retirement plans
- Clients are bringing TikTok insurance advice into advisor meetings
- Embracing a family-centric approach to financial planning
- Family communication: Financial planning’s growing blind spot
More Advisor NewsAnnuity News
- The Manhattan Life Insurance Company Acquires Union Security Life Insurance Company of New York
- Cayman Islands premier to meet with U.S. reinsurance regulators
- Investigation finds deceptive sales, churning of annuities targeting postal workers
- Corebridge annuity sales slip ahead of Equitable marriage
- California teachers settle class-action lawsuit over in-plan annuity fees
More Annuity NewsHealth/Employee Benefits News
- Healey announces campaign to help residents hold onto their healthcare coverage
- Reports from Duke University Describe Recent Advances in Managed Care (The South Had the Lowest Rates of Hospice and Palliative Medicine-certified Providers In the Us, 2024): Managed Care
- Recent Findings in Managed Care Described by Researchers from University of Washington (Improving Dental Care Access for Medicaid-enrolled Adults Through a Dental Clinic Co-located Within a Rural Health Center: a Mixed-methods Study): Managed Care
- Researchers from University of Michigan Report Recent Findings in Managed Care (Interhospital Variation in 180-Day Infections and Associated Medicare Spending after Cardiac Surgery): Managed Care
- Findings from Hannover Medical School in the Area of Clinical Trial Research Described [Clinical-pharmacological Medication Reviews for Insurants of a German Statutory Health Insurance Fund (<i>kaufmannische Krankenkasse</i> (Kkh)): a 5-year …]: Clinical Trial Research
More Health/Employee Benefits NewsProperty and Casualty News
- Judy Griffin: Combating escalating costs on Long Island
- U.S. News & World Report Announces Winners of the 2026-2027 Pet Insurance Awards
- Newsom makes last-minute push to help California utilities facing wildfire bills
- AM Best Upgrades Credit Ratings of California Casualty Group Members
- NEW YORK STATE DEPARTMENT OF FINANCIAL SERVICES ANNOUNCES $15.5 MILLION MULTI-STATE SETTLEMENT WITH MORTGAGE SERVICER
More Property and Casualty News