Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

22 Million Affected by Aflac Data Breach

Hackers stole names, addresses, Social Security numbers, ID numbers, and medical and health insurance information from Aflac’s systems.

Cyberinsurance

Insurance giant Aflac is notifying roughly 22.65 million people that their personal information was stolen from its systems in June 2025.

The company disclosed the intrusion on June 20, saying it had identified suspicious activity on its network in the US on June 12 and blaming it on a sophisticated cybercrime group.

The company said it immediately contained the attack and engaged with third-party cybersecurity experts to help with incident response. Aflac’s operations were not affected, as file-encrypting ransomware was not deployed.

Just before Christmas, the Columbus, Georgia-based company announced it had completed its investigation into the potentially compromised data and had started notifying the affected individuals.

“Based on our review of potentially impacted files, we have determined personal information associated with approximately 22.65 million individuals was involved,” the company said.

The compromised information, the insurance giant says, includes names, addresses, Social Security numbers, dates of birth, driver’s license numbers, government ID numbers, medical and health insurance information, and other data.

Advertisement. Scroll to continue reading.

“The review of the potentially impacted files determined personal information associated with customers, beneficiaries, employees, agents, and other individuals related to Aflac was involved,” Aflac said in a notification (PDF) on its website.

The company is providing the affected individuals with 24 months of free credit monitoring, identity theft protection, and medical fraud protection services.

Aflac says it is not aware of any of the stolen information being fraudulently used, but urges the impacted individuals to remain vigilant against any identity theft and fraud attempts.

The insurance giant did not name the threat actor behind the data breach, but said the incident was part of a “campaign against the insurance industry”.

This suggests that the Scattered Spider hacking group might have been responsible for the intrusion, as it occurred around the same time that Google’s Threat Intelligence Group warned that the gang was focusing on insurance companies.

Related: Nissan Confirms Impact From Red Hat Data Breach

Related: 3.5 Million Affected by University of Phoenix Data Breach

Related: University of Sydney Data Breach Affects 27,000 Individuals

Related: 113,000 Impacted by Data Breach at Virginia Mental Health Authority

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Geoff Belknap has joined HubSpot as Chief Trust Officer.

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.