More than 22 million Aflac customers impacted by June data breach

A data breach in June exposed the information of more than 22 million Aflac customers, according to a new statement from the company. 

The Georgia-based insurance giant published a statement on Friday about the conclusion of a months-long investigation into a cybersecurity incident announced earlier this year. 

The company previously warned the Securities Exchange Commission (SEC) that while it was able to stop a hacker intrusion “within hours,” some files were stolen by the cybercriminals. 

Aflac reiterated that it was not affected by ransomware. The company has begun notifying state regulators about the attack and sending breach notification letters to victims. 

Officials in Texas said more than 2 million residents of the state were affected and in total, about 22.7 million individuals had information stolen. 

The company faced no operational issues as a result of the cyberattack but the documents stolen contained information on insurance claims, health data, Social Security numbers and other personal details of “customers, beneficiaries, employees, agents, and other individuals in its U.S. business.” 

Federal law enforcement was notified of the attack and cybersecurity experts were hired to deal with the incident. 

The letters say the investigation concluded on December 4 and victims are being given access to two years of identity protection services. The letters said the deadline to enroll in the services ends on April 18, 2026.

The incident took place amid a wider campaign of attacks targeting the insurance industry by an organization known as Scattered Spider, a loosely affiliated group of English-speaking cybercriminals known for gaining access to major companies by posing as IT workers. Erie Insurance, the Philadelphia Insurance Companies and Scania Financial Services each reported cyberattacks at the time. 

Since the attacks, law enforcement has taken down a leak site used by the group and two members were arrested and charged in the U.K. A Justice Department complaint unsealed in September revealed that the Scattered Spider cybercriminal operation was able to extort at least $115 million from dozens of victims over the last three years.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

 

Total
0
Shares
Previous Post

SEC sues crypto firms for defrauding investors out of $14 million

Next Post

Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition

Related Posts

Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation

The threat actors behind a large-scale, ongoing smishing campaign have been attributed to more than 194,000 malicious domains since January 1, 2024, targeting a broad range of services across the world, according to new findings from Palo Alto Networks Unit 42. "Although these domains are registered through a Hong Kong-based registrar and use Chinese nameservers, the attack infrastructure is
Read More

TP-Link Patches Four Omada Gateway Flaws, Two Allow Remote Code Execution

TP-Link has released security updates to address four security flaws impacting Omada gateway devices, including two critical bugs that could result in arbitrary code execution. The vulnerabilities in question are listed below - CVE-2025-6541 (CVSS score: 8.6) - An operating system command injection vulnerability that could be exploited by an attacker who can log in to the web management
Read More

India Orders Phone Makers to Pre-Install Government App to Tackle Telecom Fraud

India's telecommunications ministry has ordered major mobile device manufacturers to preload a government-backed cybersecurity app named Sanchar Saathi on all new phones within 90 days. According to a report from Reuters, the app cannot be deleted or disabled from users' devices. Sanchar Saathi, available on the web and via mobile apps for Android and iOS, allows users to report suspected fraud,
Read More