California Department of Insurance Vulnerability Potentially Exposed Thousands of SSN and Other Personal Information
DataBreaches.net was recently contacted by an Indian cybersecurity firm, Banbreach, about a vulnerability involving the California Department of Insurance site. According to Banbreach, they notified the California Department of Insurance (CDI) that interactive.web.insurance.ca.gov was hosting an oracle reporting server that had generated more than 24,450 reports in the prior 24 hours. Most of the reports were appeared to be renewal reports for insurance agents that included the agents’ name, renewal ID, and Tax Identification Number (TIN). Because many individuals use their Social Security Number as their TIN, there was the possibility that many people could have their name and SSN compromised. Other reports that were exposed by the site’s vulnerability were described as:
insurance claims investigation reports with details such as names, vehicle registration numbers, and addresses;
Statistical reports on monthly frauds; and
Details of individuals and charges they were indicted for, fines paid, impacted parties etc.
https://www.databreaches.net/california-department-of-insurance-vulnerability-potentially-exposed-thousands-of-ssn-and-other-personal-information/