HomeSecurityHackers breached insurance company Aflac

Hackers breached insurance company Aflac

Aflac Insurance Company said it was the target of a serious cyberattack , with attackers likely stealing sensitive data such as Social Security numbers, medical records and insurance claims . It is the latest in a string of cyberattacks that have plagued the U.S. insurance industry.

Aflac cyberattack

With annual revenues of several billion dollars and tens of millions of policyholders, Aflac is considered the largest victim so far of the broader campaign underway against insurance companies in the United States. The incident has mobilized the FBI and specialized cybersecurity analysts, who are working to limit the scope of the breach.

See also: Hackers target US insurance companies

Erie Insurance and Philadelphia Insurance Companies also reported recent breaches that resulted in serious disruptions to their information systems. According to CNN, all of the incidents bear the technical hallmarks of the Scattered Spider cybercrime group – a particularly active and dangerous group that uses social engineering to bypass corporate defenses.

In a statement , Aflac said it was a cyberattack “by a sophisticated criminal group,” without naming the perpetrators. The company said it detected the breach early and stopped it within hours, assuring that no ransomware was used and that essential services to policyholders continue uninterrupted.

However, the scope of the data breach remains unclear. Aflac is one of the largest providers of supplemental health insurance in the US, with a particular focus on covering medical expenses not covered by primary insurance.

See also: Scattered Spider hackers target US retail

Initial estimates suggest that the hackers entered the network using social engineering – such as tricking employees into revealing critical security information. This is a common tactic of the Scattered Spider group, which often pretends to be part of technical support teams to gain access to sensitive systems.

Defense proposals

Insurance companies like Aflac need to adopt security practices, starting with full visibility across their entire infrastructure. Particular emphasis is placed on identity management, the use of multi-factor authentication (MFA), and tightening processes like password resets.

Hackers breached insurance company Aflac

Privilege separation and implementing strong authentication controls are considered critical steps to protect against increasingly sophisticated Scattered Spider methods.

See also: Salt Typhoon hackers target telecoms with GhostSpider backdoor

As we mentioned earlier, hackers heavily use social engineering techniques, so organizations are urged to invest in training employees and security teamsto recognize impersonation attempts that appear via SMS, phone calls, or popular messaging apps. Often, attackers use an aggressive tone to exert psychological pressure on the victim and ensure cooperation.

The UK has already been targeted by the Scattered Spider group, with recent breaches targeting major retailers such as Marks & Spencer, Co-op and Harrods. In all incidents, the attackers followed the same social engineering tactic and, in the final stage, activated the DragonForce.

Source: edition.cnn.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS