Last Update: 09/22/2026 at 11:34 PM EST

AssuranceAmerica Identity Data Breach

Coverage from ScanComply, Class Action U, and others

AssuranceAmerica Identity Data Breach topic image

AssuranceAmerica's March 2026 intrusion exposed driver's license numbers and insurance-related records for 6,998,886 people, driving multistate notifications, consumer fraud precautions, and scrutiny of credential security and disclosure practices.

History
09/20/20263 new articles

The story now includes broader multistate regulatory exposure, with California reporting and possible class-action scrutiny added to the breach response.

07/29/20260 new articles

The story is now more specific about timing and oversight: AssuranceAmerica says the credential-based intrusion was detected on March 17, the review finished June 15, and consumer notices began in July. It also adds state filing context and clarifies that several key details, including the theft method and ransom/public-posting status, remain unconfirmed.

07/28/20261 new articles

The story has narrowed from a broad pattern of insurer and financial-sector breach disclosures to a specific, large AssuranceAmerica incident with confirmed file copying affecting nearly 7 million people. The new detail is the attack method, the size of the affected population, and the timeline of detection and notification.

  • AssuranceAmerica disclosed 6,998,886 affected individuals.
  • Compromised employee credentials were used to access systems.
  • Files containing insurance, vehicle, claims, and identity data were copied.
  • Suspicious activity was detected March 17, 2026; notices began in July.
  • No named criminal group or dark-web publication has been confirmed.
07/26/20265 new articles

The story has broadened from a single large AssuranceAmerica breach to a wider cluster of recent privacy and breach disclosures across financial and insurance firms. The new emphasis is on recurring patterns in notification delays, regulator filings, and credit-monitoring responses rather than the original incident alone.

  • Multiple financial and insurance organizations disclosed new breach or access incidents.
  • Sensitive data now includes account numbers and some medical information.
  • State attorney general filings, especially Maine, are a common disclosure channel.
  • Several incidents involved delayed consumer notice or regulatory reporting.
  • Follow-on lawsuits and investigations are now part of the coverage.
07/23/20261 new articles

The main update is that AssuranceAmerica’s response is now more complete: it has moved from disclosure to active remediation and notifications, while filings also clarify the timeline of detection and review. The story is otherwise largely unchanged, with the attacker still unidentified and the credential source still unconfirmed.

07/21/20263 new articles

The story has narrowed from a broader cluster of financial and insurance breaches to a more detailed account of the AssuranceAmerica incident, with specific access method, timeline, and mitigation steps now confirmed. The new version also materially strengthens the breach’s scale and exposure details, while leaving the attacker’s identity and root cause unconfirmed.

  • 6,998,886 people were affected by the AssuranceAmerica breach.
  • An employee credential enabled unauthorized access and file copying.
  • Malicious activity was identified on March 17, 2026.
  • Some exposed records included tax IDs.
  • AssuranceAmerica disabled credentials and reset passwords after detection.
07/17/202642 new articles

The story has broadened into a much larger, more current breach wave centered on Ameriprise and especially AssuranceAmerica, with far larger affected populations and more explicit attention to notification delays and identity-document exposure. What was previously a general pattern of financial-services breaches is now framed as a dense, operationally active set of incidents drawing regulatory filings and legal scrutiny.

  • AssuranceAmerica disclosed exposure affecting nearly 7 million people.
  • Driver's license data was compromised in the AssuranceAmerica breach.
  • Several incidents involved weeks or months between intrusion and consumer notice.
  • Maine and other state attorney general filings are central to disclosure.
  • Plaintiffs' firms are investigating Ameriprise and AssuranceAmerica claims.
06/29/20260 new articles

The story is reframed from predominantly stored-file breaches to a broader mix of phishing- and malware-driven compromises, including one case involving unauthorized securities transactions and transfers. The overall pattern of regulatory notification, remediation, monitoring, and litigation remains largely confirmed rather than materially changed.

06/23/20263 new articles

The story has broadened from a mostly Ameriprise/LPL breach cluster into a larger financial-services breach pattern that now includes AssetMark and AssuranceAmerica, with much bigger affected populations and a clearer litigation/regulatory dimension. The current framing also sharpens the compliance issue around delayed notice to state authorities and customers.

  • AssetMark and AssuranceAmerica are newly included as breach subjects.
  • Affected populations now include about 570,000 and 611,046 people.
  • State attorneys general are now explicitly part of the story.
  • Delay is framed as a compliance issue with state notice rules.
  • The attack pattern is now characterized as credential or phishing-related.
05/11/2026Topic Formed

Recent coverage is dominated by financial-sector breach disclosures, especially Ameriprise and LPL Financial, with repeated emphasis on unauthorized access, sensitive data exposure, delayed notification, and follow-on monitoring or legal review. The signal is coherent and current, with little historical drift and strong overlap around breach response, identity theft risk, and regulatory filing requirements.