CRC Insurance Data Breach Exposes Social Security Numbers

Published
July 2, 2025
Updated
July 14, 2025
CRC Insurance Data Breach Exposes Social Security Numbers
CRC Insurance Services
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

CRC Insurance Services

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

CRC Insurance Services, LLC, a leading wholesale insurance broker and subsidiary of CRC Group, experienced a significant data breach that affected consumers in multiple states. On Feb. 19, 2025, CRC discovered that unauthorized access to its computer systems had occurred. A subsequent investigation revealed that, on Feb. 3, 2025, data was accessed and acquired without authorization from a file server used by employees in one of its local offices.

The types of personally identifiable information (PII) compromised include names, addresses, Social Security numbers, dates of birth, driver’s license numbers and financial account details such as credit or debit card numbers. In addition, some protected health information (PHI) was also exposed, including medical records and medical information.

According to disclosures filed with state authorities, 1,701 Texas residents, 175 Massachusetts residents and 33 New Hampshire residents were affected. The breach was reported to the Massachusetts Attorney General’s office on June 27, 2025, to the Texas Attorney General’s office on July 1, 2025, and to the New Hampshire Attorney General’s office on July 10, 2025.

The breach was the result of unauthorized access to a file server, but the notice does not specify whether the attack was due to phishing, malware, or another method. Law enforcement was notified, and CRC engaged a third-party cyber forensic expert to investigate, contain and remediate the incident. The severity of this breach is high due to the exposure of both PII and PHI, which can increase the risk of identity theft and fraud for those affected.

CRC Insurance Services' response

In response to the incident, CRC Insurance Services took action to investigate and contain the breach with the help of a third-party forensic firm. The company also notified law enforcement and implemented a range of measures to strengthen its cybersecurity posture, including technical enhancements and updated employee guidance.

To support affected individuals, CRC has partnered with Kroll, a global leader in risk mitigation, to provide complimentary identity monitoring services for a specified period. These services include credit monitoring, fraud consultation and identity theft restoration. Affected individuals are encouraged to enroll in these services by visiting the Kroll enrollment website provided in their notification letter.

Given the nature of the information exposed, those affected should remain vigilant by reviewing their credit reports, bank accounts and other financial statements for unusual activity. It is advisable to place a fraud alert or security freeze on credit files and to promptly report any suspected identity theft to the appropriate authorities. Additional resources and guidance are included in the official notice to consumers, which is available at the bottom of this page in PDF format.

For more information about the company, visit the CRC Group website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
CRC Insurance Services
Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Credit/Debit Numbers
  • Drivers Licenses
  • Financial Account
  • Medical Records
  • Name of individual
  • Address
  • Social Security Number Information
  • Driver’s License number
  • Medical Information
  • Other
  • Date of
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image