NY DFS Part 500 Penalties: What Non-Compliance Actually Costs
NY DFS 23 NYCRR 500 penalties are real, and they run into the millions. Since November 2024, the New York Department of Financial Services has settled five separate enforcement actions against regulated firms. Every one traces back to a preventable gap, like missing MFA or a slow breach report.
This page walks through what those cases actually involved. It also explains where DFS gets its penalty authority. That matters for any firm about to sign this year’s compliance certification.
DFS is not a paper regulator. In 2024 and 2025 alone, at least three of these settlements ran into multiple millions of dollars each, tied to control failures that show up on a lot of firms’ networks right now.
Where DFS’s Penalty Authority Actually Comes From
Part 500 itself does not set the dollar amounts. DFS’s civil penalty authority comes from New York Financial Services Law Section 408, a separate statute.
Section 408 caps penalties per offense, not per case:
| Violation Type | Penalty Cap (Per Offense) |
|---|---|
| Intentional fraud or misrepresentation of a material fact | Up to $5,000 |
| Any other violation of Part 500 | Up to $1,000 |
Those caps look small. They aren’t, once “per offense” applies across a breach touching thousands of records.
DFS does not just multiply a fixed number by a violation count. Under 23 NYCRR 500.20, the Superintendent weighs several factors before setting a final penalty:
- How the firm cooperated during the investigation
- Whether the violation was unintentional, reckless, or intentional
- Whether it stemmed from a gap the firm already knew about, from a prior exam finding
That discretion is why two firms with similar breaches can land on very different settlement numbers. It also explains why “per offense” math on paper turns into a negotiated, multimillion-dollar consent order in practice.
Case Study 1: GEICO and Travelers, November 2024
More than 116,000 New York residents had driver’s license numbers and other personal data exposed.
The two insurers were fined for different failures:
| Company | Penalty | Core Failure |
|---|---|---|
| GEICO | $9.75 million | Skipped required risk assessments and annual penetration testing, and inadequate continuous monitoring |
| Travelers | $1.55 million | Weak access controls, including a failure to enforce MFA, plus shared login credentials among independent agents |
GEICO’s failure was mostly about testing and visibility. It didn’t run the risk assessments and penetration tests Part 500 requires on a regular schedule.
Travelers’ failure was about access. Independent agents were sharing credentials, and multifactor authentication wasn’t consistently required, which is one of the same gaps LeadingIT’s NY DFS MFA requirement deep-dive walks through in detail.
Case Study 2: Eight Auto Insurers, October 2025

Less than a year later, DFS went after a wider slice of the same industry. In an October 14, 2025 press release, DFS announced it had secured more than $19 million in combined penalties from eight auto insurance companies.
The pattern was familiar: online quoting applications and agent portals exposed driver’s license numbers and dates of birth to unauthorized access.
| Company | Penalty |
|---|---|
| Infinity Insurance Company | $2,250,000 |
Most of the eight were penalized for inadequate controls on public-facing systems. Two of them, Farmers and Infinity, were also cited for a second, separate problem: they didn’t report the cybersecurity events to DFS on time.
That combination shows up again and again in these cases. A control gap gets a firm into trouble. A slow report makes it worse.
Case Study 3: Healthplex, August 2025
On August 14, 2025, DFS announced a $2 million penalty against Healthplex, Inc. The cause was narrower than the insurer cases, but no less common.

A threat actor used phishing to get into Healthplex’s systems. Once inside, they found systems that lacked the multifactor authentication Part 500 requires.
Phishing is not a sophisticated attack. It works because it only takes one employee clicking one bad link. MFA is supposed to be the backstop when that happens, and in this case, it wasn’t there.
Healthplex also missed the reporting clock. It detected the event in November 2021 and did not notify DFS until April 2022, more than four months against a 72-hour requirement.
Case Study 4: PayPal, January 2025

In January 2025, DFS announced a $2 million penalty against PayPal, Inc. This one was about controls, not timing.
DFS cited unqualified personnel running key cybersecurity functions, inadequate training, missing written policies covering access control and customer data, and access controls that failed to stop unauthorized access to nonpublic information.
No reporting violation was charged here. PayPal is the case that shows a firm can reach $2 million on control gaps alone, with no late notice anywhere in the file.
Case Study 5: Delta Dental, April 2026
The penalty was $2,250,000.
This case wasn’t about a missing technical control. It was about timing.
Delta Dental confirmed a cybersecurity event involving data exfiltration in July. DFS says the companies waited roughly six months to report it, notifying DFS in December.
Six months is not a gray area.
The Pattern Across All Five Cases
Line up all five cases and one pattern repeats.
| Case | Penalty | Control Gap Cited | Reporting Issue Cited |
|---|---|---|---|
| GEICO / Travelers (Nov 2024) | $11.3M combined | Missed risk assessments and pen testing (GEICO); weak access controls, shared credentials (Travelers) | None cited |
| Eight Auto Insurers (Oct 2025) | $19M+ combined | Inadequate controls on public-facing quoting portals | Farmers and Infinity also cited for late reporting |
| Healthplex (Aug 2025) | $2M | Missing MFA, exploited by phishing | More than four months to notify DFS |
| PayPal (Jan 2025) | $2M | Gaps in required controls | None cited |
| Delta Dental (Apr 2026) | $2.25M | Not the primary issue in this case | About six months to report a confirmed event |
Missing multifactor authentication was cited by name in two of these five cases: Travelers and Healthplex.
It’s almost never one catastrophic failure. It’s usually a preventable control gap, often MFA or loose access limits, paired with a slow or missing report.
Fix either half and the exposure usually shrinks. Fix both, and DFS has far less to act on.
One more thing worth checking before any of this applies to you: not every DFS-licensed firm carries the same obligations. If you’re not sure your firm counts as a Covered Entity at all, start with who must comply with NY DFS 23 NYCRR Part 500.
What This Means for the April 15 Certification
Every non-exempt Covered Entity has to file something with DFS each year. There are two options.

- Certification of Material Compliance: signed personally by the entity’s highest-ranking executive and its CISO, confirming the firm met Part 500’s requirements.
- Acknowledgment of Noncompliance: lists which provisions weren’t met, plus a remediation timeline or confirmation it’s already fixed.
DFS has said there’s no enforcement safe harbor for filing an Acknowledgment instead of a clean certification. Filing one doesn’t guarantee protection.
But it also isn’t a certification that turns out to be false. Signing a Certification of Material Compliance that doesn’t match reality is its own exposure, separate from whatever the underlying gap already was.
If your program has gaps you haven’t mapped yet, the 23 NYCRR 500 compliance checklist deep-dive walks through every requirement.
The April 15, 2026 filing raises the stakes further. It’s the first certification that has to attest to full compliance with every Second Amendment requirement, including the universal MFA and asset inventory rules that took effect in November 2025. The April 15 deadline guide covers exactly what changed and what to check before signing.
See Where You Stand
The same gaps that cost these firms millions, incomplete MFA and slow incident reporting, are the two things worth checking in your own environment first. This takes about two minutes and doesn’t require signing up to see your result.
Free 2-minute NY DFS 23 NYCRR 500 Risk-Check
Related Guides
- The NY DFS MFA Requirement: Are You Actually Compliant Yet?
- Who Must Comply With NY DFS 23 NYCRR Part 500?
- NY DFS Annual Certification: The April 15 Deadline Explained
- NY DFS Risk-Check: Which of the Four Compliance Tiers Are You In?
Frequently Asked Questions
New York Financial Services Law Section 408 caps penalties at $5,000 per offense for intentional fraud or misrepresentation, and $1,000 per offense for any other violation. Those caps apply per offense, not per case. That per-offense structure is why breaches touching thousands of records turn into multimillion-dollar settlements, even though the individual caps look small.
Yes. Since November 2024, DFS has settled five separate enforcement actions, each landing in the millions: GEICO and Travelers ($11.3 million combined), eight auto insurers ($19 million combined), Healthplex ($2 million), PayPal ($2 million), and Delta Dental ($2,250,000).
It’s the annual filing non-exempt Covered Entities submit to DFS, due April 15 each year. It’s signed personally by the entity’s highest-ranking executive and its Chief Information Security Officer, confirming the firm met Part 500’s requirements for the prior year.
DFS allows an Acknowledgment of Noncompliance instead of a clean certification. It lists which provisions weren’t met, along with a remediation timeline. DFS has said there’s no enforcement safe harbor for filing one, but it’s still not the same risk as signing a certification that doesn’t match reality.
Yes. The Delta Dental case is the clearest example. DFS fined the company $2,250,000 largely because it waited roughly six months to report a confirmed cybersecurity event, not because of one specific missing control.
A preventable control gap paired with slow or missing incident reporting. Missing multifactor authentication was cited by name in two of the five cases here, Travelers and Healthplex. Late reporting was cited in three: two of the eight auto insurers, Healthplex, and Delta Dental.
Ready for Your Next DFS Exam?
Getting these controls in place, and keeping them in place year over year, is what LeadingIT’s IT compliance services for financial services firms are built for. It’s the done-for-you path instead of building it in-house.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
