July was a rough month for your personal data, even if you didn't notice. Four separate incidents — an auto insurer, a healthcare giant, a restaurant chain, and an insurance tech provider — pushed driver's license numbers, Social Security numbers, and tens of millions of contact records into criminal hands. There's a decent chance one of them touched you. Here's what actually leaked, and what's worth doing today.
Four breaches, ranked by how much they should worry you
Start with the sleeper: AssuranceAmerica. The auto insurer confirmed exposure of personal information — including driver's license numbers — for 6.9 million people, which SharkStriker's July tracking calls the largest known leak of American driver's license data this year. Why that stings: you can reset a password. You can cancel a card. You cannot reset your driver's license number. Once it's out, it works for fraudsters — synthetic identities, fake accounts, impersonation — for years.
Abbott Laboratories is the volume story. ShinyHunters, the extortion crew behind a string of this year's incidents, claims about 30 million rows of customer data — names, emails, phone numbers, birthdates — with over 1 million Social Security numbers in the mix. SSN plus birthdate isn't spam material; it's the starter kit for real identity theft.
Panera Bread confirmed a breach of contact info: roughly 14 million records, about 5.1 million unique email addresses, per GiaSpace's roundup. No card numbers — but loyalty-list emails are exactly what phishing campaigns run on.
And TruStage, which supplies insurance through credit unions, disclosed a July 15 incident that disrupted some services and potentially affects millions of credit union customers. It has an FAQ and an online claim page up.
TechRepublic's ranking of 2026's biggest breaches makes the pattern plain: July wasn't a fluke, it was a continuation. The year's defining theme is compromise through vendors and third parties you never chose.
Match your response to what leaked
Driver's license exposed? Freeze your credit at all three bureaus. It's free, it takes minutes, and it blocks new accounts opened in your name. Then be suspicious of DMV-flavored messages and anyone who "verifies" you by reciting your license number.
SSN possibly involved? The freeze stops being optional — do it now. Watch your existing accounts, plan to file taxes early to beat refund fraud, and treat any caller who already knows your birthdate as hostile until proven otherwise.
Email in the Panera set? Incoming: fake rewards, fake refunds, fake delivery problems, all wearing convincing branding. One boring rule defeats all of it — never act through a link in a message you didn't ask for. Open the app yourself. Type the address yourself.
Credit union member? Check whether your insurance runs through TruStage, and use their claim page if so.
The part worth sitting with
Nobody who got caught in July's wave did anything wrong. No stronger password would've helped — these were corporate and vendor systems, not personal accounts. The realistic 2026 posture is to assume your identifiers are already out there and make them worthless: frozen credit, a skeptical inbox, and actually reading the breach notices — because increasingly they come from companies you've never heard of, about data you never knew they had.
Image: Nathan Thomas, via Pexels





