Drivers’ License Numbers Speed Off Into Hackers’ Hands in Massive Data Breach
By: Jim Stickley and Tina Davis
August 15, 2026
One of the largest data breaches involving driver’s license information this year has exposed the personal data of nearly 7 million people.
AssuranceAmerica recently confirmed that cybercriminals gained unauthorized access to its network and drove away with customer information belonging to close to 7 million individuals. The company detected suspicious activity on March 17, 2026, and later determined that attackers had accessed files containing sensitive customer information. The investigation concluded on June 15 before affected customers began receiving notifications. That happened in mid-July.
The stolen information may include names, contact information, driver’s license numbers, automobile insurance policy or account information, driver and vehicle information, and claims-related information. While there is currently no indication that the stolen data has been publicly released, criminals frequently use this type of information to commit identity theft, create convincing phishing scams, or attempt insurance fraud. They may sit on the information for a long time before they use it, so it could be a while before phishing attempts hit.
AssuranceAmerica provides insurance coverage in the following states, meaning current and former customers in these locations may be affected:
- Alabama
- Arizona
- Florida
- Georgia
- Indiana
- Nebraska
- Ohio
- Oklahoma
- Pennsylvania
- South Carolina
- Tennessee
- Texas
- Virginia
- Washington
If you receive a notification from AssuranceAmerica, review it carefully and take advantage of any identity protection services that may be offered. These are useful for letting you know if someone is trying to use your identity to open new credit accounts. They won’t stop them, but you will be alerted and can take action. Monitor your financial and credit card accounts for unauthorized activity, review your credit reports regularly, and be cautious of emails, text messages, or phone calls claiming to be from the insurance company. Cybercriminals often use stolen personal information to make scam messages appear legitimate.
Word on the street is that the hackers were able to target an employee of AssuranceAmerican to gain access to the network and copy data. This is a reminder for organizations to train employees to protect their login credentials and therefore protect the information they have access to. Regular cybersecurity awareness training is crucial for keeping up with the latest threats. As we know, cybercriminals don’t fall asleep at the wheel.