Insurance
Home›Insurance›Industry & Deals›Fiesta Insurance said it notified customers 17 days af…
Fiesta Insurance said it notified customers 17 days after data review
The Las Vegas-based franchisor began notifying affected people on July 13, 2026, after concluding on June 26 that potentially accessed files contained sensitive personal and financial information.
Fiesta Insurance Franchise Corporation took more than a year to assess a cybersecurity incident before concluding that certain files potentially accessed or acquired by an unauthorized party contained sensitive personal and financial information, according to Insurance Business.
The company said it learned on June 9, 2025 that systems in its network environment had been affected, then finished an extensive data review on June 26, 2026. It started notifying affected individuals on July 13, 2026, 17 days after making that determination.
Insurance Business reported that at least 12,097 Texas residents were affected, based on information released through the state's data-breach reporting process. The notice described information that may have included names, addresses, Social Security numbers, dates of birth, passport and driver's license numbers, financial account information, and health-related financial information, with no indication of identity theft or fraud found as of the notice date.
Fiesta, which runs a franchise network combining insurance distribution with tax-return preparation and electronic filing services, has not said how the attacker gained access, how long it maintained access, whether ransomware or extortion occurred, or which specific corporate or franchise systems were affected. Insurance Business also noted that its public notice does not state whether the affected files were encrypted or whether the incident triggered federal reporting under the FTC's Safeguards Rule.