Major Data Breach Exposes Millions of Driver’s License Numbers
AssuranceAmerica, a U.S.-based insurance firm, has disclosed a data breach impacting the personal information and driver’s license numbers of 6.9 million individuals, representing the largest known leak of American driver’s license data this year.
Founded in 1998, AssuranceAmerica provides auto and rental insurance to clients in over a dozen U.S. states. As a major insurance player, the company manages vast amounts of information regarding potential clients and drivers, including personal details and data pertaining to their state-issued driver’s licenses. Such sensitive information, particularly a driver’s license number, is at risk for exploitation in fraud and identity theft if it falls into the wrong hands.
In a breach notification directed to customers and reviewed by TechCrunch, AssuranceAmerica reported detecting unauthorized access to their systems on March 17. The investigation concluded on June 15, uncovering that hackers accessed customers’ names, contact information, and driver’s license numbers.
The notice also revealed that the hackers had obtained data related to customers’ auto insurance policies, accounts, drivers, vehicles, and claims information.
However, the company did not provide further details on any other specific types of personal information that may have been compromised.
Although AssuranceAmerica did not clarify the exact cause of the breach, they mentioned that hackers “targeted one of the Company’s employees,” and compromised credentials were subsequently “disabled.” The exact method by which those credentials were obtained remains uncertain, although previous incidents involving stolen employee credentials have been linked to password-stealing malware or vulnerabilities in compromised software.
TechCrunch attempted to contact AssuranceAmerica’s CEO Joe Skruck and founder Guy Millner for further information about the incident, including whether the company communicated with the hackers or if a ransom was paid, but did not receive a response from either party.
According to a data breach notice filed with the Indiana attorney general’s office, AssuranceAmerica has reported that the breach affects 6.99 million individuals, with notification letters scheduled for distribution on July 10.
Moreover, a separate copy of AssuranceAmerica’s breach notification, supplied by the Maine attorney general’s office at TechCrunch’s request, confirms that the number of impacted individuals is indeed 6.99 million. (Maine’s data breach portal is currently offline and under review due to a fraudulent breach disclosure published last month.)
This incident at AssuranceAmerica is part of a recent surge in data breaches targeting driver’s licenses and other identification forms. In June, the Texas state government revealed that hackers had stolen information related to at least 3 million driver’s licenses and passport numbers in a breach concerning the state’s parks and wildlife division.
TechCrunch has previously reported on multiple security issues that collectively compromised millions of government-issued identity documents, stemming from incidents related to hotel check-in systems, money transfer applications, prison payphone services, and U.K. visa providers. These data breaches are arising as websites and apps increasingly require users to submit their identity documents for legal age verification, alongside a global push for age-verification regulations by numerous governments.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


