Last Update: 08/01/2026 at 2:00 PM EST

AssuranceAmerica Breach Exposes Driver Data

Coverage from BleepingComputer, TechCrunch, and others

Articles

62

Active Days

99

The Topic

AssuranceAmerica Breach Exposes Driver Data topic image

AssuranceAmerica disclosed that an unauthorized actor accessed its systems after obtaining an employee credential and copied files containing personal, insurance, vehicle, claims, and driver’s license information belonging to 6,998,886 people. The incident was detected on March 17, 2026, while the investigation concluded on June 15, and notifications began in July. The scale and persistence of driver’s license and other identity data create continuing risks of phishing, identity theft, fraudulent insurance activity, and misuse that may not appear immediately.

First Article: 04/20/26

Latest Article: 07/27/26

Summary

  • AssuranceAmerica reported 6,998,886 affected individuals, including current and former customers and named drivers on policies.
  • Exposed files included names, contact information, insurance policy or account data, driver and vehicle information, claims data, and driver’s license numbers.
  • Some notices also referenced Social Security numbers and tax identification numbers, but the exposed fields varied by person.
  • The intrusion followed an attacker’s use of an employee credential on March 16; suspicious activity was detected the next day.
  • The company completed its affected-file review on June 15 and began sending consumer notifications in July, creating a substantial interval between detection and notification.
  • AssuranceAmerica disabled credentials, ended unauthorized sessions, isolated systems, reset passwords, added monitoring and threat-detection tools, and notified law enforcement.
  • The actor, precise credential-theft method, multifactor authentication status, ransom status, and any public posting of the data remain unconfirmed.

History

07/29/2026

The story is now more specific about timing and oversight: AssuranceAmerica says the credential-based intrusion was detected on March 17, the review finished June 15, and consumer notices began in July. It also adds state filing context and clarifies that several key details, including the theft method and ransom/public-posting status, remain unconfirmed.

07/28/2026

The story has narrowed from a broad pattern of insurer and financial-sector breach disclosures to a specific, large AssuranceAmerica incident with confirmed file copying affecting nearly 7 million people. The new detail is the attack method, the size of the affected population, and the timeline of detection and notification.

Full History

Featured

Timeline: 99 Days

Apr 20May 11Jun 1Jun 15Jul 6Jul 27

Additional Articles

⭐⭐⭐⭐⭐

TechTimes07-12-2026
AssuranceAmerica notified consumers starting July 10 after a 2026 credential compromise exposed driver license data for millions of customers and policy-associated individuals.
Security Boulevard / Evan Rowe05-03-2026
Ameriprise Financial disclosed a March 2026 breach affecting nearly 48,000 people after unauthorized access began March 2 and was detected March 18.
Insurance Business / Josh Recamara07-09-2026
AssuranceAmerica disclosed a 2026 breach detected March 17, 2026, with breach filings revised to about 6.9 million people and class actions under investigation.
GBhackers07-09-2026
AssuranceAmerica disclosed a phishing-linked breach detected March 17, 2026, exposing driver license and insurance records for nearly 7 million people nationwide.
ProgramBusiness / Maria Valdez Haubrich07-16-2026
AssuranceAmerica disclosed in 2026 that a phishing-led intrusion led to unauthorized copying of data files affecting 6,998,886 people.
Dark Web Informer07-08-2026
AssuranceAmerica confirmed a March 17, 2026 data breach affecting 6.99 million people in the United States, including driver license numbers, with notifications expected July 10.
Wealth Management / Patrick Donachie04-24-2026
LPL Financial notified the Maine Attorney General in 2025 of a phishing malware breach that enabled unauthorized securities transactions in a small set of advisor-linked client accounts.
McAfee / Brooke Seipel07-09-2026
AssuranceAmerica reported a data breach affecting 6.9 million customers after a compromised employee account exposed driver license numbers and claims data.
Malwarebytes / Pieter Arntz07-09-2026
AssuranceAmerica disclosed on a breach timeline beginning March 17 that phishing led to theft of customer personal information and driver license numbers affecting up to 6.9 million people.
Safestate07-10-2026
AssuranceAmerica notified 6,998,886 affected individuals after intrusion starting March 16 exposed driver license and insurance claims data.
Lifehacker07-08-2026
AssuranceAmerica disclosed a March 17 data breach affecting nearly 7 million policyholders, exposing insurance and driver's license numbers, with notices starting July 10.
Lifehacker07-08-2026
AssuranceAmerica disclosed in 2026 that a March data breach exposed nearly 7 million customers' insurance records, including driver's license numbers, across 12 US states.
Cybersecurity Dive07-09-2026
AssuranceAmerica disclosed a March 17 cyberattack in California and Maine filings that accessed IT systems and copied sensitive customer data for over 6.9 million people.
TechRepublic / Joseph Ofonagoro07-09-2026
AssuranceAmerica Data Breach: 6.9 Million Driver's License Numbers Exposed
AssuranceAmerica disclosed a breach affecting 6.9 million customers in Maine after March 17 discovery and June 15 investigation completion.
Security Affairs / Pierluigi Paganini07-09-2026
AssuranceAmerica disclosed in 2026 that a breach discovered on March 17 and concluded on June 15 exposed nearly 7 million driver's licenses after employee account compromise.
Class Action U07-21-2026
BUNN Commercial, LP notified Massachusetts recipients in July 2026 about a potential cybersecurity exposure involving personal information and offered TransUnion monitoring.
Emery Reddy07-15-2026
Case & Associates Properties reported a tenant data breach, with a Texas Attorney General filing dated July 14, 2026 citing at least 932 Texas residents affected.
Federman & Sherwood / Caroline Chesher07-10-2026
Federman & Sherwood investigated a YKK AP America Inc. data breach reported to the Texas Attorney General affecting about 368 Texas residents.
Fox News / Kurt Knutsson07-15-2026
AssuranceAmerica detected March 17, 2026 suspicious activity after a cyberattack that may have exposed personal data for 6,998,886 people, triggering Indiana and California notices and credit monitoring.
Zyphe / Michelangelo Frigo07-17-2026
AssuranceAmerica reported an unauthorized-access identity data breach affecting 6,998,886 people after employee credentials were compromised in 2026.

⭐⭐⭐

Claims Journal / Chad Hemenway07-02-2026
AssuranceAmerica began notifying customers in Atlanta after a March 17 targeted attack allowed an unauthorized third party to copy customer PII files.
WLTX07-06-2026
South Carolina Department of Consumer Affairs reported 41 business security breaches in early 2026 affecting 1.13 million residents and highlighted breach-notification and response steps.
Insurance Journal06-30-2026
AssuranceAmerica began consumer breach notifications after forensic review found a third-party attack copied customer PII in an Atlanta-based incident.
Claim Depot06-22-2026
AssuranceAmerica reported a 2026 data breach impacting at least 611,046 South Carolina residents after employee-targeted access to IT systems.
Claim Depot07-06-2026
Credit Acceptance Corp. disclosed a June 30, 2026 Massachusetts breach after a June 4, 2026 discovery, exposing names and Social Security numbers for affected consumers.
Claim Depot07-07-2026
YKK AP America Inc. notified the Texas Attorney General on July 7, 2026, about a data breach affecting 368 Texas residents' Social Security and payment data.
Claim Depot07-09-2026
Carlyle Senior Care Management Company Inc. disclosed a May 27, 2026 data breach to HHS affecting 4,060 individuals linked to South Carolina nursing facilities.
Claim Depot07-13-2026
LIA Insurance Administrators disclosed to the Vermont Attorney General on July 11, 2026 that a data breach exposed consumers credit and debit account information.
Claim Depot07-24-2026
Virginia Transportation Corp. confirmed in 2026 that a September 2025 network intrusion exposed PII and protected health information for residents in Rhode Island, Massachusetts, and Vermont.
Claim Depot07-24-2026
Hanscom Federal Credit Union reported on July 23, 2026 that a data breach affected 476 Massachusetts residents, with exposure of Social Security numbers and medical records.
Claim Depot07-24-2026
Navigate disclosed an undisclosed-cause data breach affecting U.S. consumers, sending July 21, 2026 notifications and offering Cyberscout-based credit monitoring and fraud assistance.
Claim Depot07-27-2026
Bridgeway Benefit Technologies LLC disclosed a data breach on unauthorized access to its systems affecting Massachusetts and Vermont residents, with Social Security numbers exposed in 2026.
Gizmodo / Bruce Gil07-08-2026
AssuranceAmerica notified customers after an unauthorized third party accessed insurance IT systems and copied files, exposing driver license data and potentially Social Security numbers.
SC Media07-09-2026
AssuranceAmerica disclosed March 17 to June 15 unauthorized access that exposed driver’s license numbers for about 6.9 million people.
InvestmentNews / Bruce Kelly04-24-2026
LPL Financial and Ameriprise Financial reported separate client data incidents to the Maine attorney general in incidents discovered in November and March.
TMCnet06-28-2026
AssuranceAmerica detected suspicious activity in March 2026 linked to a targeted cyberattack, and Edelson Lechtzin LLP is investigating potential class-action claims in Atlanta, Georgia.
Gs Legal06-30-2026
AssuranceAmerica discovered a March 16, 2026 third-party intrusion on internal servers on March 17, 2026, exposing South Carolina policyholder PII and prompting notifications around June 18.
The Lyon Firm07-23-2026
BUNN Commercial, LP notified the Massachusetts Attorney General and individuals in 2026, offering TransUnion monitoring after a cybersecurity event with possible personal data compromise.
The State07-09-2026
South Carolina Department of Consumer Affairs reported 41 data breaches between Jan 1 and Jun 30 affecting 1,131,320 residents.
Heraldonline / Damian Bertrand07-09-2026
South Carolina Department of Consumer Affairs reported 41 security breaches between Jan. 1 and June 30 affecting 1.13 million residents and issued response steps.
Class Action U07-17-2026
American Vanguard Corporation reported a data security incident affecting about 2,129 people, with incident occurrence on Nov 10, 2025 and reporting on Jun 30, 2026.
Post and Courier07-06-2026
South Carolina Department of Consumer Affairs reported 41 security-breach notifications for the first half of the year affecting 1.13 million residents and urged protective steps.
Post and Courier07-06-2026
SCDCA reported 41 security breach notices from businesses between January 1 and June 30, 2026, affecting 1.13 million South Carolina residents.
The Daily Hodl / Henry Kanapi07-09-2026
AssuranceAmerica disclosed a March 2026 cyberattack after detection on March 17, potentially exposing 6.9 million customers' insurance and driver-related data.
Schubert Jonckheer & Kolbe / Nelida Almeida04-24-2026
Ameriprise Financial reported an unauthorized March 2, 2026 data access affecting 47,876 individuals in Minnesota, with notifications starting April 17, 2026.
Databreaches06-28-2026
AssuranceAmerica Managing General Agency, LLC notified seven states after a March 17 data breach incident may have impacted at least 1.1 million residents.
The Malone Telegram06-19-2026
AssetMark, Inc. reported suspicious login activity discovered May 15, 2026 may have exposed customer files affecting about 570,000 individuals.
GS Legal06-30-2026
AssuranceAmerica reported unauthorized third-party access to internal servers on March 16, 2026, potentially exposing policyholder Social Security numbers, with South Carolina notifications mailed around June 18, 2026.
GS Legal07-17-2026
MCBS reported an incident discovered September 25, 2025, with potential unauthorized access to files containing protected health information and PII for over 295,000 South Carolinians.
Federman & Sherwood / Caroline Chesher07-14-2026
Federman & Sherwood investigates LIA Insurance Administrators after a Vermont Attorney General-reported breach exposed financial account and payment card data.
Federman & Sherwood / Caroline Chesher07-24-2026
Federman & Sherwood investigates a Virginia Transportation Corporation data breach reported to the Vermont Attorney General on July 24, 2026.
Pluang07-09-2026
AssuranceAmerica reported a phishing-caused data breach in March 2026, with notifications starting July 2026 for up to 6.9 million affected people.
AOL.com04-28-2026
Ameriprise notified nearly 48,000 customers in the United States after March 2-18, 2026 unauthorized access exposed personal and financial identifiers.
Cision PR Newswire04-24-2026
Schubert Jonckheer & Kolbe LLP investigates Ameriprise Financials March 2026 data breach after delayed notifications began April 17, 2026.
Cision PR Newswire07-09-2026
Edelson Lechtzin LLP is investigating potential class claims after hackers reportedly exposed data for up to 6.9 million people from AssuranceAmerica in Atlanta, Georgia, during 2026.
LawFuel06-02-2026
Ameriprise Financial breach response guidance covers credit-freeze mitigation steps and lawsuit deadlines after 16-day delayed detection in March 2026.
Msdlegal07-02-2026
AssuranceAmerica discovered suspicious activity on March 17, 2026 and later mailed breach notices after unauthorized copying of sensitive insurance and identity data across seven US states.
Woods Lonergan PLLC / James Woods07-13-2026
Victra sent breach notification letters starting July 9, 2026, after suspected WorldLeaks theft of Social Security numbers and financial account data affected over one million people in the United States.
Federman & Sherwood / Caroline Chesher04-20-2026
Ameriprise Financial notified the Maine Attorney General in April 2026 after unauthorized access to stored data, prompting Equifax identity monitoring and legal investigation.