Stay in the know
Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead
On October 14, 2025, New York’s Department of Financial Services (DFS) fined eight auto insurance companies for violating its cybersecurity regulations (known as “Part 500”). The fines come as recent amendments to Part 500 are set to take effect.
In early 2021, eight auto insurance companies suffered data breaches. The leaked data included driver’s license numbers and dates of birth, accessed through a third-party data prefill service that facilitated the insurance quoting process for consumers. DFS notified consumers of the breaches via public alerts in February and March 2021. After investigating, DFS found the insurance companies failed to maintain written cybersecurity programs and failed to effectively implement or update their cybersecurity policies. DFS also found the companies failed to use effective controls to protect against data breaches or conduct periodic risk assessments and that some insurance companies had failed to notify DFS within 72 hours of the breaches as required under Part 500.
It is worth noting that these fines come more than four years after the initial breaches, signaling DFS’ willingness to investigate and hold entities accountable well after the initial breach has been discovered and remediated. The fines also come as amendments to Part 500 take effect November 1, 2025. Under the amendments, regulated companies must comply with enhanced multifactor authentication guidelines for accessing internal networks and implement written policies and procedures to maintain a complete, accurate, and documented asset inventory of their information systems.
Former DFS Superintendent Adrienne Harris stated that the fines “demonstrate the Department’s unwavering commitment to holding institutions accountable when they fail to meet these robust standards, and to ensuring that consumers remain protected from data breaches and other cyber risks.”
Please contact HSF Kramer’s Data Protection and Privacy Group for more information.
The contents of this publication are for reference purposes only and may not be current as at the date of accessing this publication. They do not constitute legal advice and should not be relied upon as such. Specific legal advice about your specific circumstances should always be sought separately before taking any action based on this publication.
© Herbert Smith Freehills Kramer 2026
Receive timely insights and briefings from HSF Kramer, tailored to keep you informed and ahead