CSIDB logo
Incident

Aflac Life Insurance Japan

Incident posture

Attack window
Jun 2026
Location
Japan
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-20 00:35

Linked entities

Victim
Aflac Life Insurance Japan
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Aflac Life Insurance Japan disclosed a data breach after an unauthorized third party accessed certain systems, compromising personal and financial information of approximately 4.38 million customers, including policy and coverage details, bank account data, and premium transfer account information for about 230,000 individuals. The breach disrupted several services such as medical check‑up reservations and AI support concierge, while the company stated that its U.S. systems were unaffected and that no misuse of the exposed data has been confirmed.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 15, 2026, unauthorized actors gained access to certain systems of Aflac Life Insurance Japan, and the intrusion persisted until June 25 when the subsidiary detected the breach and filed a report with the U.S. Securities and Exchange Commission on June 30. The company stated that an unauthorized third party accessed policy and coverage details, personal information, and bank account information stored on the affected systems. According to the disclosure, the incident impacted the firm’s customer portal and resulted in the compromise of personal and financial data for approximately 4.4 million customers, including premium payment account details for around 230,000 individuals. Aflac Japan noted that this was not the first time its systems had been targeted, referencing a 2023 breach involving a third‑party U.S. contractor and a prior incident a year earlier that was described in reports as part of a broader campaign against U.S. insurers attributed to the Scattered Spider group.

The exposed information varies by individual but includes names, addresses, phone numbers, dates of birth, gender, security information, and insurance account details, with no evidence that credit card data was accessed. Aflac Japan indicated that roughly 230,000 customers had their insurance premium transfer account information exfiltrated. The breach disrupted at least five services, including reservations for medical check‑ups and health screenings and the AI support concierge, while the company maintained that inquiries and claims processing continued through its call center and other channels. Each affected customer will receive a notification letter specifying the exact data elements that were compromised, and the company has notified the relevant regulatory authorities about the incident.

In response to the discovery, Aflac Japan promptly suspended the affected systems to prevent further intrusion and stated that some systems remain shut down as a precautionary measure. The firm said it is working with third‑party cybersecurity experts to conduct an ongoing investigation into the attack’s origin and extent. Although the company confirmed that no misuse of the stolen information has been identified to date, it acknowledged that the full scope and potential ultimate impact of the breach are still unknown. Aflac Japan reiterated that the intrusion was confined to its Japanese operations and that its U.S.‑based systems were not accessed by the unauthorized party.

Sources

Sources available to members: 2 sources.

CSIDB