Cyber Incident Victim: AssuranceAmerica Managing General Agency, LLC
Timeline
Summary
AssuranceAmerica Managing General Agency, LLC experienced a data breach that exposed the names, contact information, driver’s license numbers, auto insurance policy and account details, driver and vehicle information, and claim details of nearly seven million individuals. The breach was discovered after hackers targeted one of the company’s employees and the company disabled the compromised credentials; its investigation was later completed. No ransom payment or contact with the attackers was disclosed by the company.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 17, 2026, AssuranceAmerica detected unauthorized access to its computer systems and identified that hackers had targeted one of its employees, after which the company disabled the compromised credentials. An internal investigation was launched immediately following the detection. The investigation concluded on June 15, 2026, after determining the full scope of the breach. The breach was initially discovered in March, with the investigation completed in June, as reported by multiple sources. Notification letters to affected individuals were scheduled to be sent out on July 10, 2026, according to filings with the Indiana and Maine attorneys general.

The breach exposed personal information of approximately 6.99 million individuals. Exposed data included names, contact information, and driver’s license numbers. Additionally, attackers obtained details about customers’ auto insurance policies and accounts, information about drivers and vehicles, and specifics of customer claims. The company did not disclose which other types of personal information might have been taken. Driver’s license numbers can be used for fraud and impersonation, posing a risk to the affected individuals. The incident contributed to a series of driver’s license data breaches reported in mid‑2026, including a Texas state government breach that compromised at least three million driver’s licenses and passport numbers.
After discovering the intrusion, AssuranceAmerica disabled the compromised employee credentials as part of its containment effort. The company completed its forensic investigation on June 15, 2026, but did not disclose the specific method used to steal the credentials. Prior incidents involving similar credential theft have been linked to password‑stealing malware or compromised software, though the company did not confirm the cause in this case. AssuranceAmerica did not respond to requests for comment from TechCrunch regarding possible contact with the attackers or any ransom payment. Notification letters were prepared for distribution on July 10, 2026, to inform the approximately 6.99 million affected individuals. The breach is noted as one of the largest driver’s license data exposures reported in the United States during 2026.
