The August 2026 breach story is about scale achieved through a single point of failure. AssuranceAmerica, an auto insurance managing general agency, confirmed the largest known exposure of US driver's licence numbers this year β affecting nearly 7 million people β after malicious activity targeting one employee.
Driver's licence numbers matter more than most exposed fields. Unlike a password, you cannot rotate them. They are a primary identity document for account opening, loan applications and government services, which makes them durable material for identity fraud years after the breach.
This report also catches up on the July incidents that landed while this series was on pause β including a breach that exposed 55.3 million accounts alongside live payment records.
β οΈ Important: π¨ AUGUST BREACH ALERT: AssuranceAmerica exposed close to 7 million US driver's licence numbers β the largest such exposure recorded in 2026 β from activity targeting a single employee account. Driver's licence numbers cannot be reissued the way a password can, so anyone affected faces a durable identity fraud risk. If your organisation stores government identity numbers, treat single-account compromise as a full-scale data loss scenario in your incident plan.
AssuranceAmerica: 7 Million Driver's Licences from One Employee Account
β’ Victim: AssuranceAmerica, an auto insurance managing general agency
β’ People affected: approximately 7 million
β’ Data exposed: driver's licence numbers, the largest known US exposure of this data type in 2026
β’ Entry point: malicious activity targeting a single employee
β’ Audit what any one employee account can access. If the answer is "the whole customer database", that is your breach waiting to happen.
β’ Government identity numbers deserve separate treatment from ordinary personal data β segregated storage, stricter access control, and encryption at rest.
β’ Under most US state privacy laws, driver's licence numbers trigger breach notification obligations on a shorter clock than lower-sensitivity fields.
Also in August: Liechtenstein and Hyundai TΓΌrkiye
July Catch-Up: The Four You May Have Missed
| Organisation | Scale | What was exposed |
|---|---|---|
| Suno | 55.3M accounts | Emails, phone numbers, and tens of thousands of Stripe purchase records |
| Paidwork | 23.3M emails | Names, phones, password hashes, addresses, dates of birth, bank account numbers |
| ADT | ~5.5M people | Names, phones, addresses; some dates of birth and last four of SSN/tax ID |
| KDDI | Up to 14.22M | Email addresses and passwords, via a third-party email platform |
Check What Your Website Exposes
Most breach coverage focuses on internal systems, but your public website is where trackers, forms and third-party scripts quietly collect data you may not be declaring. Run a free privacy scan to see what yours is doing. Scan your website now.
Four Lessons from This Month's Incidents
β’ Third-party software is your attack surface β KDDI's breach spread to five other providers through one supplier's flaw. Inventory the third-party code running on your systems and your website, and know who is responsible for patching each item.
β’ Detection lag is the real damage multiplier β Suno's intrusion ran from November 2025 to public disclosure in July 2026. The exposure window, not the intrusion, determines the harm.
β’ Payment metadata is personal data β Suno's Stripe records included names, addresses, card types and expiry dates. Truncated card numbers do not make a record non-sensitive under GDPR or the US state privacy laws.
Seven million driver's licence numbers from one employee account is the headline, but the pattern underneath is the more useful takeaway: concentration of access, dependency on third-party code, and long detection windows.
Each of those is auditable before an incident rather than after one. Map what single accounts can reach, inventory your third-party dependencies including everything loading on your public website, and shorten the time between compromise and detection.
Related reading: March 2026 breach report β’ GDPR fines hit β¬6 billion β’ 2026 state privacy laws
Disclaimer: Breach details summarise publicly reported information as of August 2026 and may be revised as investigations continue. This article is general information, not legal advice.