# Aflac Discloses Second Data Breach in 12 Months as Attackers Target Japan Subsidiary
American insurance giant Aflac has confirmed a significant data breach affecting its Japan subsidiary, marking the second major security incident at the Fortune 500 company within a year. According to an SEC filing and press release on June 30, 2026, unauthorized threat actors gained access to Aflac Japan's systems between June 15 and June 25, 2026, compromising personal information, bank account details, and policy coverage data.
## The Threat
Threat actors successfully infiltrated Aflac Japan's network over an 11-day period before the company detected the unauthorized access on June 25. Upon discovery, Aflac immediately suspended certain systems to contain the breach and prevent further intrusion. The attackers extracted sensitive data including:
The company has notified the Japan Financial Services Agency and other relevant Japanese authorities, and intends to provide appropriate notifications to affected individuals. Aflac emphasized that the incident is geographically isolated to its Japan operations, with no evidence that the company's U.S. business systems were compromised in this particular attack.
## Background and Context
Aflac occupies a prominent position in the global insurance landscape. As the largest supplemental insurance provider in the United States, the company serves millions of customers across the U.S. and Japan, making it a high-value target for financially motivated threat actors. The company's dual geographic footprint and access to sensitive financial and personal data make it an attractive target.
This June 2026 breach is not Aflac's first security incident. One year prior, in June 2025, Aflac disclosed another major data breach as part of a broader campaign targeting multiple insurance companies across the United States. In that incident, attackers potentially accessed documents containing sensitive information about customers, beneficiaries, employees, agents, and other individuals. While Aflac did not formally attribute last year's breach, security researchers noted that the incident exhibited hallmarks consistent with Scattered Spider (also tracked as 0ktapus, UNC3944, Scatter Swine, Starfraud, and Muddled Libra).
The fact that Aflac has suffered two material breaches within 12 months raises critical questions about the company's security posture and whether it faces sustained, targeted attacks from the same threat actor.
## The Scattered Spider Connection
The timing and profile of these incidents warrant close examination of Scattered Spider's broader campaign against the insurance sector. Scattered Spider is a financially motivated threat group known for its sophisticated social engineering capabilities and partnerships with ransomware-as-a-service (RaaS) operators. Their confirmed victims include:
| Target | Year | Method |
|--------|------|--------|
| MGM Resorts | 2023 | Social engineering / credential compromise |
| DoorDash | 2024 | Account takeover |
| Caesars Entertainment | 2023 | Credential theft |
| Coinbase | 2021 | SIM swapping / MFA bypass |
| Erie Insurance | 2025 | Account compromise |
| Philadelphia Insurance Companies (PHLY) | 2025 | Credential theft |
The 2025 wave of insurance industry attacks involved multiple companies being compromised in coordinated fashion, suggesting Scattered Spider was systematically targeting the sector. Scattered Spider has also partnered with ransomware operations including Qilin, RansomHub, and DragonForce, amplifying the potential impact of their breaches beyond data theft to include extortion and operational disruption.
## Technical Details
The June 2026 breach timeline suggests a deliberate, patient approach:
The relatively short detection window (11 days) is noteworthy. Major insurance carriers typically deploy advanced monitoring and intrusion detection systems, yet this breach persisted for over a week before discovery. This suggests either sophisticated evasion techniques by the attackers or detection gaps in Aflac Japan's monitoring infrastructure.
Aflac has engaged external cybersecurity experts to investigate the full scope of the breach, and the investigation remains ongoing. The company has suspended certain systems as a containment measure, though it notes continued service to policyholders throughout the incident response.
## Implications for Organizations
This incident carries several implications for the broader business community:
For Insurance Providers: The breach underscores persistent targeting of the insurance sector. Insurance companies hold valuable data (financial information, personal details, beneficiary records) that makes them lucrative targets. The sector appears to face sustained, organized threat activity.
For Multinational Corporations: The geographic separation between Aflac's U.S. and Japan operations did not prevent the Japan subsidiary from being compromised. This suggests that threat actors are conducting sophisticated targeting of specific subsidiaries or regions, potentially to avoid triggering the largest/most-monitored systems.
For Policyholders and Customers: Affected individuals face potential identity theft, fraud, and financial exploitation given the theft of personal information and bank account details. The compromise of policy information could also enable social engineering attacks or targeted phishing campaigns.
For Regulators: The incident highlights the need for ongoing regulatory scrutiny of critical financial services infrastructure and cross-border data protection standards.
## Recommendations
Organizations in the financial services and insurance sectors should consider implementing the following measures:
## HackWire Analysis
The second Aflac breach in 12 months reveals a critical pattern: the insurance industry faces sustained, organized targeting from sophisticated threat groups that are learning and adapting. This is not a one-off incident but part of a coordinated campaign against high-value targets in the financial services sector.
What makes this particularly concerning is the shift in targeting: last year's Aflac breach focused on U.S. operations, while this year's attack targeted the Japan subsidiary specifically. This suggests threat actors are not conducting indiscriminate attacks but are executing a deliberate, multi-phase strategy against Aflac's global footprint. They may be testing defenses, probing for the most valuable data repositories, or distributing attacks across jurisdictions to complicate investigation and enforcement.
The 11-day dwell time before detection is alarming. Aflac likely invests heavily in security infrastructure—yet attackers maintained access for over a week while exfiltrating data. This suggests either that Scattered Spider's social engineering capabilities are sophisticated enough to bypass even advanced monitoring, or that certain business units lack the visibility and alerting capabilities of core systems. For defenders in similar organizations, the implication is clear: assume your perimeter is breached, and focus relentlessly on detecting and stopping attackers during their dwell time before data exfiltration begins.
The partnership between Scattered Spider and ransomware gangs also warrants attention. While this particular breach has not (yet) resulted in a ransom demand or public naming, the fact that Aflac has not ruled out extortion suggests the possibility remains. Organizations should prepare for the worst-case scenario: that attackers have both data and encryption capabilities, and may demand payment for silence and safe deletion.
— HackWire Editorial
---
## Related Coverage