Skip to main content
Menu Icon
Close

InfoBytes Blog

Financial Services Law Insights and Observations

Filter

Subscribe to our InfoBytes Blog weekly newsletter and other publications for news affecting the financial services industry.

  • NYDFS settles with title insurance company for $1 million

    Privacy, Cyber Risk & Data Security

    On November 27, the NYDFS entered into a consent order with a title insurance company, which required the company to pay $1 million for failing to maintain and implement an effective cybersecurity policy and correct a cybersecurity vulnerability. The vulnerability allowed members of the public to access others’ nonpublic information, including driver’s license numbers, social security numbers, and tax and banking information. The consent order indicates the title insurance company discovered the vulnerability as early as 2018. The title insurance company’s failure to correct these changes violated Section 500.7 of the Cybersecurity Regulation.

    In May 2019, a cybersecurity journalist published an article on the existence of a vulnerability in the title insurance company’s application, that led to a public exposure of 885 million documents, some found through search engine results. The journalist noted that “replacing the document ID in the web page URL… allow[ed] access to other non-related sessions without authentication.” Following the cybersecurity journalist’s article, and as required by Section 500.17(a) of the Cybersecurity Regulation, the title insurance company notified NYDFS of its vulnerability, at which point NYDFS investigated further. The title insurance company has been ordered to pay the penalty no later than ten days after the effective date.

    Privacy, Cyber Risk & Data Security State Issues Securities NYDFS Auto Insurance Enforcement

  • District Court preliminarily approves $300 million auto insurance settlement

    Courts

    On May 1, the U.S. District Court for the Northern District of California preliminarily approved a $300 million class action settlement resolving claims that a national bank hid misconduct relating to its auto insurance practices. The lead plaintiff alleged that, between November 3, 2016 and August 3, 2017, the defendant made materially false or misleading statements in violation of the Securities Act, which artificially inflated the price of the defendant’s stock. Specifically, the plaintiff maintained that the defendant concealed that it allegedly force-placed unneeded collateral protection insurance (CPI) on many of its customers and failed to refund unearned guaranteed auto protection (GAP) premiums to other customers, which led to more than 20,000 customers having their cars repossessed. The plaintiff further alleged that the defendant was aware of these issues but failed to disclose them to investors or the public, and claimed that the facts did not emerge until they were published by the media in July of 2017. As a result, class members who purchased defendant’s stock during the relevant period allegedly suffered economic losses when the stock price declined as a result of two corrective disclosures that revealed the CPI and GAP issues to investors. A hearing later this year will determine the service fee award and attorneys’ fees and expenses (to be no more than 25 percent of the settlement amount). The defendant denies all claims of wrongdoing.

    Courts Consumer Finance Class Action Auto Insurance Auto Lending Settlement GAP Fees

Upcoming Events