Allstate’s Web Blunder: How Not to Secure Data, a Comedy of Errors Unfolds

New York State has slapped Allstate Insurance with a lawsuit for running websites so poorly designed they practically invited fraudsters in for a cup of tea and a driver’s license number. Apparently, “password123” wasn’t cutting it. Allstate’s National General unit allegedly prioritized profit over reasonable data security safeguards.

Pro Dashboard

Hot Take:

If Allstate’s websites were houses, they’d have been built without doors, windows, or walls – just wide-open spaces inviting everyone to take a stroll through your personal data. Who knew getting an insurance quote could lead to such a ‘drive-thru’ experience for identity thieves?

Key Points:

  • New York State sues Allstate for poorly designed websites leaking personal data.
  • Driver’s license numbers were exposed in plain text during insurance quote processes.
  • Hackers exploited the vulnerability to commit fraud, affecting over 12,000 individuals.
  • National General failed to detect attacks for months and didn’t notify affected users.
  • Lax security measures included weak passwords and lack of multi-factor authentication.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?