Doxa E&S Solutions Data Breach Exposes Social Security Numbers and Government IDs

Insurance data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the Doxa E&S Solutions Data Breach?

Doxa E&S Solutions, LLC recently confirmed a data security incident involving sensitive client information. The company operates as a surplus lines insurance brokerage and claims adjusting firm. It holds licenses across dozens of states and is affiliated with DOXA Insurance Holdings.

According to a filing submitted to the Vermont Attorney General’s Office, the firm reported the incident on July 27, 2026. The filing confirms that Social Security numbers and government-issued identification numbers were exposed. However, the company has not disclosed the exact date the intrusion occurred or when it was first discovered internally.

Because the notification did not specify a root cause, the public record currently lacks detail about how attackers or unauthorized parties gained access. This filing arrived around the same time as a related disclosure from an affiliated Doxa entity. That timing suggests the two organizations may share back-office systems or technology infrastructure, though this has not been officially confirmed.

State breach notification laws, including Vermont’s, generally require companies to report incidents affecting residents within a set window after discovery. As a result, the gap between when a breach actually happens and when the public first learns about it can span weeks or months. At this time, no further forensic details have been made public.

Who was affected?

The individuals affected by this incident are clients of Doxa E&S Solutions who had personal identification data on file with the firm. Because the company operates as a surplus lines broker and adjusting firm, its client base likely includes both policyholders and claimants across many states.

The Vermont filing confirms at least one Vermont resident was affected. However, the total number of individuals impacted nationwide has not been publicly disclosed. Given that surplus lines brokers often serve clients through shared administrative systems spanning multiple states, the true scope of this breach could extend well beyond Vermont.

At this stage, it remains unclear whether the exposed data belongs primarily to individual policyholders, business clients, claimants, or a mix of all three. Additional details may emerge as more state filings become available or as Doxa E&S Solutions issues direct notification letters to affected people.

What Information Was Potentially Exposed?

Based on the regulatory filing, the confirmed categories of exposed data are limited but highly sensitive. These are the types of identifiers that carry serious long-term risk when compromised.

  • Social Security numbers
  • Government-issued identification numbers

The company has not confirmed whether other data types, such as names, addresses, phone numbers, or policy details, were also involved. If you receive a direct notification letter, it may include more specific information about exactly what was exposed in your individual case.

Social Security numbers and government ID numbers are considered top-tier risk data because they enable direct identity theft. For example, criminals can use these numbers to open new credit accounts, apply for loans, or file fraudulent tax returns in a victim’s name. Unlike a password, these identifiers usually cannot be changed once compromised.

As a result, victims may face elevated fraud risk for years rather than months. In addition, government ID numbers can be used to create fraudulent documents or impersonate victims for benefits fraud. This combination of exposed data makes ongoing vigilance especially important for anyone affected.

What is the company doing?

Doxa E&S Solutions took the required step of notifying the Vermont Attorney General’s Office about the incident, as mandated under state law. This filing represents the company’s formal acknowledgment that client data was exposed without authorization.

However, the firm has not yet released a detailed public statement explaining the root cause of the incident or outlining specific remediation measures. It also has not confirmed whether it is offering credit monitoring or identity protection services to affected individuals. As more information becomes available, this will likely include additional notification letters sent directly to impacted clients, along with further regulatory filings in other states.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request copies of their credit reports from all three major bureaus and review them closely. Look for accounts you did not open or inquiries you do not recognize.

Because Social Security numbers were exposed, this type of monitoring should continue for an extended period. Fraudulent activity connected to a stolen Social Security number does not always appear immediately, so consistent checking matters more than a single review.

Place a Fraud Alert or Credit Freeze

Given the exposure of Social Security numbers, placing a fraud alert or a full credit freeze with Equifax, Experian, and TransUnion is a strong protective step. A freeze restricts new creditors from accessing your file, which makes it much harder for someone to open accounts in your name.

This step is free and can be lifted temporarily whenever you need to apply for credit yourself. Because government ID numbers were also exposed, consider these protections a baseline rather than an optional precaution.

Watch for Signs of Tax Identity Theft

Tax identity theft occurs when someone files a fraudulent return using your stolen Social Security number. Warning signs include a rejected tax return or unexpected letters from the IRS about a return you never filed.

If this happens, contact the IRS immediately and consider requesting an Identity Protection PIN for future filings. Acting quickly can limit the financial disruption caused by this specific type of fraud.

Stay Alert for Phishing Attempts

Scammers often use publicized data breaches as an opportunity to target victims with fake emails or phone calls. These messages may reference the Doxa E&S Solutions incident to appear legitimate while attempting to extract even more personal information.

Therefore, avoid clicking links or sharing details with anyone who contacts you unexpectedly about this breach. Instead, verify any communication by contacting the company directly through a phone number you find independently.

Preserve Your Notification Letter and Consider Legal Options

If you receive a written notice from Doxa E&S Solutions, keep it in a safe place. This letter may serve as important documentation if you later decide to pursue a legal claim related to the breach.

Because insurance brokerages are expected to implement reasonable safeguards for sensitive client data, affected individuals may have legal options available. Consulting a data breach attorney for a free case evaluation can help you understand whether you qualify for compensation.



Related Data Breaches

Check other recent data breach notifications →