Insurance giant Aflac has disclosed a major data breach impacting approximately 4.38 million customers and agents of its Japanese subsidiary. The intrusion, which ran undetected between June 15 and June 25, 2026, saw an unauthorized third party access the policyholder portal and exfiltrate names, addresses, phone numbers, dates of birth, gender, security questions, and insurance account details. Roughly 230,000 individuals also had bank account information tied to premium transfers stolen.
Aflac Japan says the breach is confined to its Japanese systems and does not affect U.S. operations. The company has suspended affected systems, engaged third-party forensics, and notified the Japan Financial Services Agency. No credit card data was accessed, and no confirmed misuse has been reported — though several customer services remain offline while recovery continues.
Source
Infosecurity Magazine · Security Boulevard · SecurityWeek
Commentary
A ten-day dwell time on a customer-facing portal exposing 4.38 million records is a rough look for any financial services company, let alone one of the largest insurers in Japan. The silver lining — no credit card data and no evidence of misuse yet — is thin comfort when the stolen dataset includes bank account numbers and enough PII to fuel targeted phishing campaigns for months.
This breach underscores a persistent problem: web-facing portals built around legacy identity verification schemes that cannot detect sustained, low-and-slow exfiltration. Organizations managing policyholder or financial data at this scale need anomaly detection on data access patterns, not just perimeter controls. Expect regulatory scrutiny from the FSA and a class-action timeline similar to what we have seen in the U.S. with comparable incidents.
