USAA notified about 32,000 members after update error misdelivered documents

Organization
USAA
Exploit
Misconfiguration
Industry
Insurance

USAA, the San Antonio based insurance and financial services provider that serves military members and their families, notified roughly 32,000 people in late August 2024 that their personal information had been exposed. The cause was an internal error rather than an intrusion.

According to the company's notifications, a routine update to its document delivery system on 13 April 2024 caused property and casualty insurance documents to be posted to other members' accounts. USAA said it became aware of the problem on 30 April 2024 and completed its investigation on 31 July 2024. Notification letters were sent on 27 August 2024. Reports put the number affected at about 32,276, of whom roughly 4,200 lived in Texas.

USAA said the misdelivered documents may have contained names, postal and email addresses, dates of birth, Social Security numbers, driver's licence numbers, passport numbers, vehicle identification numbers, policy and loan numbers, and some health information. The company said it had no evidence that fraud or identity theft had occurred, reported the incident to the Texas Attorney General's office, and offered affected members a two year subscription to Experian IdentityWorks. It also said it had updated its systems to prevent a repeat.

A proposed class action, Fitzpatrick v. United Services Automobile Association, was filed in Texas federal court on 27 September 2024. It alleged negligence and criticised both the four month gap between discovery and notification and the limited detail in the notice letters.

Sources