Automobile Club of Southern California Data Breach Reported in 2026
The Automobile Club of Southern California (ACSC) filed a data breach report in Indiana in March 2026, stemming from an incident on July 10, 2025. This breach exposed a range of sensitive customer data, potentially putting individuals at risk of identity theft and financial fraud.
- State
- Indiana
- Breach date
- July 10, 2025
- Reported
- March 9, 2026
What may have been exposed
- Full Name
- Social Security Number
- Date of Birth
- Driver's License Number
- Insurance Policy Number
- Financial Account Number
- Mailing Address
- Payment Card Information
The Automobile Club of Southern California (ACSC) formally reported a data security incident to authorities in Indiana on March 9, 2026. This filing indicates that the breach occurred on July 10, 2025, and involved unauthorized access to the organization's network infrastructure, though the specific nature of the compromise remains unspecified.
According to the public filing, the exposed data types include Full Name, Social Security Number, Date of Birth, Driver's License Number, Insurance Policy Number, Financial Account Number, Mailing Address, and Payment Card Information. These categories represent highly sensitive personal and financial details that ACSC, an affiliate of AAA, collects as a multi-line motor club, financial services provider, and insurance carrier.
The exposure of such comprehensive data carries significant risks for affected individuals. Compromised information like Social Security Numbers, Financial Account Numbers, and Driver's License Numbers can be used to facilitate identity theft, open fraudulent accounts, or commit other forms of financial fraud. Individuals should be aware that unauthorized access to this data could lead to long-term risks.
Individuals who believe they may be affected by this incident should carefully review any official notifications from ACSC. It is strongly advised to regularly monitor financial account statements, credit reports from all three major bureaus (Equifax, Experian, and TransUnion), and consider placing a fraud alert or security freeze on their credit files. Reporting any suspicious activity to relevant financial institutions and law enforcement is also a crucial step.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Indiana Attorney General filing
Related data breach cases
- Teamsters Local 17
- Bank
- American Motorcyclist Association
- Deer Management Co. LLC dba Bessemer Venture Partners
- MEBS Global Reach
- McKenzie Creative Brands
- Midvale Indemnity and American Family Connect Insurance Company
- Nishiyamato Academy
- 9World Acceptance Corporation
- Chicago Psychoanalytic Institute
- Poppins Payroll Company
- Baltimore Medical System Inc
- Pavillon International Inc
- 7The Association of the Bar of the City of New York