AssuranceAmerica Managing General Agency disclosed a cyber intrusion that exposed the personal and insurance-related data of up to 6,998,886 individuals after an unauthorized third party compromised an employee account and accessed parts of the company’s internal network. The company said the malicious activity occurred on March 16, 2026, was detected on March 17, and resulted in copied data files containing names, contact details, automobile insurance policy and account information, driver and vehicle information, and claims records. For some affected people, the exposed data may also include driver’s license numbers, Social Security numbers, and Tax ID numbers.
AssuranceAmerica said it completed its forensic review on June 15 and began notifying affected individuals in July, after initially reporting a smaller impact before later filings raised the total to nearly 7 million. In response, the insurer took affected servers offline, isolated impacted systems, disabled compromised credentials, reset passwords, expanded monitoring and threat detection, increased employee cybersecurity training, notified law enforcement, and offered two years of identity protection and credit monitoring through IDX. The company also warned customers to watch for phishing attempts and identity-related fraud.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
The company began notifying affected individuals in July 2026 and offered two years of identity protection and credit monitoring through IDX. Later reporting indicated the breach may affect as many as 6,998,886 people, up from an initial figure of 1,124,824.
AssuranceAmerica completed its forensic review of the incident on June 15, 2026. The review informed the scope of exposed data and the company’s breach response.
The company detected the intrusion on March 17, 2026, one day after the suspected compromise. It responded by taking containment steps including disabling compromised credentials, isolating affected systems, resetting passwords, enhancing monitoring, and notifying law enforcement.
AssuranceAmerica said an unauthorized third party targeted an employee account and accessed portions of its IT environment, copying files containing sensitive personal and insurance-related information. The company believes the malicious activity occurred on March 16, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.