Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

NY DFS Part 500 Penalties: What Non-Compliance Actually Costs

August 11, 2026
hero-ny-dfs-500-penalties-enforcement-1.png

NY DFS 23 NYCRR 500 penalties are real, and they run into the millions. Since November 2024, the New York Department of Financial Services has settled five separate enforcement actions against regulated firms. Every one traces back to a preventable gap, like missing MFA or a slow breach report.

This page walks through what those cases actually involved. It also explains where DFS gets its penalty authority. That matters for any firm about to sign this year’s compliance certification.

DFS is not a paper regulator. In 2024 and 2025 alone, at least three of these settlements ran into multiple millions of dollars each, tied to control failures that show up on a lot of firms’ networks right now.

Where DFS’s Penalty Authority Actually Comes From

Part 500 itself does not set the dollar amounts. DFS’s civil penalty authority comes from New York Financial Services Law Section 408, a separate statute.

Section 408 caps penalties per offense, not per case:

Violation TypePenalty Cap (Per Offense)
Intentional fraud or misrepresentation of a material factUp to $5,000
Any other violation of Part 500Up to $1,000

Those caps look small. They aren’t, once “per offense” applies across a breach touching thousands of records.

DFS does not just multiply a fixed number by a violation count. Under 23 NYCRR 500.20, the Superintendent weighs several factors before setting a final penalty:

  • How the firm cooperated during the investigation
  • Whether the violation was unintentional, reckless, or intentional
  • Whether it stemmed from a gap the firm already knew about, from a prior exam finding

That discretion is why two firms with similar breaches can land on very different settlement numbers. It also explains why “per offense” math on paper turns into a negotiated, multimillion-dollar consent order in practice.

Case Study 1: GEICO and Travelers, November 2024

More than 116,000 New York residents had driver’s license numbers and other personal data exposed.

The two insurers were fined for different failures:

CompanyPenaltyCore Failure
GEICO$9.75 millionSkipped required risk assessments and annual penetration testing, and inadequate continuous monitoring
Travelers$1.55 millionWeak access controls, including a failure to enforce MFA, plus shared login credentials among independent agents

GEICO’s failure was mostly about testing and visibility. It didn’t run the risk assessments and penetration tests Part 500 requires on a regular schedule.

Travelers’ failure was about access. Independent agents were sharing credentials, and multifactor authentication wasn’t consistently required, which is one of the same gaps LeadingIT’s NY DFS MFA requirement deep-dive walks through in detail.

Case Study 2: Eight Auto Insurers, October 2025

Spec block on the October 2025 DFS action against eight auto insurers: over $19 million combined, quoting portals exposing licence numbers and dates of birth, with two insurers also cited for late reporting.

Less than a year later, DFS went after a wider slice of the same industry. In an October 14, 2025 press release, DFS announced it had secured more than $19 million in combined penalties from eight auto insurance companies.

The pattern was familiar: online quoting applications and agent portals exposed driver’s license numbers and dates of birth to unauthorized access.

CompanyPenalty
Infinity Insurance Company$2,250,000

Most of the eight were penalized for inadequate controls on public-facing systems. Two of them, Farmers and Infinity, were also cited for a second, separate problem: they didn’t report the cybersecurity events to DFS on time.

That combination shows up again and again in these cases. A control gap gets a firm into trouble. A slow report makes it worse.

Case Study 3: Healthplex, August 2025

On August 14, 2025, DFS announced a $2 million penalty against Healthplex, Inc. The cause was narrower than the insurer cases, but no less common.

Healthplex Breach Penalty Timeline

A threat actor used phishing to get into Healthplex’s systems. Once inside, they found systems that lacked the multifactor authentication Part 500 requires.

Phishing is not a sophisticated attack. It works because it only takes one employee clicking one bad link. MFA is supposed to be the backstop when that happens, and in this case, it wasn’t there.

Healthplex also missed the reporting clock. It detected the event in November 2021 and did not notify DFS until April 2022, more than four months against a 72-hour requirement.

Case Study 4: PayPal, January 2025

Spec block on the January 2025 DFS penalty against PayPal: a $2 million penalty for gaps in required controls, including missing multi-factor authentication.

In January 2025, DFS announced a $2 million penalty against PayPal, Inc. This one was about controls, not timing.

DFS cited unqualified personnel running key cybersecurity functions, inadequate training, missing written policies covering access control and customer data, and access controls that failed to stop unauthorized access to nonpublic information.

No reporting violation was charged here. PayPal is the case that shows a firm can reach $2 million on control gaps alone, with no late notice anywhere in the file.

Case Study 5: Delta Dental, April 2026

The penalty was $2,250,000.

This case wasn’t about a missing technical control. It was about timing.

Delta Dental confirmed a cybersecurity event involving data exfiltration in July. DFS says the companies waited roughly six months to report it, notifying DFS in December.

Six months is not a gray area.

The Pattern Across All Five Cases

Line up all five cases and one pattern repeats.

CasePenaltyControl Gap CitedReporting Issue Cited
GEICO / Travelers (Nov 2024)$11.3M combinedMissed risk assessments and pen testing (GEICO); weak access controls, shared credentials (Travelers)None cited
Eight Auto Insurers (Oct 2025)$19M+ combinedInadequate controls on public-facing quoting portalsFarmers and Infinity also cited for late reporting
Healthplex (Aug 2025)$2MMissing MFA, exploited by phishingMore than four months to notify DFS
PayPal (Jan 2025)$2MGaps in required controlsNone cited
Delta Dental (Apr 2026)$2.25MNot the primary issue in this caseAbout six months to report a confirmed event

Missing multifactor authentication was cited by name in two of these five cases: Travelers and Healthplex.

It’s almost never one catastrophic failure. It’s usually a preventable control gap, often MFA or loose access limits, paired with a slow or missing report.

Fix either half and the exposure usually shrinks. Fix both, and DFS has far less to act on.

One more thing worth checking before any of this applies to you: not every DFS-licensed firm carries the same obligations. If you’re not sure your firm counts as a Covered Entity at all, start with who must comply with NY DFS 23 NYCRR Part 500.

What This Means for the April 15 Certification

Every non-exempt Covered Entity has to file something with DFS each year. There are two options.

Comparison of the two DFS annual filings a Covered Entity can submit: a Certification of Material Compliance signed by the top executive and CISO, versus an Acknowledgment of Noncompliance listing unmet provisions. DFS says the Acknowledgment carries no enforcement safe harbor, and a Certification that turns out to be false is its own separate exposure.
  • Certification of Material Compliance: signed personally by the entity’s highest-ranking executive and its CISO, confirming the firm met Part 500’s requirements.
  • Acknowledgment of Noncompliance: lists which provisions weren’t met, plus a remediation timeline or confirmation it’s already fixed.

DFS has said there’s no enforcement safe harbor for filing an Acknowledgment instead of a clean certification. Filing one doesn’t guarantee protection.

But it also isn’t a certification that turns out to be false. Signing a Certification of Material Compliance that doesn’t match reality is its own exposure, separate from whatever the underlying gap already was.

If your program has gaps you haven’t mapped yet, the 23 NYCRR 500 compliance checklist deep-dive walks through every requirement.

The April 15, 2026 filing raises the stakes further. It’s the first certification that has to attest to full compliance with every Second Amendment requirement, including the universal MFA and asset inventory rules that took effect in November 2025. The April 15 deadline guide covers exactly what changed and what to check before signing.

See Where You Stand

The same gaps that cost these firms millions, incomplete MFA and slow incident reporting, are the two things worth checking in your own environment first. This takes about two minutes and doesn’t require signing up to see your result.

Free 2-minute NY DFS 23 NYCRR 500 Risk-Check

Frequently Asked Questions

New York Financial Services Law Section 408 caps penalties at $5,000 per offense for intentional fraud or misrepresentation, and $1,000 per offense for any other violation. Those caps apply per offense, not per case. That per-offense structure is why breaches touching thousands of records turn into multimillion-dollar settlements, even though the individual caps look small.

Yes. Since November 2024, DFS has settled five separate enforcement actions, each landing in the millions: GEICO and Travelers ($11.3 million combined), eight auto insurers ($19 million combined), Healthplex ($2 million), PayPal ($2 million), and Delta Dental ($2,250,000).

It’s the annual filing non-exempt Covered Entities submit to DFS, due April 15 each year. It’s signed personally by the entity’s highest-ranking executive and its Chief Information Security Officer, confirming the firm met Part 500’s requirements for the prior year.

DFS allows an Acknowledgment of Noncompliance instead of a clean certification. It lists which provisions weren’t met, along with a remediation timeline. DFS has said there’s no enforcement safe harbor for filing one, but it’s still not the same risk as signing a certification that doesn’t match reality.

Yes. The Delta Dental case is the clearest example. DFS fined the company $2,250,000 largely because it waited roughly six months to report a confirmed cybersecurity event, not because of one specific missing control.

A preventable control gap paired with slow or missing incident reporting. Missing multifactor authentication was cited by name in two of the five cases here, Travelers and Healthplex. Late reporting was cited in three: two of the eight auto insurers, Healthplex, and Delta Dental.

Ready for Your Next DFS Exam?

Getting these controls in place, and keeping them in place year over year, is what LeadingIT’s IT compliance services for financial services firms are built for. It’s the done-for-you path instead of building it in-house.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.