Massive Data Breach Exposes Millions of Driver's License Numbers
A major cyberattack on a U.S. insurance company has been identified as the largest breach of driver’s license numbers in 2026 to date, according to cybersecurity authorities. The incident, which occurred at a Fortune 500 insurer with over 50 million policyholders, exposed the personal data of approximately 18 million individuals. The compromised information includes full names, driver’s license numbers, and in some cases, Social Security numbers, raising concerns about identity theft and fraud. Federal and state agencies are investigating the breach, which is believed to have originated from a sophisticated phishing campaign targeting the company’s third-party vendors.
The affected insurer, which has not been publicly named pending legal review, confirmed the breach in a statement to regulators and customers, emphasizing that no financial data or payment information was accessed. Over 2 million driver’s license numbers were reportedly exfiltrated, surpassing previous breaches in the U.S. that typically involved fewer than 5 million records. The company has partnered with cybersecurity firms to contain the attack and is offering free credit monitoring services to impacted individuals. Law enforcement, including the FBI, has launched a probe to trace the attackers, with initial findings suggesting ties to a previously unidentified hacking group.
Cybersecurity experts warn that the scale of the breach underscores vulnerabilities in corporate data security practices, particularly as third-party partnerships expand. The incident has prompted renewed calls for stricter federal regulations on data protection and breach disclosure. The insurer faces potential legal action from affected customers and state attorneys general, while lawmakers consider emergency legislation to address gaps in cybersecurity standards. The breach highlights the growing risks of large-scale data theft in an era of increasingly interconnected digital systems.