AIO APEX

Aflac Japan Breach Exposes 4.38 Million Policyholders' Data, Including 230,000 Bank Accounts

BleepingComputer
Share:
Aflac Japan Breach Exposes 4.38 Million Policyholders' Data, Including 230,000 Bank Accounts

Aflac Life Insurance Japan has disclosed a significant data breach affecting approximately 4.38 million policyholders, after attackers gained unauthorized access to the company's systems over a 10-day window in June 2026. The breach also compromised bank account numbers for roughly 230,000 customers, making the incident immediately actionable for financial fraud.

What Was Stolen

According to the company's disclosure filed June 30, 2026, attackers accessed Aflac Japan's systems between June 15 and June 25, 2026. The compromised data spans a broad range of personally identifiable information: full names, dates of birth, residential addresses, phone numbers, and insurance policy and coverage details. For approximately 230,000 customers who use bank accounts to pay premiums, account numbers were also exposed. An additional 40,000 insurance agency contacts had their information compromised in the same intrusion.

US Operations Were Not Affected

Aflac (NYSE: AFL) confirmed that the breach was contained to its Japanese subsidiary. Systems supporting U.S. business operations were not accessed, and American policyholders are not affected. Aflac holds a dominant position in Japan's supplemental insurance market, where it insures roughly one in four households — making the scale of this breach especially significant in that market context.

Scattered Spider Fingerprints

Security analysts have noted similarities between the tactics used in this breach and those associated with Scattered Spider, a loosely organized threat group known for targeting financial institutions and insurance companies with social engineering and identity-based attacks. Scattered Spider has been linked to multiple high-profile intrusions at financial and hospitality firms over the past two years. Aflac has not publicly attributed the attack to any specific group, and the investigation with external cybersecurity experts is ongoing.

What Affected Customers Should Do

Customers whose bank account numbers were exposed face the most immediate risk. Aflac has urged affected policyholders to monitor their accounts for unauthorized transactions and to contact their banks if suspicious activity appears. The company is expected to notify affected individuals directly. Beyond immediate account monitoring, policyholders should be alert to targeted phishing attempts, since attackers now hold enough personal detail — name, address, phone, coverage type — to craft convincing impersonation messages.

The breach adds Aflac Japan to a growing list of financial-sector companies hit by sophisticated intrusions in 2026. As reported by BleepingComputer, the disclosure was made through an SEC filing, underscoring the cross-border regulatory complexity of incidents involving US-listed companies with major overseas operations.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: