US supplemental insurance giant Aflac Incorporated has confirmed that a June 2025 intrusion into its American network exposed personal and health records, including Social Security numbers, for roughly 22.6 million individuals worldwide. The Columbus, Georgia company first disclosed suspicious activity on June 20, 2025, describing it as part of a broader cybercrime campaign against the insurance industry (ABC7 mirror), and later put the global figure at approximately 22.65 million in a December 19, 2025 update (Kayne McGladrey). Federal HIPAA reporting tells a smaller story: the HHS OCR breach portal lists 13,924,906 affected individuals, a US-only subset. Fourteen months on, the incident is in active litigation after a federal judge largely refused to dismiss the consolidated class action, and Aflac's Japanese subsidiary has since suffered a second, separate compromise affecting millions more.
What Happened
The accounts that carry the most detail place the initial compromise on June 12, 2025, when attackers used social engineering against Aflac personnel to talk their way onto the US network (Kayne McGladrey). Aflac says the intrusion was stopped within hours. There was no ransomware, no file encryption, and no operational disruption; the company stated at the time that it could still underwrite policies and process claims as usual.
Public disclosure came eight days later, on June 20, 2025, at which point Aflac said it was in the early stages of review and could not yet determine how many people were affected. That review did not finish until December 4, 2025. Notification letters began going out on December 23, more than six months after the intrusion, with the 22.65 million global figure surfacing in a December 19 company update.
One point of genuine conflict in the sourcing: TECHSHOTS attributes the 22.6 million exposure to "a vulnerability at a third-party service provider." No other source in this set supports a supply chain vector for the US breach, and the more detailed accounts describe direct social engineering of Aflac staff. Treat the third-party framing as unconfirmed.
Separately, and roughly a year later, Aflac Life Insurance Japan Ltd. disclosed on June 30, 2026 that an unauthorized third party had accessed its systems. Aflac Japan discovered the access on June 25, 2026 and shut down the affected platforms the same day. The intrusion window is reported as June 15 to June 25, 2026, a ten-day dwell time, based on the company's SEC Form 8-K (Morning Overview, Data Protection Center). Aflac Japan's later report to Japan's Financial Services Agency, however, states that the investigation confirmed the first information leak occurred on June 10 (IBTimes JP), which would push the timeline five days earlier than the 8-K window. Accounts differ; the FSA filing is the later and more investigated of the two.
What Was Taken
For the US incident, the exposed file types were consistently described across sources: claims information, health information, Social Security numbers, and other personal data belonging to customers, beneficiaries, employees, agents, and other individuals in Aflac's US business (ABC7 mirror). The more granular breakdown adds dates of birth, driver's license numbers, government-issued IDs, and medical and health insurance information (Kayne McGladrey). That combination is close to a complete identity package and is not rotatable.
Headline counts for the US-linked breach:
- 22.6 million individuals (TECHSHOTS)
- ~22.65 million individuals globally, per Aflac's own December 19, 2025 update (Kayne McGladrey)
- 13,924,906 individuals on the HHS OCR HIPAA portal, capturing only the US HIPAA-covered population
The roughly 8.7 million gap between the OCR figure and Aflac's global tally is not a discrepancy so much as a reporting boundary: a large share of the exposure fell outside US regulatory reporting entirely.
For the 2026 Aflac Japan breach, counts also vary by source and by what is being counted:
- 4.38 million customers, per the SEC Form 8-K as reported by tech-insider.org, Data Protection Center, Insurtech Curated, and Morning Overview
- ~4.4 million customers plus approximately 40,000 insurance agencies, per Aflac Japan's July 31, 2026 report to the Financial Services Agency (IBTimes JP)
The Japanese data set included policyholder names, dates of birth, gender, addresses and telephone numbers; insured persons' names, dates of birth and gender; beneficiary names; policy numbers; coverage details; secondary contact information; and premium payment bank account details covering financial institution, branch, account type, account number and account holder name (IBTimes JP).
There is a real conflict on the bank data. Morning Overview reports, under the headline figure, that hackers "stole bank details on 4.38 million" customers. IBTimes JP, citing the FSA report, states that bank account information was involved for approximately 220,000 customers, with the remainder of the 4.4 million exposed through policy and contact data. Other coverage hedges, saying bank account data was taken "for some customers" (tech-insider.org). The 220,000 figure comes from the regulator-facing filing and is the more specific claim; the 4.38 million bank-data framing appears to conflate total affected individuals with the financial-data subset. Do not repeat the higher number as settled.
Why It Matters
Two things separate this from routine breach volume. The first is the detection-to-notification gap. Aflac contained the US intrusion within hours, which is a genuinely strong mean-time-to-respond. But it took until December 4, 2025 to finish determining whose data was in the exfiltrated files, and until December 23 to start telling them. For six months, 22.6 million people whose Social Security numbers and medical records were in criminal hands had no idea. Fast containment limited the damage; slow data review erased much of that advantage from the victim's perspective.
The second is the repeat pattern across the corporate family. Aflac Japan was compromised in June 2026 through a customer-facing policyholder portal, roughly a year after the US incident and after what should have been a group-wide hardening cycle. Commentary across several outlets frames this as evidence that remediation was not synchronized across international subsidiaries, leaving regional gaps (Data Protection Center, Insurtech Curated). That analysis is opinion rather than confirmed finding, but the sequence of events is not in dispute. If your organization's incident response ends at the boundary of the affected legal entity, you have built exactly this failure mode.
Third, the legal exposure is now concrete. On August 12, 2026, Judge Clay D. Land of the US District Court for the Middle District of Georgia largely denied Aflac's motion to dismiss the consolidated class action arising from the June 2025 breach (Kayne McGladrey). Negligence survived on the theory that Aflac owed a duty to protect the data and plausibly breached it through inadequate security controls. Negligence per se survived on the theory that federal statutes can define the applicable standard of care. The case proceeds to discovery, where internal security decisions become evidence.
The Attack Technique
For the US breach, the reported vector is social engineering against people, not exploitation of a software flaw. Attackers contacted Aflac on June 12, 2025 and manipulated their way into network access. Aflac characterized the incident as part of a coordinated cybercrime campaign targeting the insurance sector broadly. None of the available sources names a specific threat group, and no attribution should be inferred.
The Japan intrusion targeted infrastructure rather than staff. The compromised systems were the "Aflac Yorisou Net" customer-only policyholder portal and an "online consultation" system (IBTimes JP, tech-insider.org). Attackers held access for roughly ten days, and one analysis argues that the volume of sensitive financial data reached in that short window points to a targeted operation with prior knowledge of where the data lived, rather than opportunistic scanning (Morning Overview). That is inference, not a confirmed finding. Aflac Japan's internal and external investigations found no comparable leakage in systems beyond the two affected platforms, and the company has said no misuse of the data has been confirmed to date. Aflac's 8-K states the 2026 incident was limited to Japan and did not affect US operations. Four Aflac Japan executives are returning part of one month's pay.
What Organizations Should Do
- Harden the help desk against social engineering. The US breach started with a conversation, not an exploit. Require out-of-band verification for password resets, MFA re-enrollment, and privileged access requests. Script the refusal path so support staff are not making judgment calls under pressure, and test it with authorized red team calls.
- Cut your data review time, not just your containment time. Aflac contained in hours and identified victims in six months. Pre-build the capability to answer "whose records were in these files" quickly: maintain data inventories, tag sensitive fields at rest, and retain the file-level logging that makes scoping an exfiltration a query rather than a project.
- Treat customer-facing portals as tier-one attack surface. Both Aflac Japan systems were policyholder-facing web platforms. Rate-limit and monitor authenticated enumeration, alert on anomalous bulk record retrieval per session, and apply the same detection engineering to the portal that you apply to the corporate network.
- Propagate remediation across every subsidiary, not just the breached one. After any group incident, run the same control audit in every regional entity and confirm it with evidence, not attestation. A hardening program that stops at a national border leaves the attacker a supported alternate route.
- Segment and instrument access to financial and identity data. Ten days of access should not reach millions of bank account records. Enforce least privilege on the data stores holding account numbers, SSNs and health information, and set volumetric alerting so mass reads page a human on the first thousand records, not the millionth.
- Assume the litigation record starts now. With negligence and negligence per se both surviving dismissal in this case, security control decisions are discoverable and judged against federal statutory standards. Document control rationale, exceptions, and risk acceptances contemporaneously, on the assumption they will be read aloud by opposing counsel.
Sources: TECHSHOTS Aflac Data Breach Exposes Personal and Health Re... | Aflac Japan says 4.4 million customers hit by data leak IBTimes JP | Aflac Data Breach: Japan Arm Hit for 4.38M in 2026 | Aflac Japan Data Breach Exposes 4.38 Million Customers Data Protec... | Aflac Japan Data Breach Impacts 4.38 Million Customers Insurtech C... | Aflac finds suspicious activity on US network that may impact Socia... | Aflac says hackers stole bank details on 4.38 million of its custom... | Aflac Breach Lawsuit Moves Forward After Ruling