22.65 Million Customers Affected in Widespread Cyberattack
The U.S. insurance sector faced a significant security incident when millions of customer records were compromised through a sophisticated cyberattack targeting Aflac. The company recently announced that approximately 22.65 million individuals have been notified following the breach, which initially came to light in June without clear disclosure of the full scope of the incident.
What Data Was Stolen
The compromised information represents a comprehensive collection of sensitive personal and financial data. According to filings with state attorneys general in Texas and Iowa, the stolen records include:
Customer full names and dates of birth
Residential addresses
Government-issued identification numbers, including passport and state ID card numbers
Driver’s license numbers
Social Security numbers
Complete medical and health insurance records
This breadth of stolen information presents significant risks for identity theft and fraudulent activities among affected individuals.
Attribution Points to Organized Cyber-Criminal Network
Federal law enforcement and independent cybersecurity experts have indicated that the perpetrators may be affiliated with an established cyber-criminal organization. Based on the timing and targeting patterns, evidence suggests that Scattered Spider—a network of primarily young English-speaking hackers—could be responsible for the attack. This group has demonstrated a focused strategy of targeting insurance companies across the industry, making Aflac one of several organizations hit during the same campaign window.
Broader Industry Under Siege
Aflac was not an isolated target. The same timeframe saw data breaches affecting Erie Insurance and Philadelphia Insurance Companies, suggesting a coordinated campaign against the insurance sector. With Aflac serving approximately 50 million customers according to company disclosures, the breach represents a substantial compromise of the insurance industry’s security infrastructure.
Implications for the Insurance Industry
The incident underscores how hackers systematically identify and exploit vulnerabilities in large financial service providers. The scale of the breach and the sophistication of the attack raise critical questions about data protection standards across the insurance industry and the need for enhanced cybersecurity protocols in handling sensitive customer information.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
Aflac Breach Exposes Security Gaps as Major Hacker Collective Targets Insurance Sector
22.65 Million Customers Affected in Widespread Cyberattack
The U.S. insurance sector faced a significant security incident when millions of customer records were compromised through a sophisticated cyberattack targeting Aflac. The company recently announced that approximately 22.65 million individuals have been notified following the breach, which initially came to light in June without clear disclosure of the full scope of the incident.
What Data Was Stolen
The compromised information represents a comprehensive collection of sensitive personal and financial data. According to filings with state attorneys general in Texas and Iowa, the stolen records include:
This breadth of stolen information presents significant risks for identity theft and fraudulent activities among affected individuals.
Attribution Points to Organized Cyber-Criminal Network
Federal law enforcement and independent cybersecurity experts have indicated that the perpetrators may be affiliated with an established cyber-criminal organization. Based on the timing and targeting patterns, evidence suggests that Scattered Spider—a network of primarily young English-speaking hackers—could be responsible for the attack. This group has demonstrated a focused strategy of targeting insurance companies across the industry, making Aflac one of several organizations hit during the same campaign window.
Broader Industry Under Siege
Aflac was not an isolated target. The same timeframe saw data breaches affecting Erie Insurance and Philadelphia Insurance Companies, suggesting a coordinated campaign against the insurance sector. With Aflac serving approximately 50 million customers according to company disclosures, the breach represents a substantial compromise of the insurance industry’s security infrastructure.
Implications for the Insurance Industry
The incident underscores how hackers systematically identify and exploit vulnerabilities in large financial service providers. The scale of the breach and the sophistication of the attack raise critical questions about data protection standards across the insurance industry and the need for enhanced cybersecurity protocols in handling sensitive customer information.