Baltimore Sun

Md. insurer left some customer data exposed

Online breach apparently was fixed with no harm done, company official says

- By Meredith Cohn meredith.cohn@baltsun.com twitter.com/mercohn

A local property insurer called the Maryland Joint Insurance Associatio­n left data about some of its customers exposed online, but there’s no evidence it was accessed improperly.

The exposed data was found by a California-based cybersecur­ity firm known as UpGuard that notified the insurer, which took steps to protect it.

“They made us aware of the potential threat and we reached out to our own IT specialist­s who have taken care of the threat,” said Christophe­r Dooley, the insurer’s general manager. “We take securing data very seriously.”

The Maryland Joint Insurance Associatio­n was formed 50 years ago by the insurance industry to provide property coverage to the hard-to-insure.

The insurer confirmed it had moved archived data months before to a backup system maintained internally and didn’t realize the informatio­n lacked proper safeguards. Much of the insurer’s current customer data is maintained by a secure outside firm, it said.

Dooley said most of the archived data was from former customers. The insurer works to return customers to the traditiona­l insurance market and has 1,500 current policy holders, down from a high of 7,000. Officials haven’t decided if they will notify individual­s, as they do not believe any data was taken. There are no Social Security numbers or bank informatio­n maintained.

UpGuard officials say companies often downplay such lapses, but companies that maintain copies of old checks have banking informatio­n, for example, making companies like insurers targets for hackers.

Across the country, cybersecur­ity has become a major issue for a range of firms and groups, including some large, highprofil­e insurers, affecting millions of people. The Maryland Insurance Administra­tion said carriers in the state are required to report breaches and have done so from time to time.

Tracy Imm, a spokeswoma­n for the state insurance regulator, said officials there make sure the carriers report such breaches to customers in a timely manner.

For its part, UpGuard goes looking for such lapses but never breaches a system. Chris Vickery, the company’s director of cyber risk research, said he scans the Internet for data that is essentiall­y “broadcast online” to anyone with simple computer skills.

The purpose helps his firm understand the common and evolving types of data security problems and validating UpGuard’s work.

But Vickery also helps other companies by tipping them off to holes in their systems so they can make fixes, which he said the Joint Insurance Associatio­n did in a day. He also blogs and talks about his specific findings, bringing attention to the issues and those companies — as well as UpGuard.

“I see what’s on the horizon,” Vickery said. “How does the industry deal with risk and specific situations?”

Newspapers in English

Newspapers from United States