Last Update: 09/22/2026 at 11:34 PM EST

AssuranceAmerica Identity Data Breach

Coverage from ScanComply, Class Action U, and others

AssuranceAmerica Identity Data Breach topic image

AssuranceAmerica's March 2026 intrusion exposed driver's license numbers and insurance-related records for 6,998,886 people, driving multistate notifications, consumer fraud precautions, and scrutiny of credential security and disclosure practices.

Key Articles3 of 63 articles

If you read one thing

It provides the clearest broad overview of the breach’s scale, access pathway, exposed data, and resulting risks.

Dark Web Informer

The evidence

It substantiates the incident’s scale while connecting employee credential compromise, exposed identity data, and the detection-to-notification interval.

Safestate

Best explainer

It adds focused explanation of the durable identity-data exposure and the roughly 115-day delay before consumer notification.

Zyphe / Michelangelo Frigo
Key Issues

Mass exposure of durable identity data

The breach affected 6,998,886 people and included driver's license numbers alongside insurance, vehicle, claims, and other personal records; some notices also referenced Social Security numbers. Because government identifiers are difficult to replace, the exposure creates persistent risks of identity theft, phishing, and fraudulent insurance activity.

Drawn from 4 articles

Employee credential compromise as the access pathway

Reporting consistently attributes the intrusion to unauthorized use of an employee account or credential, showing how concentrated employee access enabled broad copying of insurer files. The precise credential-theft method and the company's multifactor-authentication status remain unconfirmed, limiting assessment of the control failure.

Drawn from 4 articles

Extended detection-to-notification interval

AssuranceAmerica detected suspicious activity on March 17, completed its affected-file review on June 15, and began consumer notifications in July. The roughly three-month review period and reported 115-day interval between detection and notification delayed individuals' ability to take protective measures, although the company has offered credit monitoring.

Drawn from 4 articles

Looking Back
127 Day Timeline
Apr 20May 18Jun 15Jun 29Jul 27Aug 24
The Story So Far
No material change

The new articles reiterate the previously established scale, credential-based access, and identity-data exposure without establishing a material change to the incident.

Previously

AssuranceAmerica disclosed that an attacker used compromised employee credentials to access its systems and copy files affecting 6,998,886 people. The exposed information includes contact details, insurance and vehicle records, claims information, driver’s license numbers, and, in some cases, Social Security numbers or tax IDs. The incident highlights the extended identity-theft and fraud risks created when insurers lose sensitive records, while the attacker’s identity and the precise credential-theft method remain unconfirmed.

History
09/20/2026

The story now includes broader multistate regulatory exposure, with California reporting and possible class-action scrutiny added to the breach response.

07/29/2026

The story is now more specific about timing and oversight: AssuranceAmerica says the credential-based intrusion was detected on March 17, the review finished June 15, and consumer notices began in July. It also adds state filing context and clarifies that several key details, including the theft method and ransom/public-posting status, remain unconfirmed.

All Articles63 articles
Important36 articles · CI Score 60 and above
ScanComply
AssuranceAmerica confirmed in the United States during August 2026 that malicious activity targeting one employee exposed nearly 7 million driver's licence numbers.
8/21/2026 • Data Breaches & Exposure Events • General
Class Action U
BUNN Commercial, LP notified Massachusetts recipients in July 2026 about a potential cybersecurity exposure involving personal information and offered TransUnion monitoring.
7/21/2026 • Data Breaches & Exposure Events • General
Zyphe / Michelangelo Frigo
AssuranceAmerica reported an unauthorized-access identity data breach affecting 6,998,886 people after employee credentials were compromised in 2026.
7/17/2026 • Data Breaches & Exposure Events • General
ProgramBusiness / Maria Valdez Haubrich
AssuranceAmerica disclosed in 2026 that a phishing-led intrusion led to unauthorized copying of data files affecting 6,998,886 people.
7/16/2026 • Data Breaches & Exposure Events • General
Emery Reddy
Case & Associates Properties reported a tenant data breach, with a Texas Attorney General filing dated July 14, 2026 citing at least 932 Texas residents affected.
7/15/2026 • Data Breaches & Exposure Events • General
TechTimes
AssuranceAmerica notified consumers starting July 10 after a 2026 credential compromise exposed driver license data for millions of customers and policy-associated individuals.
7/12/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood / Caroline Chesher
Federman & Sherwood investigated a YKK AP America Inc. data breach reported to the Texas Attorney General affecting about 368 Texas residents.
7/10/2026 • Data Breaches & Exposure Events • General
Safestate
AssuranceAmerica notified 6,998,886 affected individuals after intrusion starting March 16 exposed driver license and insurance claims data.
7/10/2026 • Data Breaches & Exposure Events • General
Cybersecurity Dive
AssuranceAmerica disclosed a March 17 cyberattack in California and Maine filings that accessed IT systems and copied sensitive customer data for over 6.9 million people.
7/9/2026 • Cybersecurity Tech (Privacy-Relevant) • General
GBhackers
AssuranceAmerica disclosed a phishing-linked breach detected March 17, 2026, exposing driver license and insurance records for nearly 7 million people nationwide.
7/9/2026 • Data Breaches & Exposure Events • General
McAfee / Brooke Seipel
AssuranceAmerica reported a data breach affecting 6.9 million customers after a compromised employee account exposed driver license numbers and claims data.
7/9/2026 • Data Breaches & Exposure Events • General
Insurance Business / Josh Recamara
AssuranceAmerica disclosed a 2026 breach detected March 17, 2026, with breach filings revised to about 6.9 million people and class actions under investigation.
7/9/2026 • Data Breaches & Exposure Events • General
Malwarebytes / Pieter Arntz
AssuranceAmerica disclosed on a breach timeline beginning March 17 that phishing led to theft of customer personal information and driver license numbers affecting up to 6.9 million people.
7/9/2026 • Data Breaches & Exposure Events • General
Security Affairs / Pierluigi Paganini
AssuranceAmerica disclosed in 2026 that a breach discovered on March 17 and concluded on June 15 exposed nearly 7 million driver's licenses after employee account compromise.
7/9/2026 • Data Breaches & Exposure Events • General
Lifehacker
AssuranceAmerica disclosed in 2026 that a March data breach exposed nearly 7 million customers' insurance records, including driver's license numbers, across 12 US states.
7/8/2026 • Data Breaches & Exposure Events • General
Lifehacker
AssuranceAmerica disclosed a March 17 data breach affecting nearly 7 million policyholders, exposing insurance and driver's license numbers, with notices starting July 10.
7/8/2026 • Data Breaches & Exposure Events • General
Dark Web Informer
AssuranceAmerica confirmed a March 17, 2026 data breach affecting 6.99 million people in the United States, including driver license numbers, with notifications expected July 10.
7/8/2026 • Data Breaches & Exposure Events • General
Wealth Management / Patrick Donachie
LPL Financial notified the Maine Attorney General in 2025 of a phishing malware breach that enabled unauthorized securities transactions in a small set of advisor-linked client accounts.
4/24/2026 • Cybersecurity (Privacy-Relevant) • General
Fox News / Kurt Knutsson
AssuranceAmerica detected March 17, 2026 suspicious activity after a cyberattack that may have exposed personal data for 6,998,886 people, triggering Indiana and California notices and credit monitoring.
7/15/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Sergiu Gatlan
AssuranceAmerica disclosed a 2026 incident affecting 6,998,886 drivers after attackers accessed and copied insurer IT data, including policy and license information.
7/9/2026 • Data Breaches & Exposure Events • General
TechRadar
AssuranceAmerica reported to the Maine Attorney General a cyberattack detected March 17, 2026 that exposed driver license and insurance account data for 6,998,886 customers.
7/9/2026 • Data Breaches & Exposure Events • General
TechCrunch
AssuranceAmerica disclosed a data breach discovered March 17 that stole driver license numbers and personal data from about 6.99 million people, with notifications planned for July 10.
7/8/2026 • Data Breaches & Exposure Events • General
Security Boulevard / Evan Rowe
Ameriprise Financial disclosed a March 2026 breach affecting nearly 48,000 people after unauthorized access began March 2 and was detected March 18.
5/3/2026 • Data Breaches & Exposure Events • General
Simply Secure Group
AssuranceAmerica disclosed in 2026 that attackers accessed company systems in Atlanta between March 16 and March 17, exposing personal information of 6,998,886 people.
8/24/2026 • Data Breaches & Exposure Events • General
The Lyon Firm
BUNN Commercial, LP notified the Massachusetts Attorney General and individuals in 2026, offering TransUnion monitoring after a cybersecurity event with possible personal data compromise.
7/23/2026 • Data Breaches & Exposure Events • General
GS Legal
MCBS reported an incident discovered September 25, 2025, with potential unauthorized access to files containing protected health information and PII for over 295,000 South Carolinians.
7/17/2026 • Data Breaches & Exposure Events • General
Class Action U
American Vanguard Corporation reported a data security incident affecting about 2,129 people, with incident occurrence on Nov 10, 2025 and reporting on Jun 30, 2026.
7/17/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood / Caroline Chesher
Federman & Sherwood investigates LIA Insurance Administrators after a Vermont Attorney General-reported breach exposed financial account and payment card data.
7/14/2026 • Data Breaches & Exposure Events • General
Cision PR Newswire
Edelson Lechtzin LLP is investigating potential class claims after hackers reportedly exposed data for up to 6.9 million people from AssuranceAmerica in Atlanta, Georgia, during 2026.
7/9/2026 • Data Breaches & Exposure Events • General
Pluang
AssuranceAmerica reported a phishing-caused data breach in March 2026, with notifications starting July 2026 for up to 6.9 million affected people.
7/9/2026 • Data Breaches & Exposure Events • General
Gs Legal
AssuranceAmerica discovered a March 16, 2026 third-party intrusion on internal servers on March 17, 2026, exposing South Carolina policyholder PII and prompting notifications around June 18.
6/30/2026 • Data Breaches & Exposure Events • General
LawFuel
Ameriprise Financial breach response guidance covers credit-freeze mitigation steps and lawsuit deadlines after 16-day delayed detection in March 2026.
6/2/2026 • Data Breaches & Exposure Events • General
Claim Depot
Bridgeway Benefit Technologies LLC disclosed a data breach on unauthorized access to its systems affecting Massachusetts and Vermont residents, with Social Security numbers exposed in 2026.
7/27/2026 • Data Breaches & Exposure Events • General
Claim Depot
Hanscom Federal Credit Union reported on July 23, 2026 that a data breach affected 476 Massachusetts residents, with exposure of Social Security numbers and medical records.
7/24/2026 • Data Breaches & Exposure Events • General
Claim Depot
Virginia Transportation Corp. confirmed in 2026 that a September 2025 network intrusion exposed PII and protected health information for residents in Rhode Island, Massachusetts, and Vermont.
7/24/2026 • Data Breaches & Exposure Events • General
Claim Depot
Navigate disclosed an undisclosed-cause data breach affecting U.S. consumers, sending July 21, 2026 notifications and offering Cyberscout-based credit monitoring and fraud assistance.
7/24/2026 • Data Breaches & Exposure Events • General
Interesting27 articles · CI Score 45–59
Woods Lonergan PLLC / James Woods
Victra sent breach notification letters starting July 9, 2026, after suspected WorldLeaks theft of Social Security numbers and financial account data affected over one million people in the United States.
7/13/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood / Caroline Chesher
Federman & Sherwood investigates a Virginia Transportation Corporation data breach reported to the Vermont Attorney General on July 24, 2026.
7/24/2026 • Data Breaches & Exposure Events • General
SC Media
AssuranceAmerica disclosed March 17 to June 15 unauthorized access that exposed driver’s license numbers for about 6.9 million people.
7/9/2026 • Data Breaches & Exposure Events • General
Heraldonline / Damian Bertrand
South Carolina Department of Consumer Affairs reported 41 security breaches between Jan. 1 and June 30 affecting 1.13 million residents and issued response steps.
7/9/2026 • Data Breaches & Exposure Events • General
The Daily Hodl / Henry Kanapi
AssuranceAmerica disclosed a March 2026 cyberattack after detection on March 17, potentially exposing 6.9 million customers' insurance and driver-related data.
7/9/2026 • Data Breaches & Exposure Events • General
The State
South Carolina Department of Consumer Affairs reported 41 data breaches between Jan 1 and Jun 30 affecting 1,131,320 residents.
7/9/2026 • Data Breaches & Exposure Events • General
Post and Courier
SCDCA reported 41 security breach notices from businesses between January 1 and June 30, 2026, affecting 1.13 million South Carolina residents.
7/6/2026 • Data Breaches & Exposure Events • General
WLTX
South Carolina Department of Consumer Affairs reported 41 business security breaches in early 2026 affecting 1.13 million residents and highlighted breach-notification and response steps.
7/6/2026 • Data Breaches & Exposure Events • General
Post and Courier
South Carolina Department of Consumer Affairs reported 41 security-breach notifications for the first half of the year affecting 1.13 million residents and urged protective steps.
7/6/2026 • Data Breaches & Exposure Events • General
Claims Journal / Chad Hemenway
AssuranceAmerica began notifying customers in Atlanta after a March 17 targeted attack allowed an unauthorized third party to copy customer PII files.
7/2/2026 • Data Breaches & Exposure Events • General
GS Legal
AssuranceAmerica reported unauthorized third-party access to internal servers on March 16, 2026, potentially exposing policyholder Social Security numbers, with South Carolina notifications mailed around June 18, 2026.
6/30/2026 • Data Breaches & Exposure Events • General
Databreaches
AssuranceAmerica Managing General Agency, LLC notified seven states after a March 17 data breach incident may have impacted at least 1.1 million residents.
6/28/2026 • Data Breaches & Exposure Events • General
TMCnet
AssuranceAmerica detected suspicious activity in March 2026 linked to a targeted cyberattack, and Edelson Lechtzin LLP is investigating potential class-action claims in Atlanta, Georgia.
6/28/2026 • Data Breaches & Exposure Events • General
The Malone Telegram
AssetMark, Inc. reported suspicious login activity discovered May 15, 2026 may have exposed customer files affecting about 570,000 individuals.
6/19/2026 • Data Breaches & Exposure Events • General
AOL.com
Ameriprise notified nearly 48,000 customers in the United States after March 2-18, 2026 unauthorized access exposed personal and financial identifiers.
4/28/2026 • Data Breaches & Exposure Events • General
Cision PR Newswire
Schubert Jonckheer & Kolbe LLP investigates Ameriprise Financials March 2026 data breach after delayed notifications began April 17, 2026.
4/24/2026 • Data Breaches & Exposure Events • General
Schubert Jonckheer & Kolbe / Nelida Almeida
Ameriprise Financial reported an unauthorized March 2, 2026 data access affecting 47,876 individuals in Minnesota, with notifications starting April 17, 2026.
4/24/2026 • Data Breaches & Exposure Events • General
InvestmentNews / Bruce Kelly
LPL Financial and Ameriprise Financial reported separate client data incidents to the Maine attorney general in incidents discovered in November and March.
4/24/2026 • Cybersecurity (Privacy-Relevant) • General
Claim Depot
LIA Insurance Administrators disclosed to the Vermont Attorney General on July 11, 2026 that a data breach exposed consumers credit and debit account information.
7/13/2026 • Data Breaches & Exposure Events • General
Claim Depot
Carlyle Senior Care Management Company Inc. disclosed a May 27, 2026 data breach to HHS affecting 4,060 individuals linked to South Carolina nursing facilities.
7/9/2026 • Data Breaches & Exposure Events • General
Gizmodo / Bruce Gil
AssuranceAmerica notified customers after an unauthorized third party accessed insurance IT systems and copied files, exposing driver license data and potentially Social Security numbers.
7/8/2026 • Data Breaches & Exposure Events • General
Claim Depot
YKK AP America Inc. notified the Texas Attorney General on July 7, 2026, about a data breach affecting 368 Texas residents' Social Security and payment data.
7/7/2026 • Data Breaches & Exposure Events • General
Claim Depot
Credit Acceptance Corp. disclosed a June 30, 2026 Massachusetts breach after a June 4, 2026 discovery, exposing names and Social Security numbers for affected consumers.
7/6/2026 • Data Breaches & Exposure Events • General
Insurance Journal
AssuranceAmerica began consumer breach notifications after forensic review found a third-party attack copied customer PII in an Atlanta-based incident.
6/30/2026 • Data Breaches & Exposure Events • General
Claim Depot
AssuranceAmerica reported a 2026 data breach impacting at least 611,046 South Carolina residents after employee-targeted access to IT systems.
6/22/2026 • Data Breaches & Exposure Events • General
Msdlegal
AssuranceAmerica discovered suspicious activity on March 17, 2026 and later mailed breach notices after unauthorized copying of sensitive insurance and identity data across seven US states.
7/2/2026 • Data Breaches & Exposure Events • General
Federman & Sherwood / Caroline Chesher
Ameriprise Financial notified the Maine Attorney General in April 2026 after unauthorized access to stored data, prompting Equifax identity monitoring and legal investigation.
4/20/2026 • Data Breaches & Exposure Events • General