AssuranceAmerica Discloses Breach of 6.99M Drivers' License Records — Largest Known U.S. DL Theft of 2026
Atlanta-based auto insurer AssuranceAmerica has formally notified 6,998,886 individuals after attackers compromised a single employee credential on March 16, 2026, and exfiltrated files containing names, contact details, insurance policy data, claims information, and driver's license numbers across its 14-state, 9,500-agent network. The forensic review was not completed until June 15 — a 91-day gap between breach and conclusion — making this the largest publicly disclosed theft of U.S. driver's license data in 2026 and a high-value ingest for identity fraud, account-opening attacks, and downstream phishing operations. The company has not disclosed the specific initial access vector, though credential compromise of a single employee account is consistent with an infostealer or targeted phishing precursor.
The forensic review was not completed until June 15 — a 91-day gap between breach and conclusion — making this the largest publicly disclosed theft of U.S.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.