A.G.I.A. LLC Data Breach Exposes Social Security Numbers and Driver’s License Numbers

Insurance data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the A.G.I.A. Data Breach?

A.G.I.A. LLC, also known as AGIA Affinity, has disclosed a data breach that exposed sensitive personal information belonging to its customers. The company works as a third-party administrator in the insurance industry. It partners with association and membership groups to manage insurance and benefit programs for their members.

The breach did not originate inside A.G.I.A.’s own network. Instead, it traces back to Doxa Insurance Holdings LLC, a vendor that stores and manages personal data on A.G.I.A.’s behalf. Doxa suffered a cybersecurity incident that compromised the electronic systems holding this information. As a result, personal data tied to A.G.I.A. customers was exposed to unauthorized parties.

The exact discovery date for this incident has not been publicly disclosed. However, the timeline of the response is clearer. Doxa mailed notification letters to affected A.G.I.A. customers in July 2026. Shortly after, on August 3, 2026, the breach was formally reported to the Massachusetts Office of Consumer Affairs and Business Regulation.

Because Doxa acted as a data processor for multiple insurance clients, the forensic investigation into this incident likely extended beyond A.G.I.A. alone. Doxa reviewed its systems to determine which individuals and which categories of data were affected. This investigation ultimately confirmed that Social Security numbers and driver’s license numbers were exposed for A.G.I.A.’s customers.

Who was affected?

The individuals affected by this breach are customers of A.G.I.A., meaning people enrolled in insurance or benefit programs through their association or membership organizations. Since A.G.I.A. serves as an administrator for many different membership groups, the affected population likely spans multiple organizations and geographic regions across the country.

The exact number of individuals impacted by this breach has not been publicly disclosed. What is confirmed is that Doxa identified enough affected people to warrant mailing individual notification letters and filing a report with Massachusetts regulators. This suggests a meaningful scale of exposure, even without an exact figure.

Because A.G.I.A. administers programs tied to associations and membership organizations, affected individuals may include policyholders of varying ages. It remains unclear whether any minors were among those impacted. Anyone who received a notification letter from Doxa should treat it as confirmation that their data was involved.

What Information Was Potentially Exposed?

The breach at Doxa exposed specific categories of sensitive personal information tied to A.G.I.A. customers. These data types are considered highly sensitive because they can be used directly to commit identity theft or fraud.

  • Social Security numbers
  • Driver’s license numbers

Because Social Security numbers were exposed, affected individuals face a heightened risk of identity theft. Criminals can use this number to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can take months to detect and even longer to fully resolve.

In addition, exposed driver’s license numbers can be used to create fake identification documents or to impersonate victims in other ways. When combined with a Social Security number, a driver’s license number gives criminals nearly everything needed to pass identity verification checks. As a result, affected individuals should treat both pieces of information as high-risk exposures requiring immediate attention.

What is the company doing?

In response to the breach, Doxa notified affected individuals by mail in July 2026. The company also reported the incident to Massachusetts regulators, fulfilling its legal obligation to disclose the breach publicly. This notification effort allows affected customers to take protective steps quickly.

Beyond notification, Doxa is offering meaningful support to affected individuals. The company is providing 24 months of complimentary identity theft protection and credit monitoring services. These services come through Cyberscout and Identity Force, a TransUnion company, giving affected people access to established fraud-detection tools.

To enroll, individuals must visit the Cyberscout activation page and enter the unique code included in their notification letter. Enrollment must be completed within 90 days of the letter’s date, so prompt action matters. Doxa has also set up a dedicated help line at 1-833-851-9219 for questions about the incident. Representatives are available Monday through Friday, 8 a.m. to 8 p.m. Eastern time, excluding holidays, and this line will stay active for 90 days from the notification date.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Because Social Security numbers were exposed, affected individuals should check their credit reports regularly. Reviewing reports from all three major credit bureaus can help catch unauthorized accounts early. Look specifically for unfamiliar credit inquiries, new accounts, or changes to your personal information.

You are entitled to a free credit report from each bureau once a year through annualcreditreport.com. Given this breach, it makes sense to space these out and check one every few months. This way, you maintain ongoing visibility without any added cost.

Consider a Credit Freeze or Fraud Alert

Since both Social Security and driver’s license numbers were exposed, placing a credit freeze offers strong protection. A freeze blocks lenders from accessing your credit file, which stops most attempts to open new accounts in your name. This step is free and can be reversed anytime you need to apply for credit yourself.

Alternatively, a fraud alert requires creditors to verify your identity before extending new credit. This option is less restrictive than a freeze but still adds a layer of protection. Because your driver’s license number was also exposed, consider contacting your state’s DMV to flag potential misuse of that identification as well.

Enroll in the Offered Identity Protection Services

Doxa is providing 24 months of free identity theft protection and credit monitoring through Cyberscout and Identity Force. Affected individuals should take advantage of this offer right away, since it comes at no cost. This service can detect suspicious activity faster than manually checking your accounts.

To enroll, visit the Cyberscout activation page and use the unique code from your notification letter. Remember, enrollment closes 90 days after the date on your letter. Therefore, don’t delay if you want to secure this protection before the deadline passes.

Stay Alert for Phishing Attempts

After a breach involving sensitive data, scammers often follow up with phishing emails, texts, or phone calls. These messages may pretend to be from A.G.I.A., Doxa, or even the credit monitoring provider. Because of this, always verify the sender before clicking links or sharing information.

If you receive a suspicious message referencing this breach, contact Doxa’s dedicated help line directly at 1-833-851-9219 to confirm its legitimacy. In addition, never provide your Social Security number, driver’s license number, or account passwords in response to an unsolicited request. When in doubt, reach out to the company through official channels only.

Understand Your Legal Options

If your personal information was exposed in this breach, you may have legal options worth exploring. Many affected individuals choose to consult a data breach attorney for a free case evaluation. This can help clarify whether you qualify for compensation related to the exposure of your data.

Because laws around data breach liability vary by state, an attorney can explain what applies to your situation. Additionally, acting sooner rather than later matters, since claims may be subject to filing deadlines. A free consultation costs nothing and can provide clarity on your next steps.



Related Data Breaches

View the full list of tracked data breaches →