Data breach
Insurance Office of America
- Records
- 144,034
- Breach date
- 15 September 2025Estimated
- Added
- 25 September 2025
What was exposed
4 types of data · 1 puts you at serious risk
- Email addresses1
- Names1
- Phone numbers1
- Social security numbers1
About this breach
Insurance Office of America, a Florida-based insurance brokerage, disclosed a security incident in which an unauthorized party gained access to its internal network through a phishing email. According to the company's breach notice, the intrusion occurred between June 25 and June 30, 2025, and data stored on affected systems may have been accessed or acquired during that window. IOA discovered the incident on June 30, 2025, and launched an investigation with outside cybersecurity experts. Separately, our investigation team has indexed a dataset tied to this listing containing approximately 144,034 rows, with no individual or group currently claiming responsibility for the leak. The ransomware group Daixin, however, listed IOA as a victim on its leak site in September 2025, according to ransomware.live.
June 25 to 30, 2025: Per IOA's notice letter, an unauthorized party accessed the company's network via a phishing email and data on affected systems may have been accessed or acquired.
June 30, 2025: IOA discovered the security incident and began an investigation with external cybersecurity experts.
September 11, 2025: The Daixin ransomware group listed Insurance Office of America on its leak site, according to ransomware.live.
January 16, 2026: Consumer notification letters began going out, according to a filing with the Maine Attorney General.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, email addresses, phone numbers, and names.
IOA's notice letter states that affected individuals' full names were involved, along with additional fields that vary from person to person. The law firm Edelson Lechtzin LLP, which is investigating potential legal claims over the incident, reported in January 2026 that the information may have included names and Social Security numbers. Because IOA handles insurance services for carriers, health plans, and employers, its records can include personal information used for insurance policies, claims processing, and benefit programs.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers are the most sensitive item here. Combined with a name, they can be used to open new credit accounts, file fraudulent tax returns for refunds, or impersonate someone in medical or insurance contexts. Email addresses and phone numbers increase exposure to targeted phishing, since scammers can reference real details to appear legitimate. IOA has stated it has no indication of identity theft or fraud related to this event, but that determination can change over time, and credit monitoring was offered as a precaution.
What Is Insurance Office of America Doing in Response?
According to its notice, IOA took immediate steps to contain the incident and confirm the security of its network after discovery. The company worked with internal and external experts on a review of affected files, a process it described as time-intensive, and notified certain business customers before notifying individuals directly. IOA is offering affected people 24 months of complimentary credit monitoring through Epiq and set up a dedicated incident response line at 855-815-3927. The notice is signed by John Woods, the company's chief information officer.
What Should You Do If You Were Affected?
If you received a letter from IOA, enroll in the offered credit monitoring and read the enrollment instructions carefully. Regardless of notification status, you can take these steps:
Place a fraud alert or security freeze with Equifax, Experian, TransUnion, and Innovis. Freezes are free and must be requested with each bureau separately.
Review bank, credit card, and insurance statements for activity you do not recognize.
Check your credit reports and dispute anything unfamiliar.
Consider an IRS Identity Protection PIN if you want to block fraudulent tax return filings in your name.
Be skeptical of calls, texts, or emails referencing insurance matters and asking for personal details, especially since this breach began with a phishing attack.
In the news
- IOA sample individual notice letter, California Attorney Generaloag.ca.gov (opens in a new tab)
- Maine Attorney General data breach notification filingmaine.gov (opens in a new tab)
- Edelson Lechtzin LLP alert via GlobeNewswireglobenewswire.com (opens in a new tab)
- ransomware.live victim page for Insurance Office of Americaransomware.live (opens in a new tab)
