New York State Department of Financial Services Warns of New Fraudulent Campaign Targeting Consumer NPI
Privacy, Cyber & AI Decoded Alert | 2 min read
Feb 23, 2021
On February 16, the New York State Department of Financial Services (DFS) issued a cyber fraud alert, warning of a growing cybercriminal campaign to steal consumer, Nonpublic Information (NPI). The hacked data is being taken from public-facing websites and used to obtain pandemic and unemployment benefits. The first reports of fraud were received in late December 2020, and early January 2021, from automobile insurers, who reported that cybercriminals were stealing unredacted driver's license numbers by hacking their websites' instant insurance premium quote function.
The attacks target public-facing websites that display or transmit consumer NPI, and some hackers have even obtained fully redacted information. Thus far, affected entities have been primarily automobile insurers with "Instant Quote Websites," although any entity with a consumer-facing website utilizing instant quotes is at risk.
Some of the methods used to illegally obtain NPI include:
- Taking unredacted NPI from websites' Hypertext Markup Language (HTML)
- Using developer debug tools to intercept and decode unredacted NPI
- Manipulating website NPI-redaction technology to fully reveal the information
DFS recommends that its regulated entities use data analytics and website traffic metrics to identify suspicious activity such as an unusual number of abandoned quotes in a short time frame or submissions that are terminated as soon as NPI is revealed. Other recommended strategies to prevent attacks include:
- Reviewing website security controls and browser web developer tool functionality;
- Properly implementing and ensuring redaction and data obfuscation for NPI throughout the entirety of NPI transmission;
- Confirming privacy protections are up to date;
- Reviewing who is authorized to see NPI, which applications use NPI, and where NPI resides;
- Scrubbing public code repositories for proprietary code;
- Blocking IP addresses of suspected unauthorized users; and
- Implementing a quote limit per user session.
In light of recent hacks and the unprecedented surge in benefits fraud seen during the COVID-19 pandemic, DFS recommends that entities refrain from displaying any NPI, even if redacted, to users on public-facing websites unless there is a "compelling reason" to do so.
DFS-regulated entities should identify and resolve any cybersecurity flaws immediately. If an attack does occur, it must be reported pursuant to 23 NYCRR Section 500.17(a) as soon as possible, but within 72 hours at the latest.
Related Content
Related Capabilities
Featured Insights

Healthcare Alert
Aug 3, 2026
Fixing the Emergency Refill Trap: What California’s AB 1587 Means for Pharmacies

Consumer Crossroads: Where Financial Services and Litigation Intersect
Jul 30, 2026
Should Text Messages be Considered “Calls” Under the TCPA? The Seventh Circuit Says No

Healthcare Alert
Jul 30, 2026
California Courts Sharply Curtail the MICRA Damages Cap in Nursing Home Litigation

Insights for Insurers Alert
Jul 30, 2026
Analyzing a Couple of Cases Involving Exclusions in D&O Policies

In The News
Jul 29, 2026
Hinshaw Authors Contribute Two Articles in Latest Edition of the CCFL Quarterly Report

Webinar
Jul 28, 2026
Cathy Mulrow-Peattie and Sabrina Janeiro Present on Legal AI Technology

In The News
Jul 27, 2026
Scott Seaman Discusses How the Insurance Industry Contributed to the 2026 FIFA World Cup

Privacy, Cyber & AI Decoded Alert
Jul 27, 2026
Compliance Guidance for the New Vermont Data Privacy and Online Surveillance Act (VDPOSA)

Healthcare Alert
Jul 24, 2026
Q&A: Right to Electronic Monitoring Extended to Illinois Assisted and Shared Living Facilities

Press Release
Jul 23, 2026
Insurance Partner Christophe Burusco Joins Hinshaw in Los Angeles

In The News
Jul 16, 2026
Jennifer Driscoll Anticipates Epic Battle Between “Titans of the Antitrust Bar”

