New York · verified official-source register

New York Privacy Enforcement Cases

3 verified case records from the authoritative 50-state register. The fields below preserve the supplied amount, date, legal basis and explanation of why the action was brought.

3 official case source links · state register dated August 31, 2026

Actual case links

New York case register

Each record links directly to the official Attorney General or state-agency source supplied for this register. Shared multistate amounts are reproduced as stated and should not be summed as unique state penalties.

Verified case 1 of 3

Equifax

Date
July 22, 2019
Amount
Consumer Restitution Fund of up to $425 million, including $300 million initially dedicated to compensation and an additional $125 million if initial funds are depleted; $175 million in fines to the Attorneys General of 48 states, the District of Columbia, and the Commonwealth of Puerto Rico; $100 million in fines to the Consumer Financial Protection Bureau; $10 million in fines to New York State’s Department of Financial Services
Legal basis
No statutes or laws cited

Why the action was brought

Equifax’s 2017 breach compromised Social Security numbers, names, dates of birth, addresses, credit card numbers, and, in some cases, driver’s license numbers of nearly half the U.S. population. The Attorney General described Equifax’s behavior as irresponsible and negligent. An earlier website provided vague and inaccurate information, leaving consumers uncertain whether they were affected and exposed to identity theft and fraud.

View Official Case Source ↗ (opens in a new tab)

Verified case 2 of 3

Anthem, Inc.

Date
not stated in the official release
Amount
$39.5 million total; New York share: $2,715,495.21
Legal basis
not stated

Why the action was brought

Anthem’s systems were infiltrated beginning in February 2014 through malware installed via a phishing email. Attackers accessed its data warehouse and harvested names, dates of birth, Social Security numbers, health care identification numbers, home and email addresses, phone numbers, and employment information, compromising 78.8 million customers nationwide, including more than 4.6 million New Yorkers.

View Official Case Source ↗ (opens in a new tab)

Verified case 3 of 3

Root

Date
not stated in the official release
Amount
$975,000; no state share stated
Legal basis
No statutes or laws cited.

Why the action was brought

Root exposed approximately 45,000 New Yorkers’ personal information, including full plaintext driver’s-license numbers, through PDFs generated by its online quoting system. It failed to conduct adequate risk assessments, identify the exposure, and implement sufficient controls against automated attacks. Stolen license information was subsequently used in some fraudulent unemployment claims during COVID-19.

View Official Case Source ↗ (opens in a new tab)

Source data is based on verified concluded privacy, data-breach and data-security enforcement actions located on official state Attorney General or state-agency sources. Multistate settlement amounts are reproduced as stated by the official source and should not be summed as unique state penalties.