Data breach
Unknown Car Insurance Company
- Records
- 44,629,576
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
10 types of data
- Home addresses44,629,331
- Names44,457,374
- Vehicles43,418,875
- Vehicle VINs42,720,209
- Vehicle models41,960,244
- Phone numbers31,134,452
- Vehicle classes13,328,823
- Vehicle body types13,301,887
- Employment11,091,341
- Salaries11,091,341
About this breach
A large dataset tied to a car insurance operation, containing personal details on tens of millions of individuals, has been indexed by the investigation team. The listing, cataloged as of December 1, 2024, contains 44,629,576 rows. Our investigation team estimates the breach occurred around January 1, 2020, though the identity of the organization behind the data remains unconfirmed, and no hacking group has claimed responsibility for it.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Because the source company has not been identified and no verified public statement from an operator exists, key questions remain open: how the data was obtained, whether it came from a direct intrusion, a third-party supplier, or a dataset assembled from multiple sources, and who first exposed it. We will update this article if new verified information emerges.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Names — 44,457,374 records
Home addresses — 44,629,331 records
Vehicle information — 43,418,875 records, including vehicle models (41,960,244 records), VINs (42,720,209 records), body types (13,301,887 records), and vehicle classes (13,328,823 records)
Phone numbers — 31,134,452 records
Job titles — 11,091,341 records
Job salary data — 11,091,341 records
Not every individual is affected by every type of data listed here.
The scale and composition of this dataset is notable. The combination of home addresses, vehicle models, and VINs matches the kind of records a car insurance operation would hold on policyholders or prospective customers. Salary figures, where present, add another layer of sensitivity.
What Are the Potential Risks for Affected Individuals?
The main risk from a dataset like this is targeted fraud rather than account takeover. Names, addresses, and phone numbers give scammers the raw material for convincing phone and mail scams, including fake insurance renewal notices, bogus accident claims, and phishing calls that reference the victim's actual vehicle to appear legitimate.
Vehicle details such as VINs, models, and body types can also be misused. Criminals involved in vehicle-related fraud, including staged accidents or title and registration scams, value exactly this combination of data. Because no login credentials appear in the indexed fields, direct account compromise through password reuse is less of a concern here than in typical breaches, but the personal data itself supports highly personalized social engineering.
What Should You Do If You Were Affected?
There are practical steps anyone concerned about this dataset can take:
Be skeptical of unexpected calls, texts, or mail about your insurance. If a caller references your vehicle, address, or a policy you do not recognize, hang up and contact your insurer directly using the number on your policy or official website, never the number the caller provides.
Review your insurance statements and credit reports. Watch for policies you did not open, claims you did not file, or unfamiliar addresses tied to your name. You can pull free credit reports from the three major bureaus at annualcreditreport.com.
Place a fraud alert or security freeze if needed. A fraud alert is free and tells creditors to verify your identity before opening new accounts. A credit freeze goes further and can be lifted temporarily when you apply for credit.
Be careful with your VIN. Treat it like semi-sensitive information. While it alone does not grant access to your accounts, it can help criminals fabricate plausible insurance or vehicle-related paperwork.
Do not rely on a single source.
