Fiesta Insurance took a year to identify breached customer data - report

The year-long delay centered on Fiesta's file review, not a confirmed missed notification deadline

Fiesta Insurance took a year to identify breached customer data - report

Cyber

By Mav Rodriguez

Fiesta Insurance Franchise Corporation spent more than a year investigating a cybersecurity incident before determining that files potentially accessed or acquired by an unauthorized party contained sensitive personal and financial information.

At least 12,097 Texas residents were affected, according to information disclosed through the state's data-breach reporting process. Fiesta has not published the total number of affected individuals across the US.

What happened in the incident

The Las Vegas-based insurance and tax-services franchisor said it became aware on June 9, 2025, that systems within its network environment had been affected by a cyber incident. Following a forensic investigation and an "extensive data review," it determined on June 26, 2026, that potentially accessed or acquired files contained personal information.

Fiesta began notifying affected individuals on July 13, 17 days after reaching that determination. The information involved varied by individual but may have included names, addresses, Social Security numbers, dates of birth, passport numbers, driver's license numbers, financial account information and health-related financial information.

The company said it had found no indication of identity theft or fraud connected with the incident as of the date of its notice. It has not disclosed how the unauthorized party entered its systems, how long access was maintained, whether ransomware or extortion was involved, or which corporate or franchise systems were affected.

What is Fiesta Insurance?

Fiesta operates a franchise network offering personal and commercial insurance alongside tax-return preparation and electronic filing services. Its franchise materials say offices provide products including motor, home, renters and commercial insurance through relationships with national and regional carriers.

The combination of insurance distribution and tax preparation broadens the regulatory context of the incident. Professional tax preparers are treated as financial institutions under the US Federal Trade Commission's Safeguards Rule and must maintain written information-security programs to protect customer data.

The rule also requires covered financial institutions to notify the FTC no later than 30 days after discovering the unauthorized acquisition of unencrypted customer information involving at least 500 consumers. Fiesta's public notice does not state whether the affected files were encrypted, whether the incident met the federal reporting test or whether a report was made to the FTC.

Texas law separately requires businesses to notify affected individuals no later than 60 days after determining that a breach occurred. Incidents involving at least 250 Texans must be reported to the state attorney general as soon as practicable and no later than 30 days after that determination.

Based on Fiesta's stated timeline, individual notifications began within 17 days of its June 26 determination. The publicly available information therefore does not, by itself, establish that Fiesta missed the Texas notification deadlines. It also does not explain why the forensic investigation and review of the affected data lasted more than a year.

Several proposed class actions were filed against Fiesta in the US District Court for the District of Nevada following the disclosure. The complaints are allegations, and no finding of liability has been made.

The incident raises questions for insurance franchise and distribution businesses about the visibility of data held across corporate and franchise systems, the separation of information collected through different services and the time required to identify individuals affected by a cyber event. Fiesta has not publicly detailed whether the review involved decentralized franchise records or a central data environment.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!