Back to Exposure Report
Insurance June 30, 2026 Japan

Aflac Japan

Attackers maintained persistent access for 10 days before detection. 4.38 million policyholder records exposed. Second major Aflac breach in 12 months.

NamesAddressesPhone numbersDates of birthGenderSecurity detailsInsurance account informationPremium payment accounts (230,000)
1

What happened?

Between June 15 and June 25, 2026, hackers gained access to Aflac Japan's policyholder portal and repeatedly accessed customer information. Detection came on June 25 when a "high load status on the information processing unit (CPU)" triggered an investigation.

Ten days of persistent access. The attackers weren't detected by security controls—they were caught because system performance degraded. The breach wasn't found; it was stumbled upon during infrastructure monitoring.

2

What data was actually inside?

4.38 million customer records containing names, addresses, phone numbers, dates of birth, gender, security details, and insurance account information. For approximately 230,000 customers, premium payment account details were also compromised.

Insurance account information reveals policy types, coverage levels, and claims history. Combined with payment account data for 230,000 customers, attackers have both identity information and financial access details. The data enables targeted fraud across insurance and banking domains.

3

Who gets hurt and how?

4.38 million Aflac Japan policyholders whose personal information is now compromised. The 230,000 customers with exposed payment data face direct financial fraud risk. Everyone in the breach faces identity theft and targeted phishing using their real policy details.

Insurance policyholders are valuable targets. They have existing financial relationships. They expect communications from their insurer. Phishing attacks that reference real policy numbers and coverage details are highly convincing. The legitimate business relationship becomes the attack vector.

4

What did they think they were doing right?

Aflac is a Fortune 500 company with substantial security resources. Japan's insurance regulations require cybersecurity measures. The company quickly contained the breach after detection by suspending affected systems.

But detection took 10 days. Repeated access to customer information across a week and a half before anyone noticed. The containment was fast once discovered; the discovery was slow. Rapid response requires rapid detection, and that detection came from infrastructure monitoring, not security monitoring.

5

What did they not know about their own data?

The policyholder portal contained 4.38 million customer records. How many of those were active policyholders versus historical records? Insurance relationships span years or decades. Customer data accumulates across policy lifecycles, renewals, and cancellations.

This is Aflac's second major breach in roughly a year—June 2025 affected U.S. operations with 22 million exposed. The pattern suggests systemic data management challenges across geographic operations. Different subsidiaries, similar outcomes.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

Aflac filed an 8-K with the SEC disclosing the breach. Japanese regulators—Financial Services Agency and Personal Information Protection Commission—have notification requirements. 4.38 million customers must be informed of their exposure.

No threat actor has claimed the attack. No misuse of data has been confirmed yet. But the data is out. The 10-day access window provided ample time for systematic extraction. What happens next depends on who has the data and what they choose to do with it.

7

What would have changed the outcome?

Anomaly detection on data access patterns—identifying systematic enumeration before 10 days passed.

Customer data access should have patterns. Normal business operations don't involve repeatedly accessing 4.38 million records. Security monitoring that establishes baselines and alerts on deviations would have detected the breach in hours rather than days. The organizations that catch breaches early are the ones monitoring not just for intrusion, but for abnormal data access after intrusion.

Aflac Japan found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.