Aflac says hackers breached its Japan subsidiary and stole customer personal and bank account data

Aflac disclosed that attackers broke into systems at Aflac Japan and stole sensitive customer information. The company said the unauthorized access occurred between June 15 and June 25, 2026, and affected files include policy and coverage details, personal information, and bank account information. Aflac said the incident is limited to its Japan subsidiary, that some systems were suspended for containment, and that the full scope is still under investigation.
Why it matters: This affects insurance customers whose personal and financial data may now be exposed to fraud or account abuse. Affected users should watch for breach notifications, monitor financial accounts, and be alert for phishing or impersonation attempts, while defenders in insurance should review whether this reflects broader targeting of the sector.

Sources

Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches
2026.07.01 95% relevant
This is the same Aflac Japan breach and adds scale and operational detail, including that about 4.38 million policyholders were affected, around 230,000 customers had premium payment account data exposed, and Aflac suspended parts of affected systems while continuing claims and support through other channels.
Aflac Japan Data Breach Impacts 4.38 Million
Ionut Arghire 2026.06.30 98% relevant
This source updates the same Aflac Japan breach with a specific impact figure of 4.38 million affected customers and agents, a timeline showing repeated access from June 15 to June 25, confirmation that the policyholder portal was the source of exfiltration, and added detail that about 230,000 people had insurance premium transfer account information stolen.
Insurance giant Aflac discloses data breach after subsidiary hack
Sergiu Gatlan 2026.06.30 100% relevant
This article appears to be the first clear report of Aflac's June 2026 disclosure that Aflac Japan was breached and customer personal and bank account data was accessed.
← Back to all stories