Ethos Technologies, Inc. Reports Recent Data Breach Leaked Consumers’ Social Security Numbers

Console and Associates, P.C.
Contact

On December 21, 2022, Ethos Technologies, Inc. filed notice of a data breach with the Montana Office of Consumer Protection, a division of the state’s attorney general’s office, after hackers successfully carried out a cyberattack against the company. Based on the company’s official filing, the incident resulted in an unauthorized party gaining access to consumers’ Social Security numbers. After confirming that consumer data was leaked, Ethos Technologies began sending out data breach notification letters to all individuals who were impacted by the recent data security incident.

Ethos Technologies sells life insurance policies online to make the process easier for potential customers. And by doing this, the company generates millions of dollars in revenue each year. One would hope that, given the nature of the company’s business and the significant revenue generated through online sources, Ethos would take the security of consumers’ information seriously. However, the recent data breach may call the company’s commitment to data security into question. As we’ve discussed in previous posts, companies that maintain consumer information are the first and last line of defense against data breaches. And, when a large company fails to live up to the duty it owes to consumers, and a hacker is able to exploit this weakness, the company may be liable to consumers through a data breach lawsuit.

What We Know So Far About the Ethos Technologies Breach

The available information regarding the Ethos Technologies breach comes from the company’s filing with the Montana Attorney General. According to this source, on December 8, 2022, Ethos learned that the company was the recent target of a “sophisticated and successful cyberattack.” While Ethos did not mention how it came to learn of the attack, apparently, hackers were able to plug in consumer information that they had obtained through other sources into the company’s insurance application flow. This prompted a third-party service provider to return the named consumer’s Social Security number.

In response to the company’s discovery, Ethos notified the Federal Bureau of Investigation and then made changes to its website to prevent similar attacks in the future. Next, Ethos began investigating the incident to determine the scope of the incident, confirming that certain individuals’ Social Security numbers were compromised.

According to the Ethos data breach letter, the unauthorized party was able to illegally obtain consumers’ Social Security numbers through its system between August 4, 2022 and December 9, 2022.

On December 21, 2022, Ethos Technologies sent out data breach letters to all individuals whose information was compromised as a result of the recent data security incident. Currently, the total number of Ethos data breach victims remains unknown; however, the Montana Attorney General indicates that there were 68 victims in Montana alone. Ethos notes that the majority of those affected by the breach were not existing Ethos customers.

More Information About Ethos Technologies, Inc.

Founded in 2016, Ethos Technologies, Inc. is a life insurance company based in Austin, Texas. Ethos offers a variety of coverage options, including both whole and term life insurance. The company requires all applicants to provide their full name, Social Security number, medical history and current prescription information to obtain a quote. As a third-party administrator, Ethos offers policies issued through Legal & General America, and all policies are reinsured through Munich Re. Ethos Technologies employs more than 400 people and generates approximately $373 million in annual revenue.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© Console and Associates, P.C.

Written by:

Console and Associates, P.C.
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Console and Associates, P.C. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide