EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-assuranceamerica-breach
048/430

File EL-0383HighResolvedData Breach / Unauthorised Access / Employee-Targeted Attack

AssuranceAmerica Data Breach

Also filed as AssuranceAmerica Managing General Agency Breach · AssuranceAmerica Driver’s License Breach

Unauthorised access to AssuranceAmerica systems following a targeted attack on an employee, resulting in the exfiltration of personal and insurance-related data belonging to approximately 6.9 million individuals.

  • #insurance
  • #pii
  • #driver-s-license-numbers
  • #social-security-numbers
  • #auto-insurance-records
  • #claims-data
Notoriety8/10
Event
16 Mar 2026
Disclosed
18 Jun 2026
Target
AssuranceAmerica
Scale
7.0M people
Status
Resolved

01Summary

On 16 March 2026 malicious activity targeted an AssuranceAmerica employee. Suspicious activity was detected the following day (17 March). An unauthorised third party accessed company systems and copied data files. External forensic investigation concluded on 15 June 2026. The company determined that names, contact information, driver’s licence numbers, Social Security numbers / Tax IDs, automobile insurance policy and account details, driver and vehicle information, and claims-related data had been taken. Notifications to affected individuals began around mid-to-late June and continued into July 2026. The incident is one of the largest reported exposures of U.S. driver’s licence numbers in 2026.

02Background

AssuranceAmerica is a U.S. managing general agency that provides personal auto, renters and commercial auto insurance through a network of thousands of independent agents across multiple states.

03Key revelations

  1. 01One of the largest reported U.S. driver’s licence number exposures of 2026.
  2. 02Attack began with compromise of a single employee’s credentials.

04Technical analysis

Initial access via targeted attack on a single employee (consistent with phishing / credential compromise). Compromised credentials were later disabled. Exact tools or further lateral movement details have not been publicly released.

Attack vector
Targeted employee compromise (likely phishing / credential theft)
Attack method
Unauthorised access and bulk data file copying
Initial access
Valid Accounts (compromised employee credentials)
Exfiltration
Copying of data files

05Threat actor

No public attribution.

06Victims and impact

Countries affected

  • United States

07Data exposed

Data types

  • PII
  • Names
  • Contact information
  • Driver’s license numbers
  • Social Security numbers / Tax IDs
  • Automobile insurance policy and account information
  • Driver and vehicle information
  • Claims-related information

08Financial damage

Notification costs, credit monitoring, potential class-action exposure, and regulatory scrutiny. Driver’s licence numbers are particularly useful for identity fraud.

09Timeline

  1. 2026-03-16Malicious activity targeting an employee.
  2. 2026-03-17Suspicious activity detected; investigation begins.
  3. 2026-06-15Forensic review of accessed files completed.
  4. 2026-06-18Notifications to affected individuals begin.

10Reaction and fallout

Public reaction

Concern over the scale of driver’s licence and SSN exposure and the multi-month gap between detection and completion of the impact assessment.

11Legal

State notifications filed; class-action investigations reported. Credit monitoring typically offered in such cases.

Civil lawsuits

  • Class-action investigations launched

12Aftermath

Security improvements

  • Compromised credentials disabled
  • Affected systems taken offline
  • Additional security measures implemented post-incident

13Significance and legacy

Significance

Large-scale insurance-sector breach notable for the volume of driver’s licence numbers and Social Security numbers exposed.

14Disclosure and media

Publishing organisations

  • TechCrunch
  • Malwarebytes
  • Insurance Business
  • DataBreaches.net

15Field notes

  1. 01Reported as the largest known spill of U.S. driver’s licence numbers in 2026 at the time of disclosure.
  2. 02Initial access traced to a single targeted employee.

16Resolution

Investigation concluded 15 June 2026. Notifications to affected individuals began shortly afterwards and continued into July.

17Sources

Official documents

  • State attorney general breach notifications
  • AssuranceAmerica breach notice letters

References

  1. [1]TechCrunch
  2. [2]Malwarebytes
  3. [3]Insurance Business Magazine
  4. [4]State AG filings
Fact sheetEL-0383

Dates

Event
16 Mar 2026
Started
16 Mar 2026
Ended
17 Mar 2026
Discovered
17 Mar 2026
Disclosed
18 Jun 2026
Resolved
15 Jun 2026
Ongoing
No

Target

Organisation
AssuranceAmerica Managing General Agency, LLC
Type
Insurance / Managing General Agency
Sector
Insurance
Country
United States

Actor

Motivation
Unknown (data theft)
Arrested
No
Convicted
No

Data

People
6,990,000
Records
6,990,000
Sensitivity
High
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.