The point: An AI crawler from OpenAI captured customer data including names, addresses, and banking information at uniVersa insurance, highlighting insufficient crawler controls for sensitive web offerings.
At uniVersa insurance, customer data was retrieved by an AI crawler from OpenAI. Those affected include names, addresses, and in some cases banking data of insurance policyholders.
The incident affects uniVersa insurance, where an AI crawler from OpenAI accessed customer data. The captured information includes names, addresses, and in parts of the cases also banking data of policyholders.
For CISOs and data protection officers, this incident represents a relevant case study: web crawlers from AI training providers can access publicly indexed or poorly protected webpages and capture sensitive customer data if they are not explicitly excluded through robots.txt or technical blocking mechanisms. This highlights the necessity to actively control the crawlability of customer portals and sensitive webpages.
The case underscores that standard security measures such as robots.txt entries, noindex meta tags, and basic audits of one’s own web discoverability must also be considered in the context of AI-based data collection. Companies should review which of their webpages are accessible to crawlers and whether sensitive data are exposed there.
Source: www.heise.de · Published 23 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.