← Blog

Aflac Data Breaches: Full Timeline Through 2026

Share on X

People search Aflac data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 7 Aflac-linked incidents (1 company-confirmed), with headline counts up to 22M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Aflac breach history matters

Aflac operates in Finance (United States). Across indexed rows, recurring themes include cloud and database misconfiguration, third-party and supply-chain exposure. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2026 — subsidiary breach; 4.38M customers/agents; bank data exposed

Verified breach. Verified breach — disclosed June 30, 2026. Aflac Incorporated filed SEC Form 8-K stating wholly owned subsidiary Aflac Life Insurance Japan Ltd. discovered June 25, 2026 that an unauthorized third party unlawfully accessed certain Aflac Japan systems between June 15 and June 25, 2026. Aflac Japan suspended affected systems to contain the incident; several customer services remained unavailable during recovery. Investigation with external cybersecurity experts determined impacted files contain policy and coverage de Exposed categories include Policy and coverage details, personal information (names, addresses, phone numbers, dates of birth, gender, security details), insurance account information, and bank account infor. BreachHistory cites approximately 4.4M+ affected records in this row. See the aflac-japan-subsidiary 2026 record and canonical BreachHistory entry.

2025 — 22M PII

Cataloged incident. Unauthorized database access leading to PII exposure; two years of credit monitoring offered to affected individuals. Exposed categories include Names, SSNs, addresses, dates of birth, policy info. BreachHistory cites approximately 22M+ affected records in this row. See the aflac2025 and canonical BreachHistory entry.

2017 — — Aflac: Information on this security breach is provided by…

Unverified claim — treat actor counts cautiously. Information on this security breach is provided by the Office of the California Attorney General. Disclaimer: The number of breached records reported reflects our best estimate, based on all the data currently available, surrounding this breach. Because the specific number of breached records was not disclosed in the notification letter sent to the California Attorney General?s Office, the number is estimated as the minimum number of breached records necessary to trigger the obligation of Exposed categories include Personal information. BreachHistory cites approximately 500 affected records in this row. See the aflac2017 and canonical BreachHistory entry.

2016 — — Aflac: Location of breached information: Unauthorized…

Cataloged incident. Location of breached information: Unauthorized Access/Disclosure Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 930 affected records in this row. See the aflac2016 and canonical BreachHistory entry.

2015 — — Aflac: Location of breached information: Unauthorized…

Cataloged incident. Location of breached information: Unauthorized Access/Disclosure Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 6K+ affected records in this row. See the aflac2015 and canonical BreachHistory entry.

2014 — — Aflac: personal information Location of breached…

Cataloged incident. personal information Location of breached information: Desktop Computer Business associate present: No Exposed categories include Personal information. BreachHistory cites approximately 12 affected records in this row. See the aflac2014 and canonical BreachHistory entry.

2006 — — Aflac: A laptop used to submit insurance applications was…

Cataloged incident. A laptop used to submit insurance applications was stolen from a field associate's home during a burglary.  It may have contained the names and Social Security numbers of policyholders and certificate holders. Exposed categories include Personal information. No attested victim count is published for this row yet. See the aflac2006 and canonical BreachHistory entry.

Patterns and analysis

  • Cloud and database misconfiguration — appears across multiple Aflac catalog entries; prioritize controls that address this class of failure.
  • Third-party and supply-chain exposure — appears across multiple Aflac catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the Aflac company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/aflac · Latest: aflac-japan-subsidiary2026.

Sources: BreachHistory catalog (7 rows for Aflac), company and regulator disclosures cited in individual breach records.