
American insurance giant AssuranceAmerica Managing General Agency suffered a major security incident that compromised the sensitive personal information of more than one million individuals.
In a data security incident notice filed with the Office of California Attorney General, AssuranceAmerica said that on March 17, it identified unauthorised access to its internal network which appears to have resulted from malicious activity that occurred on March 16, 2026, targeting one of the company’s employees.
The insurance provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.
AssuranceAmerica Managing General Agency is a subsidiary of AssuranceAmerica Corporation, an insurance holding company headquartered in Atlanta, Georgia. As a specialised managing general agency, it collaborates with insurance carriers and independent agents to offer a broad portfolio of personal and commercial insurance products.
“During this investigation, the Company discovered that, as a result of the targeted attack, an unauthorised third party accessed the Company’s IT systems and copied a number of data files,” AssuranceAmerica said.
The compromised information included individuals’ names, contact details, automobile insurance policy or account data, driver and vehicle information, claims-related records, driver’s license numbers, Tax ID numbers, and Social Security numbers. The breach was reported to state regulators and affected 611,046 residents in South Carolina, 500,987 in Texas, 8,950 in Washington, 3,569 in Massachusetts, and 272 in Vermont.
AssuranceAmerica added that it has taken measures to strengthen its security posture and reduce the risk of a similar incident occurring again. The impacted server systems were promptly disabled and taken offline.
The company has also introduced additional safeguards across its IT environment, including password resets, enhanced monitoring and threat detection tools, and expanded cybersecurity awareness training for employees.
The insurance provider has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on AssuranceAmerica. The insurance provider also did not share details on who was behind the attack, how much data was compromised, or whether it had received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543