Aflac’s Japanese subsidiary disclosed on June 30, 2026 that hackers broke into its customer systems and stole personal data belonging to 4.38 million people, the second major cyberattack to hit the insurance giant’s corporate family in just over a year. Aflac Life Insurance Japan Ltd., a wholly owned unit of the Georgia-based Aflac Incorporated, said an unauthorized third party accessed its systems for ten days before anyone noticed, according to a Form 8-K the company filed with the Securities and Exchange Commission and reporting from Security Affairs.
Aflac Japan Confirms Data Breach Affecting 4.38 Million CustomersTimeline: How the Aflac Yoriso Net Breach UnfoldedWhat Customer Data Was ExposedInside Aflac’s SEC Filing and Regulatory NotificationsWhat the Japan FSA Notification MeansIs Scattered Spider Behind the Aflac Japan Breach?A Repeat Target: Aflac’s 2025 US BreachWhat Aflac Said About the 2025 IncidentScattered Spider’s Playbook: Why Insurers Keep Falling For ItMarket Impact: Aflac’s Stock, Revenue and Investor ConfidenceHow the Aflac Breach Compares to Other 2026 Data BreachesScattered Spider’s Known Insurance-Sector TargetsThe Regulatory Patchwork: Japan FSA vs US Disclosure Rules5 Predictions for Aflac and the Insurance SectorHow Affected Aflac Customers Can Protect ThemselvesFrequently Asked QuestionsHow many people were affected by the Aflac Japan data breach?What data was stolen in the Aflac data breach?Is this the same Aflac breach from 2025?Was Scattered Spider responsible for the Aflac Japan breach?Did the Aflac Japan breach affect US customers?What is Scattered Spider?What should Aflac customers do after the breach?Has Aflac faced any fines or lawsuits over the breach?Related Coverage
The breach hit “Aflac Yoriso Net,” the company’s customer-facing policyholder portal, along with other connected systems. Names, addresses, phone numbers, dates of birth, gender, security details, insurance account information and, for some customers, bank account data all left the building. Aflac says the exact mix of stolen data varies by customer.
Industry insights, the latest tech news, and special interviews, all in the Tech Insider Newsletter.
One email a week. No spam, unsubscribe anytime.
For a company that spent the back half of 2025 explaining a breach of its US operations, this is not the headline Aflac wanted. It also raises an uncomfortable question for the wider industry, and it lands amid a fast-growing list of 2026 cybersecurity threats facing global businesses: if a company with Aflac’s resources and a full year of hindsight can get hit twice, what does that say about everyone else’s defenses?
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
Aflac Japan Confirms Data Breach Affecting 4.38 Million Customers
Aflac Japan’s own language leaves little room for spin. In its Japanese-language customer notice, translated and reported by Security Affairs, the company said: “It has come to our attention that our customer-only website, ‘Aflac Yoriso Net,’ and other systems were subjected to unauthorized access by a third party, resulting in the leakage of some information, including customers’ personal information. At this time, no misuse of the information related to this incident has been confirmed.”
That last line matters. Aflac is drawing a distinction between data being copied and data being actively abused, a distinction that will likely shape both the regulatory response and any eventual class-action filings. The company says its investigation is ongoing with help from external cybersecurity experts, and that affected individuals will receive letters once Aflac finishes mapping exactly which fields were exposed in each case.
Timeline: How the Aflac Yoriso Net Breach Unfolded
Based on Aflac’s own disclosure, the intrusion ran from June 15 to June 25, 2026, a ten-day window during which the attacker sat inside Aflac Japan’s systems undetected. The company says it discovered the unauthorized access on June 25 and moved quickly to contain it by suspending the affected systems, a step that knocked some customer services offline during recovery.
Aflac Japan then spent five days on an initial investigation before going public on June 30, 2026, filing its 8-K with US regulators the same day it published its Japanese customer notice. Five days from discovery to public disclosure is fast by industry standards, especially compared with breaches elsewhere in the sector that have taken weeks or months to surface once investigators start digging.
Date (2026)EventJune 10-15Earliest reported point of unauthorized access to Aflac Japan systemsJune 15-25Confirmed intrusion window per Aflac’s SEC filingJune 25Aflac Japan discovers the breach and suspends affected systemsJune 25-30Internal investigation with third-party cybersecurity expertsJune 30Public disclosure, Japanese customer notice, and Form 8-K filed with SECJune 30 onwardJapan Financial Services Agency notified, individual customer letters pending
What Customer Data Was Exposed
Aflac has been explicit that exposure is uneven across the 4.38 million affected people. The confirmed categories include:
Full names, mailing addresses and phone numbersDates of birth and genderSecurity and authentication details tied to online accountsInsurance policy and coverage informationBank account information tied to premium payments, for a subset of customers
That combination of financial and policy-level data is what makes this data breach more dangerous than a typical email-and-password leak. Bank details tied to insurance premiums give fraudsters a direct line to attempt unauthorized withdrawals or to build convincing follow-up phishing messages, while policy specifics hand social engineers exactly the kind of insider detail that made help-desk impersonation so effective against other insurers in 2025.
Inside Aflac’s SEC Filing and Regulatory Notifications
Because Aflac Incorporated is a US-listed company, the Japan breach still triggered American disclosure obligations even though not a single US customer record was touched. The Form 8-K states: “On June 30, 2026, Aflac Life Insurance Japan Ltd. (‘Aflac Japan’), a wholly owned subsidiary of Aflac Incorporated, a Georgia corporation (the ‘Company’), issued a press release announcing that, on June 25, 2026, Aflac Japan discovered an unauthorized third-party had unlawfully accessed certain of Aflac Japan’s systems between June 15, 2026 and June 25, 2026.”
The filing also draws a firm boundary around scope: “Although the investigation remains ongoing, Aflac Japan has determined that certain impacted files contain policy and coverage details, personal information, and bank account information.” Aflac has stressed that the incident is confined to Japanese systems and that its US infrastructure was not accessed.
What the Japan FSA Notification Means
Aflac Japan also notified Japan’s Financial Services Agency and unspecified “other relevant authorities,” the standard first move for a regulated insurer operating in the country. Unlike the EU’s 72-hour GDPR breach-notification clock, Japan’s framework does not force insurers onto a fixed public-disclosure timeline, which helps explain why Aflac had five days between discovery and its public statement. The FSA can demand remediation plans and, in more serious cases, issue business improvement orders, but no fine or formal enforcement action tied to this incident has been made public as of this writing.
Is Scattered Spider Behind the Aflac Japan Breach?
Aflac has not named an attacker for the Japan breach, and neither the company’s press release nor its SEC filing point to a specific group. That is worth stating plainly, because it would be easy to assume this is simply a sequel to 2025’s wave of insurance-sector attacks.
What is on the record: Security Affairs, reporting on the Japan breach, noted that “Aflac is among several insurance companies hit in 2025 by cyberattacks, including Allianz Life, in a wave linked to the cybercrime group Scattered Spider.” That is a pattern observation about Aflac’s broader 2025-2026 exposure, not a confirmed technical attribution for the June 2026 Japan intrusion specifically.
Sources familiar with the investigation indicated to CNN that these incidents bear the hallmarks of a notorious and emerging cybercrime collective known as Scattered Spider.
CNN, reporting on Aflac’s 2025 cyberattack disclosure (source)
Until Aflac’s investigation concludes or a security research firm publishes forensic evidence, the responsible framing is to treat the 2026 Japan breach as unattributed, while acknowledging the obvious circumstantial overlap: a well-resourced insurer with a large personal-data footprint, hit for the second time in about a year, in an industry that a known threat actor has been actively working.
A Repeat Target: Aflac’s 2025 US Breach
This is not Aflac’s first incident. In June 2025, the company’s US operations were hit by a separate cyberattack that Aflac disclosed publicly within days of detection.
What Aflac Said About the 2025 Incident
Aflac told reporters it detected the intrusion on June 12, 2025, and that it “was able to halt the intrusion within a few hours” of discovery. According to Aflac, the attackers used social engineering to gain unauthorized network access rather than exploiting a software flaw or deploying ransomware.
This attack, similar to those currently affecting many insurance providers, was orchestrated by a sophisticated cybercrime faction.
Aflac spokesperson, June 2025 (source)
According to Aflac, the attackers employed “social engineering” techniques to gain unauthorized access to its network.
Aflac, June 2025 disclosure (source)
Aflac itself stopped short of naming Scattered Spider in its public statements. Later reporting put the total number of people affected by the 2025 US incident at approximately 22.65 million, roughly five times the scale of the 2026 Japan breach, and covering personal and health-related information rather than the bank-account data now confirmed in the Japan case.
Scattered Spider’s Playbook: Why Insurers Keep Falling For It
Scattered Spider, also tracked by researchers as UNC3944 and Octo Tempest, does not rely on exotic malware or unpatched software. Per CISA’s public guidance on the group’s tactics, members pose as company IT or help-desk staff over the phone or by text message, ask employees or contractors to reset passwords or re-enroll multi-factor authentication, and bombard targets with repeated MFA push notifications until someone taps “approve” just to make the prompts stop, a technique known as MFA fatigue.
Insurers make unusually good targets for that approach. They run large, often decentralized IT environments spanning agents, brokers and legacy policy-administration systems, and their call centers are built around resolving requests quickly, not interrogating every caller. The 2025 wave reported to have touched Aflac, Allianz Life and other insurers exploited exactly that culture of speed.
Researchers who track the group describe a pattern that looks roughly like this in practice:
Caller: “Hi, this is [name] from IT. I’m locked out and I have a client
on hold. Can you reset my MFA so I can get back in?”
Help desk: verifies a name and employee ID, resets MFA enrollment
Attacker: enrolls their own device, signs in with phished or
purchased credentials
Result: full account access, no malware, no exploit, no alert
That simplicity is the point. Vishing calls do not trip antivirus software, and a help-desk agent trying to clear a call queue is a softer target than a patched firewall.
Market Impact: Aflac’s Stock, Revenue and Investor Confidence
Aflac remains a financially massive operation. The company posted $17.164 billion in revenue for fiscal year 2025, and traded with a market capitalization in the neighborhood of $58.7 billion as of mid-2026. The insurer serves roughly 50 million policyholders in Japan and a similarly sized base in the United States, according to company materials, making it one of the largest suppliers of supplemental insurance in the world and, not coincidentally, one of the largest single repositories of sensitive personal and financial data in the industry.
Nothing in the public record so far shows a confirmed AFL share-price move tied directly to the June 30 disclosure, and Aflac has not said the breach will materially affect its financial results. But the reputational math is straightforward: this is Aflac’s second disclosed major breach in roughly thirteen months, and each incident adds to a due-diligence file that cyber insurers, institutional investors and regulators will not ignore forever.
IBM’s 2025 Cost of a Data Breach Report found the global average cost of a breach fell to $4.44 million, down 9% from $4.88 million in 2024, the first decline in five years. IBM credited faster identification and containment powered by AI-assisted defenses for the drop. Whether Aflac’s own costs land above or below that average will depend on litigation, notification expenses, and how many of the 4.38 million affected customers take up whatever remediation offer the company makes.
How the Aflac Breach Compares to Other 2026 Data Breaches
Aflac Japan’s 4.38 million figure is large but not close to the biggest breach disclosed this year. It sits in a crowded field of telecom and insurance incidents, several of them also originating in Asia-based subsidiaries of global companies.
CompanyDisclosedPeople / Records AffectedData ExposedAflac JapanJune 30, 20264.38 millionNames, addresses, DOB, policy details, bank account infoKDDI (Japan)July 7, 202612.2M email addresses, 7.6M passwordsEmail addresses and passwords via third-party zero-dayAflac (US operations)June 2025~22.65 million (per later reporting)Personal and health-related informationAT&T (dataset leak)March 30, 2024~73 millionNames, SSNs, DOB, account numbersAT&T (cloud-linked incident)July 12, 2024~109 million accountsCall and text metadata
For a closer look at the KDDI incident referenced above, see Tech Insider’s coverage of the KDDI data breach. AT&T’s two 2024 incidents eventually produced a $177 million class-action settlement, split roughly $149 million for the March dataset case and $28 million for the July cloud-linked case, covering about 99.7 million notice recipients combined. That is the scale of financial exposure a large breach can generate once litigation runs its course, and it is the benchmark Aflac’s legal team is almost certainly watching.
Scattered Spider’s Known Insurance-Sector Targets
The Aflac Japan breach lands inside a broader pattern of attacks on insurers that started well before this year. Public reporting has connected the group to a string of 2025 incidents across the sector, though attribution confidence varies from case to case.
OrganizationYearStatusAflac (US operations)2025Confirmed breach, social engineering, Scattered Spider link reported by CNN but not confirmed by AflacAllianz Life2025Confirmed breach, publicly linked to the Scattered Spider waveErie Indemnity2025Reported target in the same wave of attacksPhiladelphia Insurance / Tokio Marine2025Reported target in the same wave of attacksAflac Japan2026Confirmed breach, attacker not publicly named
Five confirmed or reported insurance-sector targets in roughly two years is enough to call this a sustained campaign against the industry rather than a string of coincidences, even where individual attribution remains unconfirmed.
The Regulatory Patchwork: Japan FSA vs US Disclosure Rules
The Aflac Japan breach is a useful case study in how differently regulators treat the same company depending on jurisdiction. Japan’s Financial Services Agency expects notification and a remediation plan but does not impose a fixed public-disclosure countdown, giving insurers a few days of breathing room to investigate before going public.
The United States runs on a patchwork instead. State breach-notification laws, which Aflac had to navigate for its 2025 US incident, set varying deadlines and required content for consumer letters. Layered on top of that, the SEC’s cybersecurity disclosure rule requires US-listed companies to report material incidents on Form 8-K within four business days of determining materiality, which is why a breach that never touched a single American customer record still produced a US regulatory filing within days of Aflac Japan’s internal investigation wrapping up.
5 Predictions for Aflac and the Insurance Sector
More scrutiny from Japan’s FSA. A second Aflac breach inside two years makes a formal review or tightened reporting requirement for Japanese insurers more likely, even without a confirmed fine tied to this incident yet.US shareholder or consumer litigation risk rises. Plaintiffs’ firms that filed suits after the 2025 US incident now have a second data point to argue a pattern of inadequate security investment, even though this breach is based in Japan.Scattered Spider-style attacks keep spreading to mid-size insurers. The tactics require no custom malware, so smaller carriers without dedicated help-desk verification protocols are the likely next targets.Faster public disclosure becomes the norm in Japan. Aflac’s five-day turnaround from discovery to disclosure may set a new informal benchmark other Japanese financial firms feel pressure to match.Phishing-resistant authentication adoption accelerates. Expect more insurers to fast-track hardware security keys and passkeys for employee and help-desk verification specifically to blunt MFA-fatigue attacks.
How Affected Aflac Customers Can Protect Themselves
Anyone who holds an Aflac Japan policy, or who has family members that do, should treat the coming weeks as a heightened-risk window rather than wait for a letter to arrive:
Review bank and insurance account statements for unauthorized transactions, especially around premium-payment datesTreat unsolicited calls, texts or emails referencing real policy numbers or coverage details as a red flag, not proof of legitimacyChange the password on any Aflac online account and avoid reusing that password anywhere elseEnable phishing-resistant multi-factor authentication wherever Aflac or a linked financial account offers itWatch for the official notification letter Aflac has promised, and verify any follow-up contact through Aflac’s published customer service channels rather than a number provided in an unsolicited message
Research from Cloudflare has found that leaked or reused credentials are involved in a large share of successful account-takeover attempts, which is exactly why reusing an Aflac password anywhere else turns one breach into several. Readers who want a deeper comparison of authentication options can see Tech Insider’s passkeys vs passwords vs 2FA breakdown.
Frequently Asked Questions
How many people were affected by the Aflac Japan data breach?
Aflac Japan says 4.38 million customers and agents had personal information exposed after attackers accessed its systems between June 15 and June 25, 2026.
What data was stolen in the Aflac data breach?
Depending on the customer, exposed data includes names, addresses, phone numbers, dates of birth, gender, account security details, insurance policy information, and in some cases bank account details tied to premium payments.
Is this the same Aflac breach from 2025?
No. This is a separate incident affecting Aflac’s Japanese subsidiary in June 2026. Aflac’s US operations were hit by a different attack in June 2025 that later reporting put at roughly 22.65 million affected people.
Was Scattered Spider responsible for the Aflac Japan breach?
Aflac has not named an attacker for the 2026 Japan breach. Reporting has linked Aflac’s 2025 US incident, along with attacks on Allianz Life and other insurers, to the group known as Scattered Spider, but no confirmed technical attribution has been published for the 2026 Japan intrusion specifically.
Did the Aflac Japan breach affect US customers?
No. Aflac says the incident was contained to Aflac Japan’s systems and did not reach its US infrastructure or customer data.
What is Scattered Spider?
Scattered Spider, also tracked as UNC3944 or Octo Tempest, is a financially motivated hacking group known for social engineering, including impersonating IT staff to trick help desks into resetting passwords and multi-factor authentication, according to CISA’s public guidance on the group.
What should Aflac customers do after the breach?
Security guidance generally recommends watching bank and insurance statements for unauthorized activity, enabling phishing-resistant multi-factor authentication where available, and treating unsolicited calls or emails that reference real policy details with suspicion rather than trust.
Has Aflac faced any fines or lawsuits over the breach?
As of publication, no fine or lawsuit tied specifically to the 2026 Japan breach has been made public. Aflac Japan says it has notified Japan’s Financial Services Agency and other relevant authorities and plans to notify affected individuals by letter.
Related Coverage
The Tech Insider Newsletter
Industry insights, the latest tech news, and special interviews, every week.
One email a week. No spam, unsubscribe anytime.