7 Million Driver’s Licences Stolen in Massive Breach – Claril Noticias

US insurance provider AssuranceAmerica confirmed on 10 July that hackers breached its systems on 17 March, stealing the personal details and driver’s licence numbers of 6.99 million customers across more than a dozen states.

How the AssuranceAmerica Breach Unfolded

Established in 1998, AssuranceAmerica provides vehicle and rental insurance across multiple US states. Due to the nature of its operations, the firm processes vast amounts of sensitive data, including state-issued driver’s licences. In the hands of cybercriminals, these licence numbers pose a severe risk of identity theft, financial fraud, and impersonation.

According to a data breach notification sent to affected individuals and seen by TechCrunch, the insurer detected unauthorised access to its IT systems on 17 March. Following an investigation concluded on 15 June, the company confirmed that hackers had successfully exfiltrated customer names, contact details, and driver’s licence numbers.

Employee Credentials Targeted by Hackers

The compromised data also includes auto insurance policy details, account information, vehicle and driver records, and claims history. AssuranceAmerica has not disclosed whether other categories of sensitive personal data were accessed during the incident.

While the exact vector of the attack remains unconfirmed, the firm revealed that cybercriminals “targeted one of the Company’s employees”, leading to the subsequent disabling of compromised credentials. Such credential-theft incidents are typically associated with password-stealing malware or vulnerabilities in third-party software.

AssuranceAmerica CEO Joe Skruck and founder Guy Millner did not respond to inquiries regarding whether the company has engaged with the hackers or paid a ransom demand.

The Growing Danger of Identity Document Leaks

Filings with the Indiana Attorney General’s office indicate that the breach affected approximately 6.99 million individuals, with formal notification dispatches scheduled to begin on 10 July.

A duplicate copy of the notification, provided by the Maine Attorney General’s office, verified the 6.99 million figure. Notably, Maine’s official data breach portal is currently offline and under review following the publication of a fraudulent disclosure on the site last month.

A Worrying Trend of Age-Verification Risks

This incident is part of a worrying surge in cyberattacks targeting government-issued identity documents. Recently, the Texas state government revealed that a breach within its parks and wildlife division exposed at least 3 million driver’s licences and passport numbers.

Similar security failures have recently compromised millions of identity documents worldwide, including leaks from hotel check-in systems, money transfer applications, prison telecommunication systems, and a UK visa service. This rise in identity document exposure coincides with a global legislative push for age-verification laws, which increasingly require internet users to upload highly sensitive government IDs to access online platforms.

By Claril

Leave a Reply

Your email address will not be published. Required fields are marked *