uniVersa says an OpenAI web crawler read customer names, addresses, and some bank details for a few hours on July 7, 2026, after a brief server misconfiguration during an IT transition.
An OpenAI web crawler reached a server holding uniVersa customer data during a brief July 7, 2026 IT transition and read records for a few hours, according to heise online. The German insurance group disclosed the incident, and BayLDA president Michael Will confirmed to heise online that the authority has received the report.
The server held customer names, addresses, contract data including insurance numbers and tariff information, and, for some customers, bank details (IBAN and BIC, the European bank account number and bank identifier). UniVersa said health data, login credentials, and credit card information were not on the server, and the central administration systems and customer portal were not affected. The number of affected customers has not been disclosed.
The exposure came from an AI training crawler, the kind of bot that fetches public web pages for model training. It reached a server that was briefly misconfigured during the IT transition. UniVersa discovered the access through internal security controls, shut the server down, and asked OpenAI not to use the data and to delete it. BayLDA president Michael Will advised affected individuals to change passwords, monitor bank activity, and be alert to unusual contact.
The European Data Protection Board's 2026 guidance on web scraping for generative AI gives regulators a vocabulary for incidents in this category. UniVersa has not yet said how many customers were affected, and the IT forensic investigation is still open.