GEICO tells employees their data was exposed in MOVEit-linked vendor breach
- Organization
- GEICO
- Exploit
- Supply Chain Attack
- Industry
- Insurance
GEICO notified its workforce in August 2023 of a security issue involving MOVEit, the Progress Software file transfer tool that was being exploited at scale that summer. The insurer said the software was used to move data to third-party vendors, and that customer data was not affected.
In a letter to employees, chief information security officer Zhiwei Fu wrote that the company had "immediately implemented measures to address the issue" and that at the time there was "no indication that any compromises have occurred in GEICO systems." Staff were advised to freeze their credit as a precaution, and the company said its security team was in contact with third-party vendors to track the fallout.
Current and former employees told reporters they believed their information had already been taken. One former employee said records belonging to her, her daughter, her husband and her stepfather had been exposed, including details supplied for health insurance purposes.
GEICO did not name the affected vendor at the time. In a January 30, 2024 notification to the Iowa Attorney General, counsel for GEICO Corporation said Delta Dental of California, which provides dental insurance to GEICO employees, learned of the MOVEit exploit on June 1, 2023, determined on July 6, 2023 that files had been taken from its MOVEit server, and told GEICO its employees were affected around December 22, 2023. Those affected were offered credit monitoring.