AssuranceAmerica says breach exposed data of nearly 7 million people
AssuranceAmerica Managing General Agency LLC says personal information belonging to 6,998,886 people may have been exposed in a cyber incident involving insurance and driver-related records.
The company began sending formal notices on July 10, 2026, after completing its review of potentially affected files on June 15. An Indiana attorney general breach listing reports that 237,141 Indiana residents were affected; the filing lists the national total as 6,998,886. The Indiana figure is a state-specific count and does not mean all affected people lived in Indiana.
What changed
The incident itself occurred in March. AssuranceAmerica says it detected suspicious activity on March 17, while the Indiana filing lists March 16 as the breach date. The company says the activity appeared to target an employee and that an unauthorized third party accessed parts of its information-technology environment and copied data files.
AssuranceAmerica says it investigated the incident, worked to determine which files were involved and completed that review on June 15. The notification period began July 10, making the current issue for consumers the formal notice and response period rather than a newly discovered attack.
What information may be involved
The company’s notice says the potentially exposed information may include names, addresses and other contact details; insurance policy or account information; driver and vehicle information; claims data; and driver’s-license numbers.
For some individuals, the information may also include Social Security numbers or tax-identification information. The notice does not say that every affected person’s record contained every category.
The combination of insurance records, driver information and identity details can make phishing or impersonation attempts more convincing. A message that references a policy, vehicle, claim or license should not automatically be treated as legitimate simply because it includes personal information.
What AssuranceAmerica says it did
According to the company’s notice, affected systems were taken offline, passwords were reset and additional monitoring and threat-detection tools were put in place. AssuranceAmerica also says it expanded employee instruction and notified law enforcement.
The company is offering eligible recipients 12 months of IDX credit monitoring. Consumers should use the enrollment instructions in their individual notice and activate the service by the deadline printed in that letter. Credit monitoring can help identify certain signs of misuse, but it does not prevent identity theft by itself.
What affected consumers should do
First, verify that a notice is genuine. Do not rely on an unexpected email or text message asking for information. Use the contact details in the letter or another trusted company contact method, and avoid clicking links in unsolicited messages.
If you received a notice, enroll in the offered IDX service before its stated deadline. Review your credit reports, bank statements, insurance accounts and claims activity for unfamiliar changes.
Consumers whose Social Security or tax-identification information may have been included should consider placing a free credit freeze with Equifax, Experian and TransUnion. A fraud alert is another free option that asks lenders to take additional steps to verify identity before opening new credit.
Anyone who suspects identity theft should report it through IdentityTheft.gov and contact the affected financial institution, insurer or account provider promptly.
What remains unknown
AssuranceAmerica has not publicly identified the person or group behind the incident. The available notice also does not establish the precise method used to target the employee, whether the information was publicly released or whether it was sold. The company’s account confirms unauthorized access and copying of files, but not those additional details.
Sources
- Indiana Attorney General, June 2026 Data Breach Report
- AssuranceAmerica individual data-security incident notice
- TechCrunch report on the AssuranceAmerica breach
- Federal Trade Commission, “What To Do After a Data Breach”
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.