Key Takeaways

  • AssuranceAmerica reports a breach affecting 6.9 million driver’s license numbers.
  • The breach involved personal information and auto insurance details.
  • Investigation revealed hackers accessed systems on March 17.
  • Notification letters to affected individuals are set for July 10.

Overview of the Breach

AssuranceAmerica, a U.S. insurance provider, has confirmed a significant data breach that has compromised the personal information and driver’s license numbers of approximately 6.9 million individuals. This incident stands as the largest known exposure of driver’s license data in the United States this year.

Details of the Incident

Founded in 1998, AssuranceAmerica offers car and rental insurance across multiple states. The company manages extensive data on potential customers, including sensitive information related to state-issued driver’s licenses. Such data can be exploited for fraud and identity theft.

According to a breach notice sent to customers, AssuranceAmerica detected unauthorized access to its systems on March 17 and completed its investigation by June 15. The findings revealed that hackers had stolen names, contact information, and driver’s license numbers, along with details about auto insurance policies, vehicles, and customer claims.

Investigation Findings

While the company did not disclose the exact cause of the breach, it indicated that the attackers targeted an employee, leading to the compromise of credentials. The method of credential theft remains unclear, but previous incidents have often involved malware or compromised software.

AssuranceAmerica’s CEO and founder did not respond to inquiries regarding any communication with the hackers or whether a ransom was paid.

Impact and Notifications

The breach has been officially listed as affecting 6.99 million individuals, with notification letters expected to be dispatched by July 10. A separate notification from the Maine attorney general’s office confirmed the same number of affected individuals, although Maine’s data breach portal is currently offline due to a prior fraudulent disclosure.

Context of Recent Breaches

This incident follows a series of data breaches involving driver’s licenses and identity documents. In June, the Texas state government reported that hackers accessed data from at least 3 million driver’s licenses and passport numbers linked to a breach in its parks and wildlife division.

Recent reports have highlighted various security lapses that have led to the exposure of millions of government-issued identity documents. These breaches coincide with a growing trend of websites and applications requiring users to provide identity verification to comply with age-verification laws being implemented by governments worldwide.