June 30, 2026: Insurance giant Aflac disclosed that its wholly owned Japanese subsidiary, Aflac Life Insurance Japan Ltd., suffered a 10-day unauthorized access window from June 15 through June 25, 2026, exposing data tied to approximately 4.38 million customers and agents—distinct from Aflac's separate 2025 U.S. breach affecting ~22 million records.
What happened
Per Aflac's SEC Form 8-K and BleepingComputer, attackers accessed systems including the customer-only Aflac Yoriso Net portal. Aflac Japan discovered the intrusion June 25, suspended affected systems to contain it, and engaged external cybersecurity experts. Several customer services remained unavailable during recovery.
What data was exposed
Aflac Japan determined impacted files contain:
- Policy and coverage details
- Personal information—names, addresses, phone numbers, dates of birth, gender, and security details (varies by customer)
- Insurance account information
- Bank account information
At initial disclosure, Aflac Japan had not confirmed misuse of leaked information. Affected individuals will receive notification letters detailing what was compromised.
What was not exposed
Aflac emphasized the breach is limited to Japan. U.S. Aflac business systems were not accessed.
Who is at risk
Japanese Aflac policyholders and agents whose data transited the Yoriso Net portal during the access window face elevated phishing, account takeover, and financial fraud risk—especially given bank account details in the exposed corpus.
Action items
- Wait for official letters from Aflac Japan before responding to unsolicited contact.
- Monitor bank accounts linked to Aflac premium payments for unauthorized transactions.
- Be skeptical of emails citing real policy numbers—verify through official Aflac Japan channels only.
- Enable MFA on email and banking portals.
Canonical record: Aflac Japan subsidiary breach 2026 on BreachHistory.