Around 6.9 million U.S. driver’s licenses and personal data were exposed following a massive leak suffered by the insurer AssuranceAmerica, as notified by the company itself.
This breach constitutes the largest leak of driver’s license information in the United States so far in 2026. The incident was detected on March 17 and, after concluding the investigation on June 15, the company confirmed that malicious actors accessed names, contact details, license numbers, and details linked to their customers’ policies and claims.
AssuranceAmerica, founded in 1998 and present in more than a dozen states, manages information for millions of policyholders and drivers. The company reported that attackers gained access through an employee’s compromised credentials, although the method used for the theft was not detailed. Incidents of this type are usually related to malware specialized in password extraction or the use of vulnerable software.
The attack occurred following the compromise of an employee’s credentials at the insurance company.
According to TechCrunch, the case adds to other recent episodes, such as the breach reported by the Texas government, which in June notified the theft of information from at least 3 million driver’s licenses and passports in an attack on the state’s parks and wildlife division.
Recomen
The magnitude of these events highlights the security challenges faced by companies that manage large volumes of personal data, especially when they implement artificial intelligence (AI) systems to automate operations.
According to the cybersecurity platform BeyondTrust, the use of autonomous AI agents grew by 466.7% year-over-year, which has increased the exposure of critical systems and sensitive data.
U.S. authorities were alerted to the magnitude of the leak.
Five keys to managing AI agents securely
The platform identified five key fundamentals to manage AI agents securely and avoid the exposure of confidential data:
- Treat AI agents as another identity in the organization: every account used by AI agents must be managed with the same rigor as any other corporate identity, with clearly defined roles and permissions.
- Apply the principle of least privilege: limiting agent access only to essential resources reduces the margin of risk in the event of potential unauthorized access.
- Maintain visibility over agent activities: it is necessary to know in detail which systems they use, what actions they execute, and what resources they handle in order to detect vulnerabilities or insecure configurations.
The recent case underscores the importance of applying strict controls to systems that manage organizational data.
- Protect the credentials and secrets used by agents: keys, tokens, and passwords must be stored and managed using secure mechanisms, avoiding their exposure in vulnerable files or systems.
- Monitor and review agent activity continuously: logging all actions, detecting anomalous behaviors, and periodically reviewing permissions are essential practices to limit the impact of potential incidents.
The secure management of identities, access, and activities in AI environments is key to reducing the blast radius of attackers and protecting sensitive data, according to BeyondTrust, a leading identity security company.
The data breach suffered by AssuranceAmerica reinforces the need to adopt these recommendations and strengthen security controls, in a scenario where digitalization and automation accelerate the exposure of critical information.




