---
title: "Seven Million Driver Records, Halted Taxis and… | Firevault"
description: "A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan's largest taxi operator, mobile…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks#webpage",
      "url": "https://fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks",
      "name": "Seven Million Driver Records, Halted Taxis and…",
      "description": "A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan's largest taxi operator, mobile…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/33656224-d50b-426b-97be-d6ecb72eb334/this-week-in-hacks-drivers-taxis-military-phones-2026-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Seven Million Driver Records, Halted Taxis and Agentic Ransomware: What This Week Tells Us About Data Exposure",
          "item": "https://fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Seven Million Driver Records, Halted Taxis and Agentic Ransomware: What This Week Tells Us About Data Exposure",
      "description": "A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan's largest taxi operator, mobile network spying against US military personnel, and the first documented agentic ransomware operation. The common thread is data that lived where attackers could reach it.",
      "url": "https://fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/33656224-d50b-426b-97be-d6ecb72eb334/this-week-in-hacks-drivers-taxis-military-phones-2026-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/33656224-d50b-426b-97be-d6ecb72eb334/this-week-in-hacks-drivers-taxis-military-phones-2026-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/33656224-d50b-426b-97be-d6ecb72eb334/this-week-in-hacks-drivers-taxis-military-phones-2026-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/33656224-d50b-426b-97be-d6ecb72eb334/this-week-in-hacks-drivers-taxis-military-phones-2026-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-20T16:31:42.988481+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 779,
      "keywords": "Seven, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap, AssuranceAmerica data breach, 7 million drivers license stolen, Nihon Kotsu cyber attack, Japan taxi malware, US military phones targeted, SS7 mobile network attack, Citizen Lab surveillance report, ad tech location tracking, ransomware taxi dispatch, Jade Puffer agentic ransomware, AI powered ransomware, this week in hacks, data breach roundup, cyber resilience",
      "articleBody": "Author: Mark Fermor, Director and Co-Founder, Firevault. Analysis of the week ending 17 July 2026, drawing on reporting by PCMag, the Financial Times, Security Affairs, Business Insider and Sysdig. AssuranceAmerica: close to seven million drivers exposed The headline breach of the week hit AssuranceAmerica, a motor insurance provider operating across fourteen states in the United States. Attackers",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How large was the AssuranceAmerica breach?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Close to seven million driver records were taken, including contact details, driving licence information, vehicle data and claims history across the fourteen US states where AssuranceAmerica operates."
          }
        },
        {
          "@type": "Question",
          "name": "What is agentic ransomware?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Agentic ransomware uses a large language model to plan and execute an attack end to end, from target selection through intrusion, encryption and reporting. Sysdig's Jade Puffer research is believed to be the first documented example."
          }
        },
        {
          "@type": "Question",
          "name": "Why does Offline Secure Storage matter after weeks like this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Every incident this week involved data or systems that were online at the moment of attack. Offline Secure Storage keeps sensitive records physically disconnected outside authorised access windows, which removes the surface an automated attacker or remote intruder needs to reach them."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

AssuranceAmerica: close to seven…Nihon Kotsu: malware halts Japan…US military phones targeted thro…Jade Puffer: the first agentic r…What connects these four storiesThe Firevault viewPractical next stepsMore Resources

[Knowledge Vault](/learn/knowledge)/ [Insight](/learn/knowledge?filter=insight)

Insight · Breach Analysis · 20 July 2026 

# Seven Million Driver Records, Halted Taxis and Agentic Ransomware: What This Week Tells Us About Data Exposure

A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan's largest taxi operator, mobile network spying against US military personnel, and the first documented agentic ransomware operation. The common thread is data that lived where attackers could reach it.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fassuranceamerica-jade-puffer-ss7-week-in-hacks)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fassuranceamerica-jade-puffer-ss7-week-in-hacks&text=Seven%20Million%20Driver%20Records%2C%20Halted%20Taxis%20and%20Agentic%20Ransomware%3A%20What%20This%20Week%20Tells%20Us%20About%20Data%20Exposure%0A%0AA%20single%20week%20in%20July%202026%20brought%20a%20seven%20million%20record%20insurance%20breach%20in%20the%20United%20States%2C%20a%20malware%20shutdown%20at%20Japan's%20largest%20taxi%20operator%2C%20mobile%20network%20spying%20against%20US%20military%20personnel%2C%20and%20the%20first%20documented%20agentic%20ransomware%20operation.%20The%20common%20thread%20is%20data%20that%20lived%20where%20attackers%20could%20reach%20it.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fassuranceamerica-jade-puffer-ss7-week-in-hacks)[](mailto:?subject=Seven%20Million%20Driver%20Records%2C%20Halted%20Taxis%20and%20Agentic%20Ransomware%3A%20What%20This%20Week%20Tells%20Us%20About%20Data%20Exposure&body=A%20single%20week%20in%20July%202026%20brought%20a%20seven%20million%20record%20insurance%20breach%20in%20the%20United%20States%2C%20a%20malware%20shutdown%20at%20Japan's%20largest%20taxi%20operator%2C%20mobile%20network%20spying%20against%20US%20military%20personnel%2C%20and%20the%20first%20documented%20agentic%20ransomware%20operation.%20The%20common%20thread%20is%20data%20that%20lived%20where%20attackers%20could%20reach%20it.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fassuranceamerica-jade-puffer-ss7-week-in-hacks)

![Shattered driver licence, halted Tokyo taxi and targeted military smartphone rendered in magenta and cyan data streams, illustrating the week in cybersecurity incidents](/__l5e/assets-v1/33656224-d50b-426b-97be-d6ecb72eb334/this-week-in-hacks-drivers-taxis-military-phones-2026-2x.jpg)

Shattered driver licence, halted Tokyo taxi and targeted military smartphone rendered in magenta and cyan data streams, illustrating the week in cybersecurity incidents

Why it matters

## What this means for organisations holding critical data

A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan's largest taxi operator, mobile network spying against US military personnel, and the first documented agentic ransomware operation. The common thread is data that lived where attackers could reach it.

In this analysis

1.  01 [AssuranceAmerica: close to seven…](#section-0)
2.  02 [Nihon Kotsu: malware halts Japan…](#section-1)
3.  03 [US military phones targeted thro…](#section-2)
4.  04 [Jade Puffer: the first agentic r…](#section-3)
5.  05 [What connects these four stories](#section-4)
6.  06 [The Firevault view](#section-5)

**On this page**[AssuranceAmerica: close to seven…](#section-0)[Nihon Kotsu: malware halts Japan…](#section-1)[US military phones targeted thro…](#section-2)[Jade Puffer: the first agentic r…](#section-3)[What connects these four stories](#section-4)[The Firevault view](#section-5)

_Author: Mark Fermor, Director and Co-Founder, Firevault. Analysis of the week ending 17 July 2026, drawing on reporting by PCMag, the Financial Times, Security Affairs, Business Insider and Sysdig._

## AssuranceAmerica: close to seven million drivers exposed

The headline breach of the week hit AssuranceAmerica, a motor insurance provider operating across fourteen states in the United States. Attackers walked away with personal data on close to seven million drivers, including contact details, driving licence information, vehicle records and claims history. The scale only became public because Maine's state notification law forced disclosure, a reminder that regulatory transparency is often the only reason customers ever learn what has happened to their information.

For anyone whose data now sits on a criminal forum, the practical exposure is long lived. Licence numbers, vehicle identifiers and claims narratives do not rotate the way a compromised password does. They feed identity fraud, targeted phishing and insurance manipulation for years.

## Nihon Kotsu: malware halts Japan's largest taxi fleet

In Tokyo, Japan's largest taxi operator Nihon Kotsu was forced to take booking and dispatch systems offline after a malware infection. Passengers were left without rides while the company worked to contain the incident and understand its origin. Security Affairs carried the full account, including the company's public apology.

The lesson is one Firevault has made before. When operational systems live on the same network as the data attackers want, a security incident becomes a service outage. Customers feel it long before the incident response report is written.

## US military phones targeted through SS7

The Financial Times reported that attackers in the Middle East have been probing mobile and advertising technology networks to locate devices belonging to US military personnel stationed in the region. The method involves the long known SS7 signalling flaw, used as a ping to flush out handset locations. Senator Ron Wyden described it as potentially the first use of commercially available data to spy on American personnel during an active conflict.

The uncomfortable truth is that the surveillance economy sells the same signals to everyone. Once mobile location data and advertising identifiers are collected at scale, adversaries can buy or steal what allies collected for marketing.

## Jade Puffer: the first agentic ransomware

Researchers at Sysdig, reported by Business Insider, revealed Jade Puffer, believed to be the first documented example of agentic ransomware. A large language model is given the objective, chooses the targets, selects the tooling, executes the intrusion, encrypts what it finds and reports back on progress. The techniques are not new. The automation is.

What used to require a team of operators can now be handed to a model overnight. That changes the economics of ransomware and shortens the time defenders have between initial access and encryption. It also removes the human bottleneck that historically limited how many organisations could be attacked in parallel.

## What connects these four stories

Each incident involves data or systems that were reachable from the open internet at the moment attackers chose to act. Insurance records held in a live application. Dispatch systems running on a connected network. Mobile identifiers moving through commercial signalling. Corporate estates waiting for an autonomous agent to knock on the door.

Perimeter controls, detection tooling and incident response all matter. None of them prevent the underlying condition, which is that sensitive data sits online by default and depends on continuous defence to stay private.

## The Firevault view

[Offline Secure Storage](/offline-secure-storage) takes the opposite starting position. A vault is physically disconnected outside authorised access periods. There is no session for a remote attacker to hijack, no service to enumerate and no automated agent that can reach the drive when it is powered down. Access is one to one, per user, within defined windows, with sessions that end automatically after 120 minutes.

Agentic ransomware only accelerates a trend we have described for two years. The organisations that fare best are the ones that treat their most sensitive records, keys, evidence, matter files and successor data as offline by default and reconnect them only when a person needs them. Everything else is a race between attacker automation and defender attention.

## Practical next steps

For individuals affected by the AssuranceAmerica disclosure, monitor credit files, enable multi factor authentication on financial accounts and be sceptical of any inbound contact referencing your policy. For operators of critical services, assume that connected dispatch, booking and identity systems will be targeted and rehearse the manual fallback. For anyone holding data that would cause harm if exposed, ask a simple question. Does this need to be online right now, or can it live offline until someone actually needs it?

_Sources: PCMag UK, Financial Times, Security Affairs, Business Insider, Sysdig research disclosure._

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)[

![Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg)

Breach Analysis 

### Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust

Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.

13 Aug 2026 4 min 







](/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026)[

![Ransomware Attacks Spike 20% in July While AI Steals the Headlines](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg)

Breach Analysis 

### Ransomware Attacks Spike 20% in July While AI Steals the Headlines

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

12 Aug 2026 4 min 







](/news/ransomware-attacks-spike-july-2026-ai-distraction)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)