Between 15 June and 25 June 2026, an unauthorised third party accessed the systems of Aflac Life Insurance Japan Ltd. (Aflac Japan), the Japanese subsidiary of Aflac Incorporated, the Fortune 500 company and largest supplemental insurance provider in the United States, serving millions of customers across the US and Japan. Aflac Japan discovered the intrusion on 25 June and disclosed it in a filing with the US Securities and Exchange Commission on 30 June. The company has not said how the intruder first got in.
What Aflac Japan has said is that the attacker did not need to breach the perimeter once. Its own account describes multiple instances of unauthorised access to the policyholder portal across the ten day window, each one an opportunity to pull data out rather than a single smash and grab. By the time the company suspended the affected systems, the intruder had reached policy and coverage details, personal information, and premium transfer account details for roughly 230,000 individuals, alongside names, addresses, phone numbers, dates of birth and security information covering a broader population Aflac now estimates at 4.38 million customers and agents. No credit card data was taken, the company said, but the bank account numbers used to collect premium payments were.
Aflac Japan disrupted at least five customer facing services while it investigated, and could not say when they would be restored. Japan's Financial Services Agency issued the insurer a business improvement order under the Insurance Business Act on 1 July, a formal step that requires Aflac to report back on the state of its controls. This is not the company's first time in this position. A year earlier, Aflac disclosed a separate breach of its US systems amid a wider wave of attacks on insurers, an incident that reportedly carried the hallmarks of Scattered Spider, the group also linked to intrusions at Erie Insurance and Philadelphia Insurance Companies. Whether the same actor returned for the Japan breach has not been confirmed. What is confirmed is the pattern: a major insurer, breached twice within two years, through channels that ultimately let someone walk out with bulk customer records each time.
The defences that failed here were not weak by conventional standards. Aflac is a Fortune 500 company with a dedicated cybersecurity function, external incident response support brought in within days, and a regulatory relationship mature enough to notify Japanese authorities almost immediately. None of that changed what happened during the ten days the portal remained accessible. A policyholder portal is built to serve verified account holders one record at a time. It has no mechanism to distinguish a legitimate high volume export from an unauthorised one once a session is open, and a detection tool that flags the anomaly after the fact cannot undo a bulk pull of bank account numbers that has already completed.
A bulk export from a policyholder portal, whether it covers 230,000 premium transfer accounts or 4.38 million customer profiles, is an execution event. Before a data extraction of that scale can run, regardless of whether the session behind it is legitimate, stolen, or replayed, a confirmation request goes to Aflac's named data protection authority on their registered device. No confirmation, no export. The control does not care whether the credential making the request passed every authentication check in the stack. It cares whether a specific, identified human authorised that specific action at that specific moment.
An intruder holding a valid session inside a policyholder portal, however many times they return to it and over however many days, cannot produce a biometric confirmation from a named authority on a device they do not hold. The execution boundary holds regardless of how many times the attacker comes back for more.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Arghire, I. 2026. Aflac Japan Data Breach Impacts 4.38 Million. SecurityWeek, 30 June 2026.
2. Gatlan, S. 2026. Insurance giant Aflac discloses data breach after subsidiary hack. BleepingComputer, 30 June 2026.
3. Aflac Incorporated. 2026. Form 8-K filing, item 8.01. US Securities and Exchange Commission, 30 June 2026.
4. Nikkei Asia. 2026. Aflac Japan reports breach on 4.38 million customers, includes bank details. Nikkei Asia, 1 July 2026.
Back to Blog
Case Studies·4 min read
15 to 25 June 2026. Ten days inside Aflac Japan's portal. 4.38 million records gone.
By GoFirm
