AssuranceAmerica Identity Data BreachAssuranceAmerica Identity Data BreachCoverage from ScanComply, Class Action U, and others
00/00/0000
DailyWeekly
AssuranceAmerica's March 2026 intrusion exposed driver's license numbers and insurance-related records for 6,998,886 people, driving multistate notifications, consumer fraud precautions, and scrutiny of credential security and disclosure practices.
It substantiates the incident’s scale while connecting employee credential compromise, exposed identity data, and the detection-to-notification interval.
It adds focused explanation of the durable identity-data exposure and the roughly 115-day delay before consumer notification.
Zyphe / Michelangelo Frigo
Key Issues
01
Mass exposure of durable identity data
The breach affected 6,998,886 people and included driver's license numbers alongside insurance, vehicle, claims, and other personal records; some notices also referenced Social Security numbers. Because government identifiers are difficult to replace, the exposure creates persistent risks of identity theft, phishing, and fraudulent insurance activity.
Drawn from 4 articles
02
Employee credential compromise as the access pathway
Reporting consistently attributes the intrusion to unauthorized use of an employee account or credential, showing how concentrated employee access enabled broad copying of insurer files. The precise credential-theft method and the company's multifactor-authentication status remain unconfirmed, limiting assessment of the control failure.
Drawn from 4 articles
03
Extended detection-to-notification interval
AssuranceAmerica detected suspicious activity on March 17, completed its affected-file review on June 15, and began consumer notifications in July. The roughly three-month review period and reported 115-day interval between detection and notification delayed individuals' ability to take protective measures, although the company has offered credit monitoring.
Drawn from 4 articles
Looking Back
127 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
Apr 20
May 11
Jun 1
Jun 22
Jul 13
Aug 3
Aug 24
The Story So Far
No material change
The new articles reiterate the previously established scale, credential-based access, and identity-data exposure without establishing a material change to the incident.
Previously
AssuranceAmerica disclosed that an attacker used compromised employee credentials to access its systems and copy files affecting 6,998,886 people. The exposed information includes contact details, insurance and vehicle records, claims information, driver’s license numbers, and, in some cases, Social Security numbers or tax IDs. The incident highlights the extended identity-theft and fraud risks created when insurers lose sensitive records, while the attacker’s identity and the precise credential-theft method remain unconfirmed.
History
09/20/2026
The story now includes broader multistate regulatory exposure, with California reporting and possible class-action scrutiny added to the breach response.
07/29/2026
The story is now more specific about timing and oversight: AssuranceAmerica says the credential-based intrusion was detected on March 17, the review finished June 15, and consumer notices began in July. It also adds state filing context and clarifies that several key details, including the theft method and ransom/public-posting status, remain unconfirmed.
AssuranceAmerica confirmed in the United States during August 2026 that malicious activity targeting one employee exposed nearly 7 million driver's licence numbers.
8/21/2026 • Data Breaches & Exposure Events • General
BUNN Commercial, LP notified Massachusetts recipients in July 2026 about a potential cybersecurity exposure involving personal information and offered TransUnion monitoring.
7/21/2026 • Data Breaches & Exposure Events • General
Case & Associates Properties reported a tenant data breach, with a Texas Attorney General filing dated July 14, 2026 citing at least 932 Texas residents affected.
7/15/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica notified consumers starting July 10 after a 2026 credential compromise exposed driver license data for millions of customers and policy-associated individuals.
7/12/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed a March 17 cyberattack in California and Maine filings that accessed IT systems and copied sensitive customer data for over 6.9 million people.
7/9/2026 • Cybersecurity Tech (Privacy-Relevant) • General
AssuranceAmerica disclosed a phishing-linked breach detected March 17, 2026, exposing driver license and insurance records for nearly 7 million people nationwide.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica reported a data breach affecting 6.9 million customers after a compromised employee account exposed driver license numbers and claims data.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed a 2026 breach detected March 17, 2026, with breach filings revised to about 6.9 million people and class actions under investigation.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed on a breach timeline beginning March 17 that phishing led to theft of customer personal information and driver license numbers affecting up to 6.9 million people.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed in 2026 that a breach discovered on March 17 and concluded on June 15 exposed nearly 7 million driver's licenses after employee account compromise.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed in 2026 that a March data breach exposed nearly 7 million customers' insurance records, including driver's license numbers, across 12 US states.
7/8/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed a March 17 data breach affecting nearly 7 million policyholders, exposing insurance and driver's license numbers, with notices starting July 10.
7/8/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica confirmed a March 17, 2026 data breach affecting 6.99 million people in the United States, including driver license numbers, with notifications expected July 10.
7/8/2026 • Data Breaches & Exposure Events • General
LPL Financial notified the Maine Attorney General in 2025 of a phishing malware breach that enabled unauthorized securities transactions in a small set of advisor-linked client accounts.
4/24/2026 • Cybersecurity (Privacy-Relevant) • General
AssuranceAmerica detected March 17, 2026 suspicious activity after a cyberattack that may have exposed personal data for 6,998,886 people, triggering Indiana and California notices and credit monitoring.
7/15/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed a 2026 incident affecting 6,998,886 drivers after attackers accessed and copied insurer IT data, including policy and license information.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica reported to the Maine Attorney General a cyberattack detected March 17, 2026 that exposed driver license and insurance account data for 6,998,886 customers.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed a data breach discovered March 17 that stole driver license numbers and personal data from about 6.99 million people, with notifications planned for July 10.
7/8/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed in 2026 that attackers accessed company systems in Atlanta between March 16 and March 17, exposing personal information of 6,998,886 people.
8/24/2026 • Data Breaches & Exposure Events • General
BUNN Commercial, LP notified the Massachusetts Attorney General and individuals in 2026, offering TransUnion monitoring after a cybersecurity event with possible personal data compromise.
7/23/2026 • Data Breaches & Exposure Events • General
MCBS reported an incident discovered September 25, 2025, with potential unauthorized access to files containing protected health information and PII for over 295,000 South Carolinians.
7/17/2026 • Data Breaches & Exposure Events • General
American Vanguard Corporation reported a data security incident affecting about 2,129 people, with incident occurrence on Nov 10, 2025 and reporting on Jun 30, 2026.
7/17/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood investigates LIA Insurance Administrators after a Vermont Attorney General-reported breach exposed financial account and payment card data.
7/14/2026 • Data Breaches & Exposure Events • General
Edelson Lechtzin LLP is investigating potential class claims after hackers reportedly exposed data for up to 6.9 million people from AssuranceAmerica in Atlanta, Georgia, during 2026.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica discovered a March 16, 2026 third-party intrusion on internal servers on March 17, 2026, exposing South Carolina policyholder PII and prompting notifications around June 18.
6/30/2026 • Data Breaches & Exposure Events • General
Ameriprise Financial breach response guidance covers credit-freeze mitigation steps and lawsuit deadlines after 16-day delayed detection in March 2026.
6/2/2026 • Data Breaches & Exposure Events • General
Bridgeway Benefit Technologies LLC disclosed a data breach on unauthorized access to its systems affecting Massachusetts and Vermont residents, with Social Security numbers exposed in 2026.
7/27/2026 • Data Breaches & Exposure Events • General
Hanscom Federal Credit Union reported on July 23, 2026 that a data breach affected 476 Massachusetts residents, with exposure of Social Security numbers and medical records.
7/24/2026 • Data Breaches & Exposure Events • General
Virginia Transportation Corp. confirmed in 2026 that a September 2025 network intrusion exposed PII and protected health information for residents in Rhode Island, Massachusetts, and Vermont.
7/24/2026 • Data Breaches & Exposure Events • General
Navigate disclosed an undisclosed-cause data breach affecting U.S. consumers, sending July 21, 2026 notifications and offering Cyberscout-based credit monitoring and fraud assistance.
7/24/2026 • Data Breaches & Exposure Events • General
Victra sent breach notification letters starting July 9, 2026, after suspected WorldLeaks theft of Social Security numbers and financial account data affected over one million people in the United States.
7/13/2026 • Data Breaches & Exposure Events • General
South Carolina Department of Consumer Affairs reported 41 security breaches between Jan. 1 and June 30 affecting 1.13 million residents and issued response steps.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica disclosed a March 2026 cyberattack after detection on March 17, potentially exposing 6.9 million customers' insurance and driver-related data.
7/9/2026 • Data Breaches & Exposure Events • General
South Carolina Department of Consumer Affairs reported 41 business security breaches in early 2026 affecting 1.13 million residents and highlighted breach-notification and response steps.
7/6/2026 • Data Breaches & Exposure Events • General
South Carolina Department of Consumer Affairs reported 41 security-breach notifications for the first half of the year affecting 1.13 million residents and urged protective steps.
7/6/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica reported unauthorized third-party access to internal servers on March 16, 2026, potentially exposing policyholder Social Security numbers, with South Carolina notifications mailed around June 18, 2026.
6/30/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica Managing General Agency, LLC notified seven states after a March 17 data breach incident may have impacted at least 1.1 million residents.
6/28/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica detected suspicious activity in March 2026 linked to a targeted cyberattack, and Edelson Lechtzin LLP is investigating potential class-action claims in Atlanta, Georgia.
6/28/2026 • Data Breaches & Exposure Events • General
Ameriprise notified nearly 48,000 customers in the United States after March 2-18, 2026 unauthorized access exposed personal and financial identifiers.
4/28/2026 • Data Breaches & Exposure Events • General
Ameriprise Financial reported an unauthorized March 2, 2026 data access affecting 47,876 individuals in Minnesota, with notifications starting April 17, 2026.
4/24/2026 • Data Breaches & Exposure Events • General
LPL Financial and Ameriprise Financial reported separate client data incidents to the Maine attorney general in incidents discovered in November and March.
4/24/2026 • Cybersecurity (Privacy-Relevant) • General
LIA Insurance Administrators disclosed to the Vermont Attorney General on July 11, 2026 that a data breach exposed consumers credit and debit account information.
7/13/2026 • Data Breaches & Exposure Events • General
Carlyle Senior Care Management Company Inc. disclosed a May 27, 2026 data breach to HHS affecting 4,060 individuals linked to South Carolina nursing facilities.
7/9/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica notified customers after an unauthorized third party accessed insurance IT systems and copied files, exposing driver license data and potentially Social Security numbers.
7/8/2026 • Data Breaches & Exposure Events • General
YKK AP America Inc. notified the Texas Attorney General on July 7, 2026, about a data breach affecting 368 Texas residents' Social Security and payment data.
7/7/2026 • Data Breaches & Exposure Events • General
Credit Acceptance Corp. disclosed a June 30, 2026 Massachusetts breach after a June 4, 2026 discovery, exposing names and Social Security numbers for affected consumers.
7/6/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica began consumer breach notifications after forensic review found a third-party attack copied customer PII in an Atlanta-based incident.
6/30/2026 • Data Breaches & Exposure Events • General
AssuranceAmerica discovered suspicious activity on March 17, 2026 and later mailed breach notices after unauthorized copying of sensitive insurance and identity data across seven US states.
7/2/2026 • Data Breaches & Exposure Events • General
Ameriprise Financial notified the Maine Attorney General in April 2026 after unauthorized access to stored data, prompting Equifax identity monitoring and legal investigation.
4/20/2026 • Data Breaches & Exposure Events • General