Aflac Japan Data Breach Impacts 4.38 Million
Aflac Japan experienced a data breach where hackers accessed its policyholder portal multiple times between June 15 and June 25, 2026. Approximately 4.38 million customers and agents had personal information exposed, including names, addresses, phone numbers, dates of birth, gender, security information, and insurance account details. Additionally, insurance premium transfer account information of about 230,000 individuals was also exfiltrated. No credit card information was accessed. The breach was limited to Aflac Japan systems and did not affect Aflac's US business systems. The company took immediate containment actions and notified relevant authorities. The investigation is ongoing with third-party cybersecurity experts involved.
AI Analysis
Technical Summary
Between June 15 and June 25, 2026, attackers gained unauthorized access multiple times to Aflac Japan's policyholder portal, resulting in the exfiltration of personal data for approximately 4.38 million customers and agents. The compromised data includes personal identifiers and insurance-related information, with a subset of 230,000 individuals having their insurance premium transfer account information accessed. The breach was confined to Aflac Japan's systems and did not impact Aflac's US operations. Upon discovery, Aflac Japan suspended affected systems to contain the incident and engaged third-party experts to assist in the investigation. Notifications were sent to affected individuals and authorities. No credit card data was compromised. The breach's root cause and vulnerability exploited have not been disclosed.
Potential Impact
The breach exposed sensitive personal and insurance-related information of approximately 4.38 million individuals, potentially increasing the risk of identity theft, fraud, and targeted phishing attacks. The exposure of insurance premium transfer account information for around 230,000 people could lead to financial fraud attempts. Service disruptions affected at least five Aflac Japan services, with no estimated restoration timeline provided. The breach did not impact Aflac's US business systems. No credit card information was compromised, limiting the scope of financial data exposure.
Mitigation Recommendations
Aflac Japan has taken immediate containment measures by suspending affected systems to prevent further unauthorized access. The company is conducting an ongoing investigation supported by third-party cybersecurity experts and has notified relevant authorities. Affected customers will receive notification letters detailing the specific information exposed. No official patch or remediation details have been provided. Organizations should monitor communications from Aflac Japan for updates and follow any guidance issued. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Aflac Japan Data Breach Impacts 4.38 Million
Description
Aflac Japan experienced a data breach where hackers accessed its policyholder portal multiple times between June 15 and June 25, 2026. Approximately 4.38 million customers and agents had personal information exposed, including names, addresses, phone numbers, dates of birth, gender, security information, and insurance account details. Additionally, insurance premium transfer account information of about 230,000 individuals was also exfiltrated. No credit card information was accessed. The breach was limited to Aflac Japan systems and did not affect Aflac's US business systems. The company took immediate containment actions and notified relevant authorities. The investigation is ongoing with third-party cybersecurity experts involved.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Between June 15 and June 25, 2026, attackers gained unauthorized access multiple times to Aflac Japan's policyholder portal, resulting in the exfiltration of personal data for approximately 4.38 million customers and agents. The compromised data includes personal identifiers and insurance-related information, with a subset of 230,000 individuals having their insurance premium transfer account information accessed. The breach was confined to Aflac Japan's systems and did not impact Aflac's US operations. Upon discovery, Aflac Japan suspended affected systems to contain the incident and engaged third-party experts to assist in the investigation. Notifications were sent to affected individuals and authorities. No credit card data was compromised. The breach's root cause and vulnerability exploited have not been disclosed.
Potential Impact
The breach exposed sensitive personal and insurance-related information of approximately 4.38 million individuals, potentially increasing the risk of identity theft, fraud, and targeted phishing attacks. The exposure of insurance premium transfer account information for around 230,000 people could lead to financial fraud attempts. Service disruptions affected at least five Aflac Japan services, with no estimated restoration timeline provided. The breach did not impact Aflac's US business systems. No credit card information was compromised, limiting the scope of financial data exposure.
Mitigation Recommendations
Aflac Japan has taken immediate containment measures by suspending affected systems to prevent further unauthorized access. The company is conducting an ongoing investigation supported by third-party cybersecurity experts and has notified relevant authorities. Affected customers will receive notification letters detailing the specific information exposed. No official patch or remediation details have been provided. Organizations should monitor communications from Aflac Japan for updates and follow any guidance issued. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/aflac-japan-data-breach-impacts-4-38-million/","fetched":true,"fetchedAt":"2026-06-30T13:06:23.485Z","wordCount":970}
Threat ID: 6a43bf4f27e9c79719cf63e4
Added to database: 06/30/2026, 13:06:23 UTC
Last enriched: 06/30/2026, 13:06:42 UTC
Last updated: 06/30/2026, 13:06:42 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.