On July 8, 2024, the John P. Meehan Agency discovered unusual activity in their network. An investigation confirmed unauthorized access to a single employee email account between July 2, 2024, and July 8, 2024, during which data on the account was acquired. The company issued a press release on November 22, and affected customers began receiving notifications in November 2025.
The compromised data varied by individual but may have included names, Social Security numbers, driver's license or state identification numbers, passport numbers, financial account information, payment card information, dates of birth, and medical information. The exact number of affected individuals is not publicly confirmed at this time.
Additional details may emerge as the situation develops, and notification timelines for individuals can vary.