Skip to content
  • Home
  • Latest Data Breaches
  • Contact Us
  • About Us
  • Resources
  • What You Need to Know
info@databreachrights.com
info@databreachrights.com
  • Home
  • Latest Data Breaches
  • Contact Us
  • About Us
  • Resources
  • What You Need to Know

National Insurance Company Data Breach Exposes Social Security Numbers and Insurance Account Numbers

/ Insurance / By databreachrights
Published: 10 October 2026
Insurance data breach illustration
Breach Discovery: September 2026Breach Notification: October 2026

A law firm holding records on behalf of National Insurance Company confirmed in September 2026 that a cybersecurity incident exposed names, Social Security numbers, insurance account numbers, and in some cases dates of birth. The total number of people affected has not been publicly disclosed. Affected individuals should place a credit freeze and enroll in the free monitoring service offered in their notice right away.

CompanyNational Insurance Company
IndustryInsurance
Data Types ExposedFull Names, Social Security Numbers, Insurance Account Numbers, Dates of Birth
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Network Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the National Insurance Company Data Breach?

National Insurance Company has been named in a data breach notification tied to a cybersecurity incident at an outside law firm. The firm, Squire Patton Boggs, held personal information on behalf of a client. That filing appeared on the Massachusetts breach notification list for October 2026, which is how this incident came to public attention.

According to the notice, the firm confirmed on a specific date in September 2026 that sensitive personal information sat inside files affected by the incident. The firm also finished matching mailing addresses to impacted individuals around that same time. However, the notice does not say when unauthorized access to the files actually began or how long it continued.

The letter does state that the information came into the firm’s possession through legal work it performed for one or more clients. As a result, people who never directly interacted with the firm could still be affected, since companies like insurers often send client records to outside counsel for claims and compliance matters. The firm says it opened an investigation, alerted law enforcement and regulators, and added new monitoring tools to help prevent a repeat incident.

Who was affected?

The notice identifies the affected group as clients of National Insurance Company whose records were held by the law firm. Because the filing came through a Massachusetts regulatory listing, individuals in that state were clearly included. In addition, notices of this type are often sent to residents of many states at once, so the true geographic reach could extend well beyond Massachusetts.

The exact number of people affected has not been publicly disclosed. Neither the state listing nor the notice itself includes a total count. This means anyone who holds or held an account with National Insurance Company should not assume they are in the clear simply because a national figure has not surfaced.

It also is not clear whether the affected population includes only policyholders or extends to other individuals whose information passed through the insurer’s claims or legal files. Because insurance records often include family members or dependents, the scope could include minors in some cases, though the notice does not specifically address this.

What Information Was Potentially Exposed?

The notice lists a defined set of personal data categories involved in this incident. Not every affected person had the same items exposed, since the notice specifies that dates of birth were only involved in some instances.

  • Full names
  • Social Security numbers
  • Insurance account numbers
  • Dates of birth (in some instances)

Social Security numbers are especially sensitive because, unlike a password or account number, they cannot simply be reset. Once exposed, a Social Security number can remain useful to criminals for years. When combined with a name and date of birth, it becomes a powerful tool for opening new credit accounts, filing fraudulent tax returns, or passing identity verification checks at banks and other institutions.

The presence of insurance account numbers adds another layer of risk. Criminals could potentially use these numbers to attempt fraudulent claims or to take over existing policy accounts. Because this data was held in connection with insurance records, affected individuals should also watch for unusual activity tied to their coverage, not just their credit files.

What is the company doing?

Squire Patton Boggs, the law firm that held the data, says it launched an investigation after discovering the incident. In addition, the firm reports that it contacted law enforcement and relevant regulators and added new security controls and monitoring systems as a precaution against future intrusions.

The firm is also offering complimentary identity theft protection and credit monitoring through Epiq to individuals who received a notice. Enrollment instructions and an activation code were included directly in the letter. For broader context, the notice also points readers to a reference guide covering fraud alerts and security freezes, which includes guidance sourced from the Federal Trade Commission.

This notice was filed with Massachusetts regulators as part of the state’s required data breach reporting process. Because state filings like this one can understate the true scope of a breach, individuals in other states may still receive their own version of the same notice.

What Should Affected Individuals Do?

Place a Fraud Alert or Credit Freeze

Because Social Security numbers were involved, affected individuals should strongly consider placing a fraud alert or a full credit freeze with Equifax, Experian, and TransUnion. A freeze is generally the stronger option, since it blocks new accounts from being opened in your name without your direct approval.

This step matters because Social Security numbers do not expire or reset. Once a freeze is in place, you can temporarily lift it whenever you need to apply for credit yourself, which keeps you protected without creating lasting inconvenience.

Monitor Your Credit Reports and Insurance Accounts

Affected individuals should pull free credit reports from annualcreditreport.com and review them closely for unfamiliar accounts or inquiries. Because insurance account numbers were also exposed, it makes sense to review insurance statements and claims history for activity you do not recognize.

Regular monitoring helps you catch fraud early, before it causes lasting financial damage. If you notice anything suspicious, report it to the insurer and to the credit bureaus right away.

Enroll in the Offered Identity Protection Services

The notice includes an offer for complimentary identity theft and credit monitoring through Epiq, along with an activation code. If you received this letter, it is worth enrolling promptly, since these services can flag suspicious activity faster than you might catch it on your own.

Keep a copy of your notice and the enrollment details in a safe place. This way, if you ever need to prove your eligibility for these protections or reference your specific case, you will have the documentation ready.

Stay Alert for Phishing Attempts

After a breach like this, scammers often send fake emails, texts, or phone calls pretending to represent the insurer or the law firm involved. Be cautious of any message asking you to confirm personal details or click a link, even if it looks official.

Instead, contact the organization directly using a phone number or website you already trust, not one provided in the suspicious message. This simple habit can prevent a second round of fraud following the original breach.

Consider Speaking With a Data Breach Attorney

If your personal information was included in this incident, you may have legal options worth exploring. Consulting with an attorney who focuses on data breach cases can help you understand whether you qualify to join a claim.

Many consultations are free and carry no obligation, so there is little downside to asking questions. An attorney can also help you understand realistic timelines and what kind of compensation past settlements have provided to affected consumers.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

  • Aon plc Data Breach Exposes Client and Corporate Data
  • American Family Connect Insurance Company Data Breach Exposes Personal and Policyholder Information
  • United Underwriters Data Breach Exposes Personal and Financial Information

Browse all recent data breaches →

← Previous Post
Next Post →

DataBreachRights

5547 Edmonson Pike Suite 67

Nashville, TN 37211

Email : info@databreachrights.com

 

  • Home
  • Latest Data Breaches
  • Contact Us
  • Resources
  • Terms of Service
  • Legal Disclaimer
  • Privacy Policy
Were you affected?
Free, no-obligation case review
Check now