Aflac Japan Suffers Second Major Data Breach in 13 Months, Exposing 4.38 Million Customers
Aflac’s Japanese subsidiary, Aflac Life Insurance Japan Ltd., disclosed a cyberattack on June 30, 2026, revealing that hackers accessed its systems for ten days from June 15 to June 25 before detection. The breach compromised the personal data of 4.38 million customers, marking the second major cyber incident for the insurance giant in just over a year.
Scope and Impact of the Breach
The attack targeted Aflac Yoriso Net, the company’s customer portal, along with connected systems. Exposed data includes:
- Personal identifiers: Names, addresses, phone numbers, dates of birth, and gender
- Account details: Security credentials and insurance policy information
- Financial data: Bank account numbers for a subset of customers
Aflac confirmed that no misuse of the stolen data has been detected, though the company is still mapping the full extent of the exposure. Affected individuals will receive notification letters once the investigation concludes.
Timeline of the Attack
- June 10–15, 2026: Earliest reported unauthorized access
- June 15–25, 2026: Confirmed intrusion window
- June 25, 2026: Aflac Japan discovers the breach, suspends affected systems
- June 25–30, 2026: Internal investigation with third-party cybersecurity experts
- June 30, 2026: Public disclosure via SEC filing and Japanese customer notice
The five-day gap between discovery and disclosure aligns with Japan’s regulatory framework, which does not impose a fixed public notification deadline like the EU’s GDPR.
Regulatory and Legal Fallout
As a U.S.-listed company, Aflac filed a Form 8-K with the SEC, emphasizing that the breach was confined to its Japanese operations. The company also notified Japan’s Financial Services Agency (FSA), though no fines or enforcement actions have been announced.
The incident follows Aflac’s 2025 U.S. breach, which exposed 22.65 million records five times the scale of the Japan attack through a social engineering attack. While Aflac has not attributed the 2026 breach to a specific group, reporting links the 2025 incident to Scattered Spider, a cybercrime collective known for targeting insurers via MFA fatigue and help-desk impersonation.
Broader Industry Implications
The breach underscores persistent vulnerabilities in the insurance sector, where decentralized IT systems and high-pressure customer service environments create opportunities for social engineering attacks. With Scattered Spider and similar groups actively targeting insurers, the incident raises questions about the effectiveness of existing defenses, even for well-resourced companies.
Aflac’s stock has not shown a confirmed reaction to the disclosure, but the reputational and legal risks remain significant. The company’s $17.16 billion in 2025 revenue and 50 million policyholders in Japan make it a prime target, and the breach could accelerate regulatory scrutiny in Japan and beyond.
Comparison to Other 2026 Breaches
While substantial, the Aflac Japan breach is smaller than some of 2026’s largest incidents, including:
- KDDI (Japan): 12.2 million email addresses and 7.6 million passwords exposed via a third-party zero-day
- AT&T (2024): 73 million records leaked, leading to a $177 million class-action settlement
The Aflac breach’s inclusion of bank account details heightens the risk of follow-up fraud, particularly through phishing and unauthorized withdrawals.
Unanswered Questions
- Attribution: No group has been officially named, though circumstantial evidence points to Scattered Spider’s playbook.
- Financial Impact: Aflac has not disclosed potential costs, but litigation and remediation expenses could align with the $4.44 million global average for data breaches (per IBM’s 2025 report).
- Long-Term Response: The FSA may tighten reporting requirements for Japanese insurers, while U.S. regulators could scrutinize Aflac’s security posture in future filings.
The incident serves as a reminder of the insurance sector’s appeal to cybercriminals and the challenges of defending against attacks that exploit human, rather than technical, vulnerabilities.
Source: https://tech-insider.org/aflac-japan-data-breach-2026/
JAFLAC cybersecurity rating report: https://www.rankiteo.com/company/jaflac
"id": "JAF1785487197",
"linkid": "jaflac",
"type": "Breach",
"date": "6/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '4.38 million',
'industry': 'Insurance',
'location': 'Japan',
'name': 'Aflac Life Insurance Japan Ltd.',
'size': 'Large (50 million policyholders in Japan)',
'type': 'Subsidiary'}],
'attack_vector': 'Unauthorized Access',
'customer_advisories': 'Notification letters to be sent to affected '
'individuals',
'data_breach': {'data_exfiltration': 'Confirmed',
'number_of_records_exposed': '4.38 million',
'personally_identifiable_information': 'Names, addresses, '
'phone numbers, dates '
'of birth, gender, '
'security credentials, '
'insurance policy '
'information',
'sensitivity_of_data': 'High (includes bank account numbers)',
'type_of_data_compromised': ['Personal identifiers',
'Account details',
'Financial data']},
'date_detected': '2026-06-25',
'date_publicly_disclosed': '2026-06-30',
'description': 'Aflac’s Japanese subsidiary, Aflac Life Insurance Japan Ltd., '
'disclosed a cyberattack on June 30, 2026, revealing that '
'hackers accessed its systems for ten days from June 15 to '
'June 25 before detection. The breach compromised the personal '
'data of 4.38 million customers, marking the second major '
'cyber incident for the insurance giant in just over a year.',
'impact': {'brand_reputation_impact': 'Significant',
'data_compromised': 'Personal identifiers, account details, '
'financial data',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential litigation and regulatory scrutiny',
'operational_impact': 'Suspension of affected systems',
'payment_information_risk': 'High (bank account numbers exposed)',
'systems_affected': 'Aflac Yoriso Net customer portal and '
'connected systems'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Persistent vulnerabilities in the insurance sector due to '
'decentralized IT systems and social engineering risks. '
'Highlights the need for improved defenses against '
'human-targeted attacks.',
'motivation': 'Data Exfiltration',
'post_incident_analysis': {'root_causes': 'Potential social engineering '
'(linked to Scattered Spider’s '
'playbook in 2025 incident)'},
'references': [{'source': 'SEC Filing (Form 8-K)'},
{'source': 'Japanese customer notice'}],
'regulatory_compliance': {'legal_actions': 'Potential litigation',
'regulatory_notifications': ['SEC (Form 8-K)',
'Japan’s Financial '
'Services Agency '
'(FSA)']},
'response': {'communication_strategy': 'SEC filing (Form 8-K), Japanese '
'customer notice',
'containment_measures': 'Suspended affected systems',
'incident_response_plan_activated': 'Yes',
'third_party_assistance': 'Yes (cybersecurity experts)'},
'title': 'Aflac Japan Suffers Second Major Data Breach in 13 Months, Exposing '
'4.38 Million Customers',
'type': 'Data Breach'}