Cybercrime
,
Data Breach Notification
,
Data Privacy
Incident Is Insurance Giant’s Second Major Data Breach Since June 2025
Marianne Kolbasuk McGee (HealthInfoSec) •
July 1, 2026

Aflac’s Japanese life insurance subsidiary said nearly 4.4 million customers and agents were affected by a June hacking incident. (Image: Aflac)
Insurance giant Aflac is notifying regulators and nearly 4.4 million Aflac Life Insurance Japan customers and agents of a hacking incident detected last week that potentially affected their personal and financial information. The data breach is Aflac’s second hacking incident affecting millions of people in the past year.
See Also: From Data Deluge to AI Advantage: Securing systems, building resilience, elevating CX
Georgia-based Aflac on Tuesday reported the incident involving its Japanese subsidiary to the U.S. Securities and Exchange Commission, saying the data breach was limited to its IT systems in Japan and didn’t affect the company’s U.S. business systems.
“Although the investigation remains ongoing, Aflac Japan has determined that certain impacted files contain policy and coverage details, personal information and bank account information,” Aflac told the SEC. “Aflac Japan has notified the Japan Financial Services Agency and other relevant authorities, and intends to provide appropriate notifications to individuals affected by this incident.”
On Wednesday, Aflac Japan also posted a breach notice along with a frequently asked questions page on its local website about the incident, disclosing that 4.38 million people are affected, including 230,000 whose insurance premium transfer account information was leaked.
Aflac Japan said that on June 25, it “detected a high load on the information processing unit, CPU.” The investigation has so far revealed “that some information, including customer and agent personal details, was illegally viewed and leaked by systems such as Aflac Yoroiso Net, by third parties.”
“The first instance of unauthorized access occurred on June 15, and we have confirmed multiple unauthorized access incidents up to June 25,” Aflac Japan said.
“The cause and scope of impact are under investigation, and details of recurrence prevention measures are being considered,” Aflac Japan said. Based on the findings, the company “will implement necessary measures from both technical and administrative perspectives.”
As Aflac Japan responds to the incident, it said it has suspended certain systems and services supporting its “Yoriso Net” portal for policyholders. That includes the portal’s comprehensive medical checkup and checkup reservation service, fertility concierge service, online budgeting service and Aflac AI support concierge.
Restoration of those services will be “as soon as safety confirms,” the company said.
Leaked information varies depending on the system that was accessed by the unauthorized actor, but potentially includes customer name, date of birth, gender, address, phone number, policy number, coverage details and insurance premium transfer account, such as financial institution name, branch name, deposit type, account number and account name.
The Aflac Japan data breach is the second major hacking incident affecting millions of customers’ information that Aflac has disclosed since June 2025 (see: Aflac: Cybercrime Campaign Targeting the Insurance Industry).
Aflac first disclosed its earlier incident to the SEC on June 20, 2025, saying that the company was the victim of a “sophisticated cybercrime campaign” targeting insurers.
The June 2025 Aflac attack came on the heels of attacks on two other large U.S. insurers, including Erie Indemnity Co. – which does business as Erie Insurance – and Philadelphia Insurance Companies (see: Two Insurers Say Ongoing Outages Not Ransomware-Based).
Security researchers had speculated that cybercriminal gang Scattered Spider was behind the attack on Aflac, as well as those other insurance industry incidents.
In January, Aflac said that the 2025 data theft incident affected nearly 22.7 million people, including compromising their health and personal information, Social Security numbers, and other sensitive data (see: Aflac Notifies 22.7 Million People of June Data Theft Attack).
Aflac declined ISMG’s request for additional details about the company’s latest breach, but in a statement said, “the Aflac Japan incident has no connection to the incident we disclosed in the U.S. in June 2025.”
Some experts said multiple hacks on major companies within a short window of time are more common that many people realize.
“This brings to light the critical issue of re-victimization,” said Theresa Payton, CEO of security firm Fortalice Solutions. “Sophisticated threat actors view a multinational corporation as a single entity with multiple entry points. If the main network is heavily reinforced after an initial incident, attackers will naturally pivot to see if identical gaps exist within overseas branches,” said Payton, who was White House CIO under President George W. Bush and was the first woman to hold the job.
While the investigation into Aflac’s most recent hack is still ongoing, the incident could indicate the attackers are leveraging shared weaknesses in either identity access gaps, cloud configurations or third-party vendors, she told ISMG.
Although it’s not clear from the outside what the attackers used to gain a foothold in the latest Aflac breach, other investigations into incidents involving re-victimization have uncovered issues such as attackers taking advantage of undetected persistence including deeply embedded backdoors; the access broker market for compromised credentials or session cookies; and the “blueprint effect,” she said.
“Public disclosures, while necessary, give the broader hacking community a map. Other syndicates will scan a company’s global subsidiaries to check if the publicized vulnerabilities remain unpatched in those regions,” Payton said of the blueprint effect.
Cybercrime syndicates operate with a focus on efficiency and return on investment, she said. “An organization actively recovering from a first breach is often at its most vulnerable, internal IT teams are facing burnout, resources are stretched thin, and monitoring tools may be in flux during network rebuilds, creating an ideal window for a secondary attack.”