Aflac Insurance Company said it is investigating a new cybersecurity incident after unauthorized access to the information systems of its subsidiary in Japan . According to the company, the perpetrators were able to gain access to sensitive customer data , including personal information, insurance policy information and bank accounts.

This development is deeply concerning, as it is the second major security incident disclosed by Aflac in about a year, confirming that the insurance industry continues to be one of the main targets of organized cybercrime groups.
What do we know about the attack?
In an official filing with the United States Securities and Exchange Commission (SEC), Aflac announced that its subsidiary, Aflac Life Insurance Japan, detected illegal access to its information systems on June 25, 2026.
The internal investigation showed that the attackers appeared to have gained access to the corporate network for a period of approximately ten days, between June 15 and 25, before being detected by security teams.
See also: Blackfield: Demands $2 million from Nidec after ransomware attack
Immediately after the breach was discovered, the company activated incident response plans, isolating critical systems and temporarily suspending certain services in order to prevent further spread of the attack.
Despite the restrictions imposed on internal infrastructure, Aflac points out that insurance services to its customers continue to be provided as normal.
Aflac: What data may have been leaked
The investigation is still ongoing, but initial findings indicate that cybercriminals gained access to files containing highly sensitive information. Among the data that may have been exposed are insurance policy details, coverage information, personal customer data, as well as banking details related to payments and insurance transactions.
The company has already informed the Japanese Financial Services Agency and the relevant supervisory authorities, while it is committed to personally notifying everyone who is found to be affected by the incident.
At the same time, it clarifies that so far there are no indications that the information systems supporting Aflac's activities in the United States were affected.

External experts undertake the investigation
To investigate the attack, Aflac is working with specialized cybersecurity consultants and digital forensics teams, who are examining how the breach occurred, as well as the true scope of the leak.
See also: Nissan: Employee data breach via Oracle PeopleSoft vulnerability
Although the company has not yet estimated the financial impact of the incident, it is clear that such an attack can have significant costs. In addition to technical restoration work, companies are called upon to manage potential legal liabilities, customer compensation, increased regulatory scrutiny and, most importantly, the loss of trust of policyholders.
The history of cyberattacks at Aflac
The new breach follows another serious incident that Aflac disclosed about a year ago. At the time, the company said cybercriminals may have gained access to files containing personal information of customers, employees, insurance agents and beneficiaries.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Although Aflac had not officially named those responsible for the previous attack, several cybersecurity analysts had pointed out that the characteristics of the breach strongly suggested the actions of the Scattered Spider.
Scattered Spider and attacks on the insurance industry
Scattered Spider is considered one of the most active cybercrime groups in recent years. It is known for its highly targeted social engineering attacks, corporate account compromise , and collaboration with ransomware organizations.
In the past, it has been linked to attacks against major organizations such as MGM Resorts, Caesars Entertainment, DoorDash, Coinbase, Reddit, Twilio, and Riot Games, while it has reportedly collaborated with ransomware groups such as Qilin, DragonForce, and RansomHub.
In addition, the same group has been attributed to the recent series of attacks that hit insurance companies in the United States, including Erie Insurance and Philadelphia Insurance Companies.

The insurance sector remains a key target
Insurance companies are an extremely attractive target for cybercriminals, as they handle a huge amount of personal, financial and medical information. The value of this data on the black market is particularly high, which makes attacks increasingly frequent and more sophisticated.
See also: Indian government website down after hacking attack
The latest Aflac incident highlights once again the importance of continued investment in cybersecurity, prompt detection of suspicious activity, and implementation of robust protection mechanisms against modern digital threats. As organized cybercrime groups continue to evolve their techniques, businesses must continually strengthen their defenses to limit the risk of new breaches.
Source: www.bleepingcomputer.com
