AssuranceAmerica Confirms Data Breach Affecting Nearly 7 Million People

AssuranceAmerica has confirmed a data breach affecting approximately 6.99 million individuals after attackers accessed customer records containing driver's license and insurance information.
Illustration for the AssuranceAmerica data breach showing the company's logo over a stack of driver's licenses against a dark background with digital code, representing the exposure of driver's license and customer insurance information affecting nearly 7 million individuals.

U.S. insurance provider AssuranceAmerica has confirmed a data breach affecting approximately 6.99 million individuals after attackers gained unauthorized access to company systems earlier this year. According to the company’s official data breach notice and state regulatory filings, the incident exposed driver’s license numbers and other sensitive personal information belonging to customers.

AssuranceAmerica said malicious activity targeting one of its employees occurred on March 16, 2026. The company detected suspicious activity the following day, launched an investigation, and determined that an unauthorized third party had accessed portions of its IT environment and copied certain data files. The investigation concluded on June 15, 2026.

Nearly 7 million individuals affected

According to the company’s breach notice, the compromised information varies by individual but may include:

  • Full names
  • Contact information
  • Driver’s license numbers
  • Driver information
  • Vehicle information
  • Auto insurance policy and account information
  • Claims-related information

State breach filings indicate approximately 6.99 million individuals were affected, making it one of the largest publicly disclosed U.S. data breaches involving driver’s license information this year.

Investigation and response

AssuranceAmerica said the incident stemmed from malicious activity targeting one of its employees but did not disclose how the employee’s access was compromised or identify the threat actor responsible.

Following the discovery, the company said it disabled compromised credentials, terminated unauthorized sessions, isolated affected systems where appropriate, notified law enforcement, reset passwords, enhanced monitoring and threat detection capabilities, and provided additional cybersecurity training to employees.

Driver’s license exposure increases identity theft risk

Driver’s license numbers are valuable to cybercriminals because they can be used alongside other personal information to facilitate identity theft, account fraud, and targeted phishing campaigns. Combined with names, contact information, insurance records, and vehicle details, the exposed information could be used to impersonate victims or bypass certain identity verification processes.

Affected individuals should remain alert for suspicious communications and unauthorized activity involving their personal or financial accounts.

Alleged AssuranceAmerica data appears for sale

Update, August 29, 2026: BreachNews has identified a dark web forum listing posted on August 21 that appears to offer data allegedly obtained from AssuranceAmerica.

The seller claims to possess approximately 7.2 million records containing personal, insurance, and payment-related information. The listing provides a detailed inventory of the allegedly compromised data, including names, Social Security numbers, driver’s license information, addresses, vehicle details, insurance policy information, claims records, medical information, and certain payment-related data.

The seller also claims the records are linked across multiple datasets and offers samples and portions of the database for sale.

BreachNews has not independently verified the authenticity of the full dataset or the seller’s claims. However, the company named in the listing, approximate record count, and several categories of information advertised by the seller are consistent with information previously disclosed in connection with the AssuranceAmerica breach.

View a redacted screenshot of the August 21 forum listing. Personally identifiable information contained in the seller’s sample record has been removed by BreachNews.

At the time of this update, this is the only public sale listing tied to the AssuranceAmerica breach that BreachNews has independently identified. The listing does not establish whether the seller was responsible for the original intrusion, and BreachNews has not identified a publicly confirmed attribution of the attack to a specific threat actor.

No identity protection services announced

According to state breach filings, AssuranceAmerica is not offering complimentary identity theft protection services to affected individuals. Consumer notification letters were expected to be mailed during July 2026.

BreachNews will continue monitoring the incident and update this article if additional information becomes available regarding the authenticity or distribution of the allegedly stolen data or the identity of the threat actor responsible.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site