AssuranceAmerica Data Breach Exposes Driver's License Records of Nearly 7 Million People
AssuranceAmerica is notifying 6.99 million people that hackers stole driver's license numbers and insurance records after a March cyberattack on an employee account.
Overview
AssuranceAmerica is notifying nearly 7 million people that hackers stole sensitive customer information, including driver’s license numbers, following a cyberattack discovered in March, according to TechCrunch. The Atlanta-based auto insurer, founded in 1998 and operating through more than 9,500 independent agents across 14 U.S. states, disclosed that 6,998,886 people had their information exposed, according to BleepingComputer and eSecurity Planet.
The incident is being described as the largest known exposure of American driver’s license data so far in 2026, according to CyberInsider and SC Media.
What We Know
AssuranceAmerica detected suspicious activity in its systems on March 17, 2026, one day after hackers targeted an employee account, according to BleepingComputer. In a data breach notice sent to customers and seen by TechCrunch, the company said it “discovered hackers in its computer systems on March 17” and concluded its investigation on June 15, according to TechCrunch.
The stolen files contained names and, for individual customers, one or more of the following: contact information, automobile insurance policy or account information, driver and vehicle information, claims-related information, and driver’s license numbers, according to CyberInsider, which cited the notification letter’s own data-element list. TechCrunch reported the same categories, noting that the hackers “took information about customers’ auto insurance policies and accounts, their drivers and vehicles, and details about customer claims” in addition to names, contact information, and driver’s license numbers.
AssuranceAmerica has not disclosed the specific technique used to breach its systems. The company’s notice said only that the hackers “targeted one of the Company’s employees” and that it subsequently “disabled compromised credentials,” according to TechCrunch. SC Media similarly reported that hackers targeted an employee, leading to the compromise of credentials, without specifying how. Malwarebytes reported that no law enforcement or vendor report has publicly linked the intrusion to a specific threat group, ransomware operation, or nation-state actor, and that no ransom demand or payment has been reported.
After discovering the intrusion, AssuranceAmerica disabled the compromised credentials, terminated unauthorized sessions, isolated affected systems, notified law enforcement, reset passwords, deployed enhanced monitoring and threat detection tools, and provided additional cybersecurity training to employees, according to eSecurity Planet.
According to a data breach listing with the Indiana attorney general’s office, AssuranceAmerica listed the breach as affecting 6.99 million people, with notification letters set to be sent out on July 10, as reported by TechCrunch.
TechCrunch emailed questions about the incident to AssuranceAmerica CEO Joe Skruck and founder Guy Millner, including asking whether the company had any contact with the hackers or paid a ransom. Neither responded, according to TechCrunch.
What We Don’t Know
AssuranceAmerica has not identified the attackers or confirmed whether ransomware was involved, according to eSecurity Planet. The company has also not detailed exactly how the employee’s credentials were obtained, and it did not respond to TechCrunch’s questions about contact with the hackers or any ransom payment, according to TechCrunch.
Analysis
The roughly four-month gap between AssuranceAmerica’s detection of the intrusion in March and the start of customer notifications in July reflects a pattern common to large-scale breach investigations, where forensic review of exactly which records were copied can take months to complete before regulators and affected individuals are notified. With driver’s license numbers now compromised for nearly 7 million people, the exposure adds to a string of large insurance-sector breach disclosures already reported this year, underscoring how concentrated troves of policyholder identity data continue to be an attractive target for intruders who compromise a single employee account.