Menu
Browse

Cyber Incident Victim: Aflac Incorporated

Date:

Jan 2018

Location:

United States of America

Summary

Aflac Incorporated experienced a cybersecurity incident involving unauthorized access to independent contractor sales agents' email accounts, potentially exposing clients' sensitive personal information. The breach compromised details including names, addresses, dates of birth, policy and Social Security numbers, and bank account data, with the company's internal review confirming the exposure scope. The incident occurred over several months but did not disclose the total number of affected individuals.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In early 2018, Aflac Incorporated experienced a cybersecurity incident involving unauthorized access to the email accounts of its independent contractor sales agents. The breach occurred over an extended period, with attackers compromising these accounts between January 17 and April 2. During this nearly three-month window, threat actors gained access to sensitive client information stored within the agents' email systems. Aflac's internal investigation, concluded on April 25, confirmed that personal data belonging to policyholders had been exposed through these compromised accounts. The company did not publicly disclose the specific number of affected individuals or agents involved in the breach, nor did it reveal the exact method of initial email account compromise.

Cyber Incident Image

The exposed client information included highly sensitive personal identifiers such as full names, physical addresses, dates of birth, Aflac policy numbers, Social Security numbers, and bank account details. This combination of compromised data elements created significant risks for identity theft and financial fraud against impacted clients. Aflac issued a press release acknowledging the breach, though the notification was not immediately posted on the company's official website according to contemporaneous reports. The disclosure did not specify whether the company implemented additional security measures for agent email accounts following the incident or if law enforcement agencies were involved in investigating the breach. No information was provided regarding potential motives behind the attack or whether the exposed data was subsequently misused by the threat actors.

Sources
Sources available to members
1 source