Dormant High impact Data breach Checked 2w ago

AssuranceAmerica breach exposes 7 million driver records

U.S. auto insurer AssuranceAmerica confirmed hackers broke into its systems in March 2026 after compromising an employee account, and stole personal data including driver's license numbers, and for some people Social Security numbers, on nearly 7 million people. State breach filings put the number at 6,998,886, making it one of the largest known U.S. driver's license data leaks reported this year. The company has been notifying affected customers and former customers, and multiple law firms have opened class-action investigations.

Started
Mar 16, 2026
Latest activity
Jul 17, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States
Sectors
Finance, Consumers
Scale
one U.S. auto insurer, AssuranceAmerica, affecting nearly 7 million people

Current status

No credible reporting found after the July 17, 2026 PCMag roundup; searches on 2026-08-28 for AssuranceAmerica breach, lawsuits, settlement, and August updates returned only prior known coverage, a July 31 rehash listicle with no new facts, and the company's own site.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Impact

Attackers accessed personal information tied to auto, renters, and commercial auto insurance records, including driver's license numbers for about 6.99 million people, and Social Security numbers for some of those people.

What to do

If you have or had an AssuranceAmerica policy, read any breach notification letter you receive, enroll in the credit monitoring it offers, consider a credit freeze, and watch for signs your driver's license number or Social Security number is being misused.

Timeline

  1. Aug 31, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Aug 23, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  3. Jul 17, 2026

    PCMag's roundup said customer notices and agent outreach were underway, with no new attacker activity or attribution reported.

    Containedpcmag.com
  4. Jul 15, 2026

    Fox News reported that AssuranceAmerica had disabled compromised credentials, ended unauthorized sessions, and was offering 12 months of credit monitoring. No new attack activity or attribution was reported.

    Containedfoxnews.com
  5. Jul 13, 2026

    AssuranceAmerica issued a public statement saying it had disabled compromised credentials, ended unauthorized sessions, isolated affected systems, reset passwords, added monitoring, trained staff, and notified law enforcement.

    Containedaol.com
  6. Jul 10, 2026

    Reporting confirmed the stolen data included Social Security numbers for some affected individuals, in addition to driver's license numbers.

    Containedtechlicious.com
  7. Jul 9, 2026

    AssuranceAmerica disclosed the breach affected 6,998,886 people in a filing with the Maine Attorney General's office.

    Containedesecurityplanet.com
  8. Jul 9, 2026

    Law firm Edelson Lechtzin LLP announced a class-action investigation into the breach; other firms including CPM Legal and Stueve Siegel Hanson also opened investigations.

    Containedmorningstar.com
  9. Jul 9, 2026

    State breach filings confirmed 6,998,886 people were affected, and the company continued notifying customers.

    Containedesecurityplanet.com
  10. Jun 27, 2026

    State officials began notifying residents in at least seven states that their data may have been exposed.

    Contained
  11. Jun 25, 2026

    Reports named the breached entity as AssuranceAmerica Managing General Agency, LLC and said the company detected suspicious activity on March 17, 2026, a day after an employee was targeted.

    Emergingvpncentral.com
  12. Jun 18, 2026

    AssuranceAmerica confirmed a breach exposing driver's license numbers and personal data for nearly 7 million people after an employee account was compromised.

    Emergingsecurityaffairs.com
  13. Mar 17, 2026

    AssuranceAmerica detected suspicious activity after an attacker targeted an employee to gain unauthorized access to its IT environment.

    Emergingesecurityplanet.com

Sources

Related reports