MAPFRE Insurance faces lawsuit for data breach - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.ā„¢

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Top Stories
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be anĀ INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Top Stories
Top Stories RSS Get our newsletter
Order Prints
September 19, 2023 Top Stories
Share
Share
Tweet
Email

MAPFRE Insurance faces lawsuit for data breach

Image of a landscape with an overlay of digital icons, with the words "MAPFRE Insurance" superimposed.
By Doug Bailey
MAPFRE Insurance, which writes property and casualty insurance in 19 US states, was hit with a data breach in July impacting more than 300,000 of its customers and is now facing a federal lawsuit seeking class action status alleging negligence and violations of privacy regulations.
The company, based in Webster, Mass., has been somewhat tightlipped about the incident but in a letter sent to customers sent at the end of August, MAPFRE said the data breach occurred between July 1 and July 2, and involved ā€œan unknown partyā€ obtaining access to driver’s license numbers through its online quoting platform.
ā€œThe unknown party may also have obtained access to information regarding vehicles you own, including make, model, year, and vehicle identification number,ā€ the letter stated.
MAPFRE said it took down the online quoting platform as soon as it became aware of the breach and implemented additional controls within the system to prevent a reoccurrence of the incident.
In a statement, the company said ā€œan unknown party used information about certain individuals – which was already in the unknown party’s possession – to obtain access to additional information through mapfreinsurance.com. The company has not responded to questions about how the ā€œunknown partyā€ apparently already had customer login information.

Security testing conducted

In a subsequent statement, MAPFRE said it retained an independent third-party, which it declined to identify, to conduct security testing of the platform before bringing it back online.
ā€œThe Company’s Agent Portal was not involved,ā€ the insurer said.
MAPFRE declined to provide a spokesperson to respond to questions about the incident.
MAPFRE, a Spanish-headquartered multinational insurer, purchased Massachusetts-based Commerce Insurance in 2007. It is certainly not alone in being victimized by cyber criminals and such incidences are becoming almost common. Recent reports say third-party data breaches rose 136% last year, particularly affecting insurers, healthcare organizations, utilities, retail chains and many others.
ā€œMost large organizations connect and share data with dozens of partners and vendors,ā€ said a report by cybersecurity company ForgeRock. ā€œBut a compromised login credential in any one of those companies can put all the others at risk.ā€

Cyberattack frequency no excuse, say attorneys

Attorneys for impacted consumers say, however, that the frequency of cyberattacks is no excuse for companies allowing them to happen.
ā€œWhile the exact reason(s) for the data breach remain unclear, there is no doubt
that [MAPFRE] failed to adequately protect [customers’] private information
and incorporate the tools necessary to keep such private information safe,ā€ reads a lawsuit filed early this month in US District Court of Massachusetts, by two customers of the insurer that is seeking class action status. ā€œSuch negligent failures resulted in injuriesā€¦ā€
The lawsuit seeks unspecified damages for MAPFRE’s alleged failure to exercise reasonable care in securing and safeguarding the sensitive consumer data.
ā€œTo the world of cyber criminals, MAPFRE’s private information, including data that was in possession at the time of the data breach, is extremely valuable,ā€ reads the lawsuit, filed by attorneys at Watley Kallas LLP, in Boston, and Migliaccio & Rathod LLP, in Washington, DC. ā€œBy accessing plaintiffs’ private information, hackers can simply use a driver’s license to steal identities. Stolen driver’s licenses wreak havoc and identity theft issues for MAPFRE potential customers and customers.ā€
The suit alleges there was a long delay in notifying customers of the data breach, giving more time for hackers to copy sensitive information that included names, driver’s license numbers, make, model, year, and vehicle identification numbers.
The suit cites a national credit reporting blogger, about the value of driver’s license to thieves.
ā€œIf someone gets your driver’s license number, it is also concerning because it’s connected to your vehicle registration and insurance policies, as well as records on file with the department of motor vehicles, place of employment, doctor’s office, government agencies, and other entities,ā€ said the blogger, Sue Poremba. ā€œHaving access to that one number can provide an identity thief with several pieces of information they want to know about you. Next to your Social Security number, your driver’s license is one of the most important pieces to keep safe from thieves.ā€
With a driver’s license number, bad actors can manufacture fake IDs, slotting in the number for any form that requires ID verification or use the information to craft curated social engineering phishing attacks,ā€ said Tim Sadler, CEO of email security firm Tessian.

A 'lucrative' scam

ā€œUsing these numbers to fraudulently apply for unemployment benefits in someone else’s name is a scam proving especially lucrative for hackers as unemployment numbers continue to soar,ā€ he said. ā€œIn other cases, a scam using these driver’s license numbers could look like an email that impersonates the DMV, requesting the person verify their driver’s license number, car registration or insurance information, and then inserting a malicious link or attachment into the email.ā€
MAPFRE has offered complimentary credit monitoring for a year that includes theft resolution services and $1 million in identity theft insurance. The company has denied the allegations in the complaint and said it will vigorously defend the lawsuit, which it said contains ā€œmany inaccuracies,ā€ which it has not specified.
The 46-page complaint alleges seven counts of alleged transgressions including violation of the Drivers’ Privacy Protection Act, negligence, breach of contract, breach of implied contract, unjust enrichment, breach of fiduciary duty, and appeal for injunctive relief.
The suit alleges MAPFRE’s data-security measures remain inadequate even after the recent incident.
ā€œEven if every employee is trained in security best practices, just one accidental click on a malicious link in a legitimate-looking email can open the door to an intruder,ā€ said the recent data breach report from ForgeRock. ā€œAccounts can be taken over, data stolen, and systems brought down. The results can be devastating and far-reaching for the organization, its customers, and other companies it shares data with. Still, from the intruder’s standpoint, it only takes one compromised identity.ā€
The report said the number of breached records reported in 2022 was actually the lowest in five years having dropped by more than half: 1.5 billion in 2022 as opposed to an average of 3.9 billion over the past four years.
ā€œBut looks can be deceiving,ā€ it said, ā€œa closer analysis reveals that while the number of breached records is lower, the records stolen contain more highly sensitive identity data that can result in longer-term damage.ā€
Attacks targeting organizations through third-party service providers accounted for 52% of all breaches, the report said, illustrating the interconnectedness of identities. Healthcare and education emerged as the most vulnerable industry sectors.

Doug Bailey is a journalist and freelance writer who lives outside of Boston. He can be reached atĀ [email protected].

Ā© Entire contents copyright 2023 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.

Doug Bailey

Doug Bailey is a journalist and freelance writer who lives outside of Boston. He can be reached at [email protected].

Older

Low financial literacy may be costing consumers money

Newer

U.S attorney alleges obstruction, seeks stiffer sentence for ‘Annuity King’

Advisor News

  • Estate planning during the great wealth transfer
  • Main Street families need trusted financial guidance to navigate the new Trump Accounts
  • Are the holidays a good time to have a long-term care conversation?
  • Gen X unsure whether they can catch up with retirement saving
  • Bill that could expand access to annuities headed to the House
More Advisor News

Annuity News

  • Insurance Compact warns NAIC some annuity designs ā€˜quite complicated’
  • MONTGOMERY COUNTY MAN SENTENCED TO FEDERAL PRISON FOR DEFRAUDING ELDERLY VICTIMS OF HUNDREDS OF THOUSANDS OF DOLLARS
  • New York Life continues to close in on Athene; annuity sales up 50%
  • Hildene Capital Management Announces Purchase Agreement to Acquire Annuity Provider SILAC
  • Removing barriers to annuity adoption in 2026
More Annuity News

Health/Employee Benefits News

  • Bill would remove BMI from state health standards
  • Nebraska Farm Bureau rolls out its own health plan
  • Mass. seeing more people drop health insurance
  • LTCi: Why some coverage is better than none at all
  • GOVERNOR HEALEY DEMANDS THAT CONGRESSIONAL REPUBLICANS VOTE TO EXTEND ACA CREDITS TO PREVENT HUGE SPIKES IN HEALTH CARE COSTS
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • Judge tosses Penn Mutual whole life lawsuit; plaintiffs to refile
  • On the Move: Dec. 4, 2025
  • Judge approves PHL Variable plan; could reduce benefits by up to $4.1B
  • Seritage Growth Properties Makes $20 Million Loan Prepayment
  • AM Best Revises Outlooks to Negative for Kansas City Life Insurance Company; Downgrades Credit Ratings of Grange Life Insurance Company; Revises Issuer Credit Rating Outlook to Negative for Old American Insurance Company
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Slow Me the Money
Slow down RMDs … and RMD taxes … with a QLAC. Click to learn how.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

Press Releases

  • ePIC University: Empowering Advisors to Integrate Estate Planning Into Their Practice With Confidence
  • Altara Wealth Launches as $1B+ Independent Advisory Enterprise
  • A Heartfelt Letter to the Independent Advisor Community
  • 3 Mark Financial Celebrates 40 Years of Partnerships and Purpose
  • Hexure Launches AI Enabled Version of Its Platform to Power Life Insurance Sales
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
Ā© 2025 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet