AssuranceAmerica Breach Exposes Data of 6.9 Million Drivers

Nearly 7 million American drivers just had their personal information stolen. AssuranceAmerica, an auto insurance company operating in 14 U.S. states, disclosed a data breach that exposed names, contact info, policy details, driver’s license numbers, and claims data.

The breach happened March 16. The company detected suspicious activity the next day and found attackers had targeted one of its employees, gained access to internal systems, and made off with data files.

It took until June 15 — three full months — for AssuranceAmerica to finish reviewing the stolen files and figure out who was affected. That’s 6,998,886 people, per a filing with Maine’s Attorney General.

TechCrunch first reported the story. The breach notification letters go out Friday.

AssuranceAmerica says it responded by disabling compromised credentials, kicking the attackers out, isolating affected systems, and notifying law enforcement. They’ve also reset passwords and deployed enhanced monitoring and threat detection tools. Plus additional cybersecurity training for staff.

The company is advising affected customers to check their credit reports, bank accounts, and financial statements for anything suspicious.

This isn’t an isolated incident. Last month, insurance giant Aflac disclosed a breach at its Japanese subsidiary that hit 4.38 million customers. The insurance sector is taking fire, and the data being stolen — driver’s license numbers, policy details — is exactly the kind of information criminals can use for identity theft and fraud.

If you’re an AssuranceAmerica customer, watch your accounts closely. The company is sending notifications, but don’t wait for the letter.