Auto insurance provider AssuranceAmerica hit by cyberattack, affecting over 6.9 million customer data
According to filings disclosed by multiple U.S. state regulators, Atlanta-based auto and renters insurance provider AssuranceAmerica experienced a cyberattack in March this year, leading to a data breach affecting over 6.9 million customers, involving sensitive information such as names, policy numbers, driver's license numbers, and Social Security numbers. The attack originated from a targeted intrusion on an employee, and the company has taken emergency measures and reported the incident to law enforcement.

According to state regulatory filings in the U.S., AssuranceAmerica, a privately held auto and renters insurance company, suffered a cyberattack earlier this year affecting more than 6.9 million customers. The company, headquartered in Atlanta, operates in the auto and renters insurance sectors.
AssuranceAmerica stated that the attack was detected on March 17 and traced back to a targeted attack against one of its employees the previous day. Details have been submitted in filings to the California Attorney General's office.
The investigation revealed that an unauthorized party breached the company's IT department and copied multiple data files. The company has notified law enforcement of the attack.
According to filings submitted to the Maine Attorney General's office, the breach affected more than 6.9 million individuals, with nearly 880 affected in Maine. It should be noted that the Maine Attorney General's office has stopped posting new breach notifications on its public website since June due to an attack on its own data breach reporting system.
Scope of sensitive data
According to the breach notification copy filed in California, the information copied during the attack may include: names, insurance policy numbers, claims information, driver's license numbers, vehicle information, and Social Security numbers.
Following the incident, AssuranceAmerica stated that it took affected servers offline and implemented a series of hardening measures to prevent future attacks, including resetting passwords, strengthening monitoring and threat detection software, and providing additional cybersecurity response training to employees.
The company advises customers to review credit reports, bank information, and other records to guard against potential fraud, and offers 12 months of credit monitoring services to help customers identify suspicious activity.
There is currently no indication of who specifically carried out the attack. In 2025, a series of insurance companies experienced attacks linked to a wave of social engineering attacks traced to a cybercrime group known as Scattered Spider. The group has connections to other affiliates within a larger underground community called The Com.
Officials at AssuranceAmerica did not immediately respond to requests for comment.