NSE Insurance Agencies disclosed that unauthorized parties may have accessed and acquired files containing personal information during a November 2025 network intrusion. The exposed data includes Social Security numbers, financial account details, and medical information.
What happened
NSE Insurance Agencies observed unauthorized access to its network on or about November 28, 2025. The company secured its environment and began an investigation with external cybersecurity professionals. On August 24, 2026, that investigation determined that certain files containing personal information may have been accessed and acquired between November 6, 2025, and November 29, 2025.
The affected information includes full names and one or more of the following: Social Security numbers, driver's license or state ID numbers, other government ID numbers, financial account information, credit or debit card information, medical information, and health insurance policy information. Not all information was affected for every individual. Starting on or about September 21, 2026, NSE mailed notices to all potentially impacted individuals for whom it had a last known home address.
What was said
The NSE Insurance Agencies NSE Insurance Agencies notice of data breach said, "The privacy and security of the personal information we maintain is of the utmost importance to NSE Insurance Agencies."
NSE said it has been working with "external cybersecurity professionals experienced in handling these types of incidents."
The company also stated, "We have no evidence that any personal information has been or will be misused as a direct result of the incident."
Why it matters
NSE's notice lists Social Security numbers, government IDs, financial account and card details, medical information, and health insurance policy information in the same set of files. Insurance agencies collect all of these categories to write and service policies, so a single intrusion can expose an individual's financial, identity, and health profiles at once.
NSE is not alone among insurers who experienced a data breach this month. United Underwriters Insurance, a property-and-casualty insurer based in Provo, Utah, disclosed a breach involving the unauthorized download of files from its systems. The company mailed its notification letters on September 21, 2026, the same date NSE began mailing its own. The company determined the files were downloaded on May 1, 2026, and a report filed with Massachusetts regulators says the breach affected Social Security numbers, medical records, financial accounts, and driver's licenses. That is nearly the same set of data types NSE reported.
The problem also reaches larger insurers. AssuranceAmerica reported that nearly 7 million individuals were affected, in an incident that began with malicious activity targeting a single employee and yielded credentials used to access and copy files.
The bottom line
NSE's breach, along with United Underwriters and AssuranceAmerica, shows the insurance sector is a repeat target because of the sensitive records it holds. When intrusions take months to scope, the delay between attack and notification can be as damaging as the attack itself.
Related: HIPAA Compliant Email: The Definitive Guide
FAQs
What is medical identity theft?
Medical identity theft happens when someone uses another person's identity or health insurance information to obtain care or prescriptions.
Why can it take months to notify people after a breach?
Organizations often need time to investigate, determine which files were affected, and identify who those files belong to before they can send notices.
What is the difference between personal information and protected health information?
Personal information covers identifiers like names, Social Security numbers, and financial accounts, while protected health information covers health-related details tied to a specific person.
Go deeper: What is the difference between PII and PHI?
