# Aflac Discloses Second Data Breach in 12 Months as Attackers Target Japan Subsidiary


American insurance giant Aflac has confirmed a significant data breach affecting its Japan subsidiary, marking the second major security incident at the Fortune 500 company within a year. According to an SEC filing and press release on June 30, 2026, unauthorized threat actors gained access to Aflac Japan's systems between June 15 and June 25, 2026, compromising personal information, bank account details, and policy coverage data.


## The Threat


Threat actors successfully infiltrated Aflac Japan's network over an 11-day period before the company detected the unauthorized access on June 25. Upon discovery, Aflac immediately suspended certain systems to contain the breach and prevent further intrusion. The attackers extracted sensitive data including:


  • Personal information of customers and policyholders
  • Bank account details associated with customer accounts
  • Policy and coverage information detailing insurance policies and coverage specifics
  • Beneficiary and employee records

  • The company has notified the Japan Financial Services Agency and other relevant Japanese authorities, and intends to provide appropriate notifications to affected individuals. Aflac emphasized that the incident is geographically isolated to its Japan operations, with no evidence that the company's U.S. business systems were compromised in this particular attack.


    ## Background and Context


    Aflac occupies a prominent position in the global insurance landscape. As the largest supplemental insurance provider in the United States, the company serves millions of customers across the U.S. and Japan, making it a high-value target for financially motivated threat actors. The company's dual geographic footprint and access to sensitive financial and personal data make it an attractive target.


    This June 2026 breach is not Aflac's first security incident. One year prior, in June 2025, Aflac disclosed another major data breach as part of a broader campaign targeting multiple insurance companies across the United States. In that incident, attackers potentially accessed documents containing sensitive information about customers, beneficiaries, employees, agents, and other individuals. While Aflac did not formally attribute last year's breach, security researchers noted that the incident exhibited hallmarks consistent with Scattered Spider (also tracked as 0ktapus, UNC3944, Scatter Swine, Starfraud, and Muddled Libra).


    The fact that Aflac has suffered two material breaches within 12 months raises critical questions about the company's security posture and whether it faces sustained, targeted attacks from the same threat actor.


    ## The Scattered Spider Connection


    The timing and profile of these incidents warrant close examination of Scattered Spider's broader campaign against the insurance sector. Scattered Spider is a financially motivated threat group known for its sophisticated social engineering capabilities and partnerships with ransomware-as-a-service (RaaS) operators. Their confirmed victims include:


    | Target | Year | Method |

    |--------|------|--------|

    | MGM Resorts | 2023 | Social engineering / credential compromise |

    | DoorDash | 2024 | Account takeover |

    | Caesars Entertainment | 2023 | Credential theft |

    | Coinbase | 2021 | SIM swapping / MFA bypass |

    | Erie Insurance | 2025 | Account compromise |

    | Philadelphia Insurance Companies (PHLY) | 2025 | Credential theft |


    The 2025 wave of insurance industry attacks involved multiple companies being compromised in coordinated fashion, suggesting Scattered Spider was systematically targeting the sector. Scattered Spider has also partnered with ransomware operations including Qilin, RansomHub, and DragonForce, amplifying the potential impact of their breaches beyond data theft to include extortion and operational disruption.


    ## Technical Details


    The June 2026 breach timeline suggests a deliberate, patient approach:


  • June 15: Attackers gain initial access to Aflac Japan systems
  • June 15-25: 11-day window of unauthorized system access and data extraction
  • June 25: Aflac Japan discovers the intrusion
  • June 25-30: Investigation and notification of authorities
  • June 30: Public disclosure via SEC filing

  • The relatively short detection window (11 days) is noteworthy. Major insurance carriers typically deploy advanced monitoring and intrusion detection systems, yet this breach persisted for over a week before discovery. This suggests either sophisticated evasion techniques by the attackers or detection gaps in Aflac Japan's monitoring infrastructure.


    Aflac has engaged external cybersecurity experts to investigate the full scope of the breach, and the investigation remains ongoing. The company has suspended certain systems as a containment measure, though it notes continued service to policyholders throughout the incident response.


    ## Implications for Organizations


    This incident carries several implications for the broader business community:


    For Insurance Providers: The breach underscores persistent targeting of the insurance sector. Insurance companies hold valuable data (financial information, personal details, beneficiary records) that makes them lucrative targets. The sector appears to face sustained, organized threat activity.


    For Multinational Corporations: The geographic separation between Aflac's U.S. and Japan operations did not prevent the Japan subsidiary from being compromised. This suggests that threat actors are conducting sophisticated targeting of specific subsidiaries or regions, potentially to avoid triggering the largest/most-monitored systems.


    For Policyholders and Customers: Affected individuals face potential identity theft, fraud, and financial exploitation given the theft of personal information and bank account details. The compromise of policy information could also enable social engineering attacks or targeted phishing campaigns.


    For Regulators: The incident highlights the need for ongoing regulatory scrutiny of critical financial services infrastructure and cross-border data protection standards.


    ## Recommendations


    Organizations in the financial services and insurance sectors should consider implementing the following measures:


  • Credential security: Deploy hardware security keys and FIDO2 authentication to prevent SIM swapping and MFA bypass techniques favored by Scattered Spider
  • Network segmentation: Isolate critical systems and geographic business units to limit lateral movement and breach scope
  • Enhanced monitoring: Deploy behavioral analytics and user activity monitoring to detect unauthorized access patterns faster than the 11-day window seen here
  • Threat intelligence sharing: Participate in industry information sharing groups to track Scattered Spider's tactics and targeting patterns
  • Incident response planning: Develop and test incident response procedures specific to ransomware and data theft scenarios
  • Third-party risk management: Assess and monitor security controls at all subsidiaries and business units, not just primary operations

  • ## HackWire Analysis


    The second Aflac breach in 12 months reveals a critical pattern: the insurance industry faces sustained, organized targeting from sophisticated threat groups that are learning and adapting. This is not a one-off incident but part of a coordinated campaign against high-value targets in the financial services sector.


    What makes this particularly concerning is the shift in targeting: last year's Aflac breach focused on U.S. operations, while this year's attack targeted the Japan subsidiary specifically. This suggests threat actors are not conducting indiscriminate attacks but are executing a deliberate, multi-phase strategy against Aflac's global footprint. They may be testing defenses, probing for the most valuable data repositories, or distributing attacks across jurisdictions to complicate investigation and enforcement.


    The 11-day dwell time before detection is alarming. Aflac likely invests heavily in security infrastructure—yet attackers maintained access for over a week while exfiltrating data. This suggests either that Scattered Spider's social engineering capabilities are sophisticated enough to bypass even advanced monitoring, or that certain business units lack the visibility and alerting capabilities of core systems. For defenders in similar organizations, the implication is clear: assume your perimeter is breached, and focus relentlessly on detecting and stopping attackers during their dwell time before data exfiltration begins.


    The partnership between Scattered Spider and ransomware gangs also warrants attention. While this particular breach has not (yet) resulted in a ransom demand or public naming, the fact that Aflac has not ruled out extortion suggests the possibility remains. Organizations should prepare for the worst-case scenario: that attackers have both data and encryption capabilities, and may demand payment for silence and safe deletion.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)