AssuranceAmerica data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
AssuranceAmerica Managing General Agency, LLC, an Atlanta-based auto and specialty insurer that works through independent agents across multiple U.S. states, notified regulators and consumers of a cybersecurity incident after unauthorized access to portions of its IT environment.
On its official Notice of Data Breach (dated July 10, 2026), the company said it detected suspicious activity on March 17, 2026 that appeared to result from malicious activity on March 16, 2026 targeting one of its employees. An investigation with external forensic specialists found that an unauthorized third party accessed certain systems and copied data files. The company completed its file-evaluation review on June 15, 2026, then began mailing notices. Iowa’s Attorney General letter said consumer mail by July 15, 2026.
In a filing with Maine’s Office of the Attorney General reported by BleepingComputer and other outlets, AssuranceAmerica listed 6,998,886 people affected nationwide. That figure is from the regulatory filing as reported in the press—not a Delist count. Iowa’s AG letter separately listed 1,839 Iowa residents to be notified; do not treat any single-state figure as the nationwide total.
Sources
What data was exposed
Company notices say the personal information in the affected files varies by individual and included the individual’s name and one or more of the following:
- Contact information
- Automobile insurance policy or insurance account information
- Driver or vehicle information
- Claims-related information
- Driver’s license number
- Tax ID information or Social Security number (for a limited number of individuals, per AssuranceAmerica’s July 10, 2026 Notice; also listed on some state consumer-notice forms, including South Carolina’s published sample)
Not every person received every field. Rely on the notice you were mailed for what applied to you.
Breach details
| Detail | Value |
|---|---|
| Breach name | AssuranceAmerica Managing General Agency |
| Date | Intrusion ~March 16–17, 2026; file review completed June 15, 2026 |
| Disclosed | Company Notice July 10, 2026; consumer mail ~July 2026 (Iowa AG: mail by July 15, 2026) |
| Accounts affected | 6,998,886 nationwide (Maine AG filing, as reported in press); Iowa AG letter: 1,839 Iowa residents |
| Domain | assuranceamerica.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by AssuranceAmerica; it reflects a publicly reported security incident.
For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.
What to do now
Based on the data types named in company notices, practical steps include:
- Place a free credit freeze with Equifax, Experian, and TransUnion if your notice names a Social Security number, Tax ID, or driver’s license number—those identifiers are commonly used in new-account and impersonation attempts.
- Treat unexpected calls, texts, or emails that cite your insurance policy, claim, or license details as possible social engineering; hang up and contact AssuranceAmerica or your agent through a number you look up yourself (the company Notice lists 1-844-854-2353, Monday–Friday 9 a.m.–9 p.m. ET).
- Review credit reports, bank and card statements, and insurance mail for unfamiliar policies, claims, or account openings.
- Keep any breach letter you receive; it is the record of what fields applied to you.
- Credit monitoring: AssuranceAmerica’s Notice offers complimentary 12-month IDX monitoring to affected California and Pennsylvania residents (enrollment deadline on the Notice: October 10, 2026). Enroll only through channels printed on your letter or the official Notice—not through links in unexpected messages. Other states should follow the steps printed in their own letter.
For a short triage checklist, see first 48 hours after a data breach. If the letter itself is confusing, see a company emailed me about a breach.
How this shows up on the open web
Names, contact details, and driver’s license numbers sit next to the same building blocks people-search sites and data brokers already publish. After a license-heavy insurance incident, tailored phishing and impersonation can sound more plausible when someone can also look up your current address or phone online. Run a free open-web scan to see which people-search and broker sites are exposing your personal data. Delist does not claim to have scanned AssuranceAmerica’s systems or this incident’s files, and it does not remove records from a breach dump.
Related reading on ID scans and DMV-side exposure: when a store scans your driver’s license, IDScan.net (2026), and Florida DMV / DAVID (2026).
My driver’s license was in an insurance breach—what should I do first?
Freeze credit at all three bureaus if your notice names SSN, Tax ID, or a license number. Treat calls that cite your policy or license as possible scams, and use only the channels printed on AssuranceAmerica’s letter or its July 10, 2026 Notice (1-844-854-2353). CA and PA residents: check the Notice for IDX monitoring enrollment. A free Delist scan checks open-web people-search listings—not this dump.
Frequently asked questions
How many people did AssuranceAmerica say were affected?
Press coverage of the company’s Maine Attorney General filing cites 6,998,886 people nationwide. That figure comes from the regulatory filing as reported publicly—not from a Delist count. Iowa’s AG letter separately listed 1,839 Iowa residents to be notified.
Was every person’s Social Security number exposed?
No. AssuranceAmerica’s July 10, 2026 Notice says Tax ID or Social Security number applied for a limited number of individuals. Company notices say name plus one or more listed fields. Check the letter you received.
Is AssuranceAmerica offering credit monitoring to everyone?
Its public Notice describes complimentary 12-month IDX monitoring for affected California and Pennsylvania residents, with an October 10, 2026 enrollment deadline on that page. Other states should follow whatever their mailed letter says—not cold emails.
Can Delist remove my record from the AssuranceAmerica breach files?
No. Delist does not scrub insurer systems or breach dumps. A free scan looks at open-web people-search and broker listings only.
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- IDScan.net breach (2026)
- Florida DMV / DAVID breach
- When a store scans your driver’s license
- First 48 hours after a data breach
- Got a breach email?
- How to freeze your credit
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.