Aflac discloses network intrusion tied to insurance sector campaign

Organization
Aflac Incorporated
Exploit
Hacking
Industry
Insurance

Aflac disclosed on June 20, 2025 that it had detected suspicious activity on parts of its United States network eight days earlier, on June 12. The supplemental insurer said it stopped the intrusion within hours and that its systems stayed operational, allowing it to continue underwriting policies, paying claims and serving customers.

Aflac said the attackers used social engineering to get into the network, and described the event as part of a broader cybercrime campaign against the insurance industry. It said no ransomware was deployed.

The company said a review was under way of files the intruders may have reached. Those files potentially held claims records, health information, Social Security numbers and other personal data belonging to customers, beneficiaries, employees, agents and other individuals connected to its U.S. business. Aflac gave no victim count at disclosure, saying the scope was still being determined.

Aflac did not name a threat actor. Researchers quoted by The Record and Cybersecurity Dive linked the activity to Scattered Spider, an English speaking group known for impersonating staff to help desks and call centres, which Google Threat Intelligence had recently warned was shifting from retail to insurance targets. Erie Insurance and Philadelphia Insurance Companies reported incidents in the same period. Aflac opened a dedicated phone line and offered two years of identity theft protection and credit monitoring.

Updates

  1. Aflac began notifying roughly 22.65 million people, the first victim count it has given after declining to provide one at disclosure in June. The figure comes from filings with the Texas and Iowa attorneys general.

Sources