Desk live·
ForensicPost
Insurance/Exposure/File 22-0527b

Elephant Insurance Breach Reached 2.76 Million People, Most of Whom Only Asked for a Quote

Names, birth dates and driver’s license numbers left the Virginia auto insurer over six days in spring 2022. Plaintiffs say the quote form’s auto-fill handed the numbers out, the same way GEICO’s had. The company has never confirmed how it happened.

Constructed geometry · not a chart of case data
JurisdictionUSAHenricothe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetElephant Insurance Co.
ActorUnattributed
S. Rosler8 min readConfidence: high3 sources reviewed

Elephant Insurance Co., the U.S. auto insurer owned by Britain’s Admiral Group, told customers in letters dated late May 2022 that an unauthorised party had viewed or copied data between March 26 and April 1, 2022. The fields were name, date of birth and driver’s license number. A filing with the Maine attorney general, as reported, put the total at 2,762,687 people. The company held the records on current and former customers and on people who had requested a quote.

Elephant identified unusual activity in April and finished identifying affected individuals on April 25. It offered 12 months of credit monitoring. It has not confirmed how the data was taken.

The Quote Form, Again

The class action alleges the mechanism: the online quoting platform auto-populated a driver’s license number when given a name, address and birth date, and attackers used that feature at scale. That is what GEICO’s tool had done a year earlier, filed at 21-0419, and what New York’s regulator penalised at GEICO and Travelers in 2024. Elephant has neither confirmed nor denied it. The allegation is a plaintiffs’ claim and is carried as one; the six-day window and 2.76 million count fit it.

Standing, A Decade On

The consolidated case, Holmes v. Elephant Insurance, was dismissed in June 2023 for lack of standing. On Oct. 14, 2025, the Fourth Circuit reversed as to two plaintiffs whose license numbers had appeared on the dark web and affirmed the dismissal for the rest. The court’s line is the one the sector has lived with since the CareFirst ruling filed at 15-0520: exposure alone is not injury, and a plaintiff needs to show the data went somewhere.

For a driver’s license number, that showing is unusual. The number is used quietly, in a benefits claim or a loan application, and the person whose number it is finds out when something is denied. Two of nearly 3 million could show it. The rest could not, which is a statement about evidence rather than about what happened to them.

How we reported this

Compiled from Elephant’s sample notice as filed with the California attorney general, the Fourth Circuit’s 2025 opinion and contemporaneous trade reporting, listed below. The 2,762,687 figure is attributed to a Maine filing reported by others; the portal could not be fetched. A separate Elephant email-account incident notified in January 2023 is not part of this file. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Elephant Insurance sample notice, May 27, 2022California Attorney General
  2. Elephant Insurance Reports Data BreachInsurance Journal
  3. Holmes v. Elephant Insurance Co., No. 23-1782U.S. Court of Appeals for the Fourth Circuit
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary