Cyber Incident Victim: Aflac Life Insurance Japan
Timeline
Summary
Aflac Japan disclosed that an unauthorized third party accessed its systems over a ten‑day window before the breach was detected, leading to the exposure of personal and financial data of approximately 4.38 million customers and agents. The compromised information includes names, addresses, phone numbers, dates of birth, gender, security details and insurance account information, with premium transfer account data for about 230,000 individuals also taken; no credit card data was accessed. The incident is confined to the Japanese subsidiary’s systems, prompting the temporary shutdown of services such as medical check‑up reservations, health screenings and the AI support concierge while call‑center operations continue. Investigations are ongoing with third‑party experts, authorities have been notified, and the company states that no misuse of the exposed data has been confirmed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On June 15, 2026, unauthorized actors gained access to certain systems of Aflac Life Insurance Japan and maintained access through multiple entries until June 25, when the intrusion was detected. The breach was disclosed in an SEC filing on June 30, 2026, which noted that the compromised systems were confined to Aflac Japan’s environment and did not affect the company’s United States operations. Investigators determined that the accessed files contained policy and coverage details, personal information, and bank account information. According to the company’s disclosures, approximately 4.38 million customers and agents had their personal data exposed, including names, addresses, phone numbers, dates of birth, gender, security information, and insurance account details. Additionally, the premium transfer account information of roughly 230,000 individuals was exfiltrated, while no credit card data was accessed. The nature of the exposed information varies from one individual to another, and each affected person will receive a notification letter outlining the specific data involved. The breach also disrupted the customer portal, leading to the temporary shutdown of some systems to prevent further spread of the intrusion. As a result, services such as reservations for medical check-ups, health screenings, and the AI support concierge were rendered unavailable, with at least five distinct services reported as impacted. Aflac Japan stated that inquiries and procedures, including claims for insurance benefits and other payments, continued to be handled through its call center and other alternative channels while the investigation proceeded.

In response to the detected intrusion, Aflac Japan immediately implemented containment measures, including the suspension of certain affected systems, and engaged third‑party cybersecurity experts to support the ongoing investigation. The company notified the relevant authorities and affirmed that, to date, no misuse of the information related to this incident has been confirmed. Although the full scope and potential ultimate impact remain under review, Aflac Japan has indicated that it cannot yet estimate when the disrupted services will be fully restored. The incident follows earlier security events involving the subsidiary, notably a 2023 breach in which customer details were stolen and offered for sale after a third‑party United States contractor was compromised, and a separate data breach that occurred approximately one year prior to the 2026 event. Throughout the response, Aflac Japan has maintained communication with affected individuals through the promised notification letters and has kept its call center operational to handle customer inquiries and claims.
