Menu
Browse

Cyber Incident Victim: Noblr Reciprocal Exchange

Date:

Jan 2021

Location:

United States of America

Summary

Attackers exploited an insurance provider's instant quote platform by inputting pre-obtained personal details to harvest driver's license numbers inadvertently exposed in the system's source code. The breach involved unauthorized access to sensitive data through automated third-party information retrieval during quote generation, potentially exposing policy application documents. Following detection of abnormal activity, the organization blocked suspicious IP addresses and modified its platform to prevent further exploitation. The incident impacted approximately 97,600 individuals, including those without direct relationships with the provider, as attackers leveraged stolen identifiers to illicitly gather additional personal information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On January 21, 2021, Noblr Reciprocal Exchange’s web team detected a surge in incomplete insurance quotes through its public-facing instant quote platform, triggering an internal investigation. The platform allowed users to input basic personal details (name and date of birth) to generate tailored quotes by automatically retrieving additional information—including driver’s license numbers—from a third-party service provider. Investigators determined attackers had exploited this process by submitting pre-obtained names and birthdates to harvest driver’s license numbers, which were inadvertently exposed in the webpage’s source code. The attackers’ activity suggested they already possessed consumers’ identifying information prior to targeting Noblr’s system. Between January 21 and January 27, Noblr’s security team identified that threat actors could also access full policy application documents by completing the quote process, potentially exposing further personal data.

Cyber Incident Image

Noblr initiated containment measures on January 25 by blocking suspicious IP addresses linked to the anomalous activity. By January 27, after confirming driver’s license number theft, the company modified its quote platform to prevent further unauthorized access. The breach impacted 97,633 individuals, including consumers with no prior relationship to Noblr, as attackers could input any person’s details into the system. Notifications began on May 14, 2021, advising affected parties that compromised data stemmed from the automated third-party retrieval process. Noblr did not disclose whether additional personal information beyond driver’s license numbers was exfiltrated or specify the identity of the third-party provider involved in the quote system. The incident highlighted vulnerabilities in automated data aggregation features and the risks of source code exposure.

Sources
Sources available to members
1 source