breach
Aflac Japan Breach: Ten-Day Intrusion Exposes Bank Details
2026-06-30

Aflac, the supplemental insurer best known for the duck adverts, has told the SEC that intruders spent ten days inside its Japanese subsidiary's systems before being spotted. Aflac Japan caught the unauthorised access on 25 June 2026 and went public five days later.
The interesting bit is what walked out the door. The attackers made off with policy and coverage details, personal information, and bank account numbers. Aflac has pulled certain systems offline, brought in outside investigators, and notified Japan's Financial Services Agency. Policyholders are still being served, and the company says the US side of the business was untouched.
Two breaches in a year
This is the second Aflac disclosure in roughly twelve months. The 2025 incident in the United States bore the hallmarks of Scattered Spider, the social engineering outfit behind the MGM and Caesars attacks, as well as Erie Insurance and Philadelphia Insurance. No attribution has been offered for the Japan intrusion yet, and the two may be entirely unrelated. But there is a reason the same industry keeps appearing in breach notifications.
Insurance companies sit on a particular kind of jackpot. A claims system holds names, addresses, dates of birth, government IDs, medical detail, financial information and bank account numbers, all neatly indexed against real people with real money. For an attacker working a downstream fraud or extortion play, it is hard to find a richer dataset in one place.
Ten days is a long time
The dwell time deserves a second look. Ten days inside an insurer's network is plenty of time to map systems, find the databases that matter, stage data for exfiltration and quietly leave. The fact that Aflac Japan still describes the full scope as unknown is honest, but it is also a reminder that initial breach disclosures are almost always a floor, not a ceiling. The numbers tend to grow once forensics catches up with reality.
What makes intrusions like this hard to stop at the perimeter is that they rarely begin at the perimeter. Scattered Spider and groups like it have made their name by phoning service desks, impersonating staff, and talking their way into credentials and MFA resets. The technical controls matter, but the front line is usually a human being on a call.
What to watch
- Scope drift. Expect the categories of data and the number of affected policyholders to expand as the investigation continues.
- Attribution. If Japan is also a Scattered Spider job, or a copycat using the same social engineering playbook, that tells a story about how this group is scaling its operation across geographies.
- Regulatory response. Japan's FSA has been increasingly active on cyber incident handling. How Aflac Japan's disclosure timeline is judged matters for everyone else operating there.
The duck is fine. The data is the problem.