AGIA, an insurance marketing and program administration company, has notified certain individuals that their personal information may have been involved in a cybersecurity incident affecting a company that maintains data on AGIA’s behalf. Companies that share personal data with vendors and business partners remain responsible for making sure that data is properly protected, and affected individuals deserve clear answers about what happened and what they can do next.
AGIA’s Data Breach Investigation
According to a notification letter dated July 27, 2026, Doxa Insurance Holdings, LLC (“Doxa”) notified individuals that it was the victim of a cybersecurity incident that impacted data it maintains in its electronic systems on behalf of A.G.I.A., LLC. In other words, the personal information at issue was originally collected in connection with AGIA’s insurance and benefit programs, but was affected while in the custody of Doxa, a vendor that processes or stores that data as part of its services to AGIA.
The letter states that Doxa elected to notify the FBI of the incident rather than filing a local police report, and it directs affected individuals to a dedicated help line for additional information about their specific circumstances. As is common with vendor-side breaches, the notification letter does not specify exactly how the incident occurred, when it was first discovered, or the full scope of what data was accessed.
Data breaches involving third-party vendors and administrators are an increasingly common feature of the insurance industry, since companies like AGIA often rely on outside firms to help process claims, administer benefit programs, and manage customer records. When a vendor experiences a security incident, the individuals affected are often customers of the company that originally collected their information, even though the breach itself occurred on another company’s systems. This arrangement can make it more difficult for affected individuals to understand exactly who is responsible for protecting their data and who they should contact with questions.
As part of its response, Doxa is offering affected individuals complimentary identity theft protection and credit monitoring services through Cyberscout/Identity Force, a TransUnion company, for 24 months from the date of enrollment. Enrollment must be completed within 90 days of the date of the letter. Companies and their vendors that collect and store sensitive personal information have a duty to implement reasonable safeguards to protect it, and when that duty is not met, whether by the original company or by a vendor it entrusted with the data, affected individuals may have legal recourse.
Notification letters like this one are typically required under state data breach notification laws, which generally obligate a company (or, in some cases, its vendor) to notify affected residents within a certain time frame after discovering unauthorized access to protected personal information. Under Massachusetts law specifically, affected individuals also have the right to obtain a police report connected to the incident and the right to place a security freeze on their credit accounts, both of which are addressed in the notification letter’s accompanying resources.
When Did This Breach Occur?
The exact date the underlying cybersecurity incident occurred has not been publicly disclosed. The notification letter sent to affected individuals is dated July 27, 2026, and directs recipients to enroll in the complimentary credit monitoring offer within 90 days of that date. Neither AGIA nor Doxa has published additional detail about when the incident was first detected or how long it took to identify affected individuals.
What Information Was Breached?
AGIA and Doxa have not publicly disclosed which specific categories of personal information were involved in this incident. The notification letter does not itemize the types of data affected, instead directing individuals with questions to a dedicated help line using a unique code included in their personal letter. The offer of credit monitoring and identity theft protection services suggests the information at issue may include data commonly associated with identity theft risk, though this has not been confirmed publicly by either company.
What You Can Do
If you received a notification letter referencing AGIA or Doxa Insurance Holdings, consider taking the following steps to protect yourself:
- Enroll in the complimentary Cyberscout/Identity Force credit monitoring and identity theft protection services referenced in your notification letter within the stated enrollment window.
- Regularly review your bank and credit card statements for unauthorized or unfamiliar transactions.
- Consider placing a fraud alert or security freeze with the three major credit bureaus: Equifax, Experian, and TransUnion.
- Request and review your free annual credit reports for signs of unauthorized activity.
- Be cautious of phishing emails, calls, or texts referencing this incident, since scammers often target individuals shortly after a breach becomes public.
File a Data Breach Lawsuit Against AGIA
If your personal information was affected by this incident involving AGIA and its vendor Doxa Insurance Holdings, you may have legal options available. Companies that share personal data with third-party vendors remain responsible for ensuring that data is reasonably protected, and affected individuals may be entitled to compensation when that responsibility is not met.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.