← All posts

They Found the Breach in 24 Hours. It Took 115 Days to Tell Anyone.

In my experience, the number that boards fixate on after a breach is the wrong one. They want to know how fast the team detected the intrusion. AssuranceAmerica detected theirs in roughly 24 hours — the kind of response time most organizations would celebrate. And yet nearly seven million people spent the next four months not knowing their driver's license numbers, Social Security numbers, and insurance records were in someone else's hands.

That gap — between finding the fire and sounding the alarm — is where the real risk lives.

What Happened

On March 16, 2026, an attacker phished credentials from an AssuranceAmerica employee and used them to walk into the company's IT environment. By March 17, the company had spotted the suspicious activity, disabled the compromised account, killed the unauthorized sessions, and isolated affected systems. Textbook containment.

But the attacker had already copied what they came for. The stolen files contained names, contact information, auto insurance policy details, claims records, vehicle information, and driver's license numbers for 6,998,886 people — according to the company's filing with Maine's Attorney General. For a subset, the haul also included Social Security numbers and Tax IDs.

The forensic review — figuring out exactly which files were taken and whose data was in them — did not wrap up until June 15. Notification letters started going out on July 10. That is 115 days from detection to disclosure.

AssuranceAmerica is an Atlanta-based insurer specializing in non-standard auto coverage, distributing through a large network of independent agents across more than a dozen states. They are not a household name. But the scale of this breach — nearly seven million records — puts it among the largest driver's license exposures of 2026. And the lawsuit is already moving: Edelson Lechtzin LLP announced its class action investigation on July 9, before most affected people had even received a letter.

The Question Your Board Should Be Asking

Here is the uncomfortable truth this breach exposes: detection speed and disclosure speed are two completely different capabilities, and most organizations are only measuring the first one.

In Cyber Risk Is Business Risk, I frame the board's job around Three Questions. One of them is: How much risk are we actually carrying? AssuranceAmerica's answer turned out to be "a single employee credential away from exposing seven million people." That is not a technology failure. That is an architecture problem — one set of credentials should never open the door to your entire customer archive.

But the second question matters just as much: Are we confusing compliance with security? The 115-day timeline is likely defensible under many state breach notification laws, which allow the clock to run while the forensic investigation determines who was affected. In the strictest states — Colorado, Florida, California — the legal argument gets harder, because those statutes start the clock when you have "reason to believe" a breach occurred, not when you have finished counting every victim. AssuranceAmerica knew on March 17 that data had been exfiltrated. Regulators in hard-deadline states may not care that the final tally took another 90 days.

This is the compliance-versus-security trap I see organizations fall into repeatedly. They optimize for the legal defensibility of their notification timeline while ignoring what those 115 days cost in trust — and in litigation exposure. A class action investigation launched before the letters even hit mailboxes. That is not a sign of a legally defensible position. That is a sign of a narrative that got away from you.

What Makes This Breach Different

Three things stand out.

The single-credential problem. One phished employee account gave an attacker access to files covering nearly seven million people. That number spans current and former policyholders, probably going back years. Every year of lapsed-policy data you retain beyond regulatory requirements is breach liability waiting to happen. If AssuranceAmerica had enforced strict data retention limits, the headline number might have been two million instead of seven.

The driver's license angle. Credit cards can be replaced in ten minutes. Driver's license numbers cannot — most state DMVs will not issue a new number without evidence of actual fraud. For 6.9 million people, the stolen number will remain their number for years. Paired with the policy, vehicle, and claims data also taken, the stolen files give attackers everything they need to impersonate your insurance company with near-perfect credibility.

The missing credit monitoring. AssuranceAmerica is not offering blanket identity protection services. Their notification letter says some recipients "may be eligible" depending on "applicable legal requirements" — meaning only where a state statute forces the issue. For a breach that exposed Social Security numbers, that is a decision the litigation will make very expensive.

What to Ask Your CISO This Week

If this story sounds familiar, it should. We have seen some version of this pattern — credential theft, lateral access to unprotected data stores, slow disclosure — play out at Aflac, the NAIC itself, and a half-dozen other insurance sector targets this year alone.

Here are the questions worth raising in your next board or risk committee meeting:

"If one employee credential were compromised tomorrow, how many customer records could an attacker reach before we noticed?" If the answer is in the millions, you have a segmentation problem. Detection speed is meaningless if exfiltration takes less time than your alert threshold.

"What is our notification timeline — not the legal maximum, but our actual plan?" Map it now, before you need it. The difference between a staged disclosure at 30 days and a single notification at 115 days is the difference between controlling your story and reading about it in a class action press release.

"How many years of customer data are we retaining past the regulatory minimum?" Every year beyond the requirement is scope you are adding to your next breach. Data retention is breach-size policy.

AssuranceAmerica did a lot of things right. They caught the intrusion fast. They contained it by the book. But none of that mattered to the seven million people who spent four months exposed without knowing it — or to the plaintiffs' attorneys who had their investigation announcement ready before the first letter was postmarked.

Detection is a capability. Disclosure is a decision. Your board needs to understand both.