
American insurance giant AssuranceAmerica Managing General Agency revealed that a cybersecurity incident earlier this year compromised the sensitive personal data of over 1 million people.
In a data security incident notice filed with the Office of California Attorney General,AssuranceAmerica said that on March 17, it identified unauthorised access to its internal network which appears to have resulted from malicious activity that occurred on March 16, 2026, targeting one of the company’s employees. The insurance provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
“During this investigation, the Company discovered that, as a result of the targeted attack, an unauthorised third party accessed the Company’s IT systems and copied a number of data files,” AssuranceAmerica said.
The compromised information included individuals’ names, contact details, automobile insurance policy or account data, driver and vehicle information, claims-related records, driver’s license numbers, Tax ID numbers, and Social Security numbers. Initially, AssuranceAmerica reported that 1,124,824 individuals were affected by the breach. However, a recent filing with the Maine state regulator, reviewed by Cybernews, states that the incident affected as many as 6,998,886 people.
AssuranceAmerica added that it has taken measures to strengthen its security posture and reduce the risk of a similar incident occurring again. The impacted server systems were promptly disabled and taken offline. The company has also introduced additional safeguards across its IT environment, including password resets, enhanced monitoring and threat detection tools, and expanded cybersecurity awareness training for employees.
The insurance provider has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543