Global Navigation
Office of The Attorney General
The State of New Jersey Office of The Attorney General (Dept. of Law & Public Safety) The State of New Jersey NJ Home Services A to Z Departments/Agencies OAG Frequently Asked Questions
Services A to Z Departments/Agencies OAG Frequently Asked Questions
OAG Home
OAG Contact
spacer
Back to News Releases
OAG Home Attorney General's Biography
Attorney General's Biography
spacer spacer spacer
   
 
spacer spacer spacer
spacer spacer spacer
For Immediate Release: For Further Information:
September 7, 2018

Office of The Attorney General
- Gurbir S. Grewal, Attorney General
Division of Consumer Affairs 
- Paul R. Rodríguez, Acting Directo
Division of Law

- Michelle Miller, Director 
Media Inquiries-
Lisa Coryell
609-292-4791
spacer
Citizen Inquiries-
609-984-5828
spacer
spacer spacer spacer
spacer
Software Developer Agrees to Implement Security Protocols to Settle Investigation into Data Breach Exposing Personal Information of Auto Dealership Customers Nationwide, Including Thousands in NJ
spacer
spacer spacer spacer
spacer
spacer
spacer spacer spacer
spacer

NEWARK – Attorney General Gurbir S. Grewal and the Division of Consumer Affairs today announced a settlement with data management software developer Lightyear Dealer Technologies that resolves the Division’s investigation into a cyber security lapse that allowed unauthorized public internet access to a company database containing personally identifiable information of customers and employees of more than 100 auto dealerships nationwide, including at least four dealerships in New Jersey.

The security gap was exposed in 2016 when a security researcher accessed unencrypted files containing names, addresses, social security numbers, driver’s license numbers, bank account information and other data belonging to thousands of individuals, including at least 2,471 New Jersey residents.

To resolve the Division’s investigation into the breach, Lightyear Dealer Technologies, which does business as “DealerBuilt,” agreed to enact a variety of data security reforms designed to prevent similar breaches in the future.

“Through this settlement, New Jersey is holding DealerBuilt accountable for a security lapse that exposed sensitive personal data belonging to thousands of our residents and untold numbers of consumers nationwide,” said Attorney General Grewal. “As a result of our negotiations, DealerBuilt has agreed to implement comprehensive cyber-security protocols to better protect consumers in all states against the threat of identity theft or other cybercrimes.”
The reforms include:

  • the creation of an Information Security Program to be implemented and maintained by a Chief Security Officer with appropriate background and experience in information security;
  • the maintenance and implementation of encryption protocols for personal information stored on laptops or other portable devices or transmitted wirelessly; the maintenance and implementation of policies that clearly define which users have authorization to access its computer network; and
  • the maintenance of enforcement mechanisms to approve or disapprove access requests based on those policies; and the maintenance of data security assessment tools, including vulnerability scans. DealerBuilt also agreed to an $80,784 settlement amount.

“Data breaches like this are a sobering reminder of what can happen when companies fail to adequately protect the sensitive data they collect and store electronically,” said Paul R. Rodriguez, Acting Director of the Division of Consumer Affairs. “As this settlement demonstrates, New Jersey stands ready to vigorously enforce the laws that protect consumers from the risk of having their most personal information exposed online.”

Through its investigation, the Division found that in April 2015, a misconfigured file synchronizing program allowed unauthorized public internet access to a database containing unencrypted files backed up by approximately130 of DealerBuilt’s client dealerships nationwide, including at least four in New Jersey.

Sometime between October 29 and November 3, 2016, a security research was able to access the DealerBuilt database and downloaded files from five of those dealerships, including one in New Jersey: Winner Ford in Cherry Hill.

Upon learning of the vulnerability on DealerBuilt’s systems, the security researcher published an online article drawing attention to the fact that the files were backed up and stored without adequate security protocols in place.

In the wake of the breach, the Division began an investigation to ascertain whether DealerBuilt’s conduct was in violation of the New Jersey Consumer Fraud Act ("CFA") and/or the New Jersey Identity Theft Prevention Act ("ITPA").

In a Consent Order resolving the investigation, DealerBuilt agreed to an $80,784 settlement amount comprised of $49,420 in civil penalties and $31,364 in reimbursement of the Division's attorneys' fees, investigative costs and expert fees. Under the terms of the Order, $20,000.00 in civil penalties will be suspended and automatically vacated at the expiration of two years provided DealerBuilt complies with the terms of the Consent Order and does not engage in any acts or practices in violation of the CFA and/or the ITPA.

Investigator Christopher Spaldo and former Investigator Brian Morgenstern of the Division of Consumer Affairs’ Cyber Fraud Unit conducted this investigation.
Deputy Attorney General Zachary N. Klein and former Deputy Attorney General Russell M. Smith, Jr. within the Affirmative Civil Enforcement Practice Group in the Division of Law represented the Division in this matter.

Follow the New Jersey Attorney General’s Office online at Twitter, Facebook, Instagram, Flicker & YouTube. The social media links provided are for reference only. The New Jersey Attorney General’s Office does not endorse any non-governmental websites, companies or applications.

spacer
spacer spacer spacer
spacer
 
News Index Page I top
 
Executive Assistant Attorney General
Attorney General's Message Ask the Attorney General
Contact OAG About OAG
OAG News OAG Frequently Asked Questions
OAG Library Employment
OAG Grants Proposed Rules
OAG History OAG Services A-Z
Statutes
OAG Agencies / Programs / Units
Other News Pages Otras Noticias en Español Division of NJ State Police Division of Law News Governor's Office News Division of Highway Traffic Safety News Office of the Insurance Fraud Prosecutor Juvenile Justice Commission News Division on Civil Rights News Division of Consumer Affairs News Division of Criminal Justice News Election Law Enforcement Commission Division of Gaming Enforcement News
NJ State Police News Governor's Office News Division of Highway Traffic Safety News Office of the Insurance Fraud Prosecutor Juvenile Justice Commission News Division on Civil Rights News Division of Consumer Affairs News Division of Criminal Justice News Election Law Enforcement Commission Division of Elections News Division of Gaming Enforcement News Office of Government Integrity News
   
Contact Us | Privacy Notice | Legal Statement | Accessibility Statement
NJ Home Logo
Departmental: OAG Home | Contact OAG | About OAG | OAG News | OAG FAQs
Statewide: NJ Home | Services A to Z | Departments/Agencies | FAQs
Copyright © State of New Jersey
This page is maintained by OAG Communications. Comments/Questions: email or call 609-292-4925
OAG Home OAG Home NJ State Police News Governor's Office News Division of Highway Traffic Safety News Office of the Insurance Fraud Prosecutor Juvenile Justice Commission News Division on Civil Rights News Division of Consumer Affairs News Division of Criminal Justice News Election Law Enforcement Commission Division of Elections News Division of Gaming Enforcement News Office of Government Integrity News Click to Enlarge Image Click to Enlarge Image Click to Enlarge Graphic Click to enlarge chart Click to enlarge map Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click to Enlarge Click on image to enlarge... Click on image to enlarge... Click to enlarge...Click to enlarge...Click to enlarge...Click to enlarge... Click to enlarge... click to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlargeclick to enlarge click to enlarge