Aflac Incorporated Discloses Cybersecurity Incident
- Quick incident response - intrusion was stopped within hours of detection
- Business operations remain fully functional with no ransomware impact
- Company proactively offering free 24-month credit monitoring and identity protection services
- Systems continue to process claims and underwrite policies without disruption
- Unauthorized access gained to sensitive customer and employee data including SSNs and health information
- Exact number of affected individuals still unknown
- Part of a broader cybercrime campaign targeting insurance companies
- Social engineering vulnerability exposed security weaknesses
Insights
Aflac's data breach exposes sensitive information, bringing regulatory risks and remediation costs despite prompt containment.
This cybersecurity incident at Aflac represents a significant security breach with potential material implications. While the company deserves credit for detecting and containing the intrusion within hours, the compromise of highly sensitive data—including health information and social security numbers—triggers substantial concerns. The unauthorized access to such regulated data likely activates reporting requirements under multiple state data breach notification laws and potentially HIPAA regulations.
The attack methodology aligns with current threat landscapes—social engineering remains one of the most effective vectors despite technological defenses. This speaks to the persistent challenge of the human element in security architectures. The fact that this was part of a broader campaign targeting multiple insurers suggests a sophisticated threat actor specifically targeting the sector for its valuable data assets.
Several key risk factors stand out from this disclosure: First, the potentially compromised data includes the most sensitive categories of personal information (health data, SSNs), which carry heightened regulatory scrutiny. Second, the offering of 24-month credit monitoring services indicates Aflac anticipates significant impact, as such services typically cost $10-25 per affected individual. Third, the lack of specificity regarding affected population size suggests the investigation remains in early stages.
While operations continuing without disruption is positive, and the absence of ransomware limits operational impact, the potential regulatory penalties, legal liabilities, remediation costs, and reputational damage cannot be overlooked. Similar incidents in the insurance sector have resulted in substantial financial impacts extending for multiple quarters.
We have engaged leading third-party cybersecurity experts to support our response to this incident. While the investigation remains in its early stages, in the spirit of transparency and care for our customers, we are sharing that our preliminary findings indicate that the unauthorized party used social engineering tactics to gain access to our network. Additionally, we have commenced a review of potentially impacted files. It is important to note that the review is in its early stages, and we are unable to determine the total number of affected individuals until that review is completed. The potentially impacted files contain claims information, health information, social security numbers, and/or other personal information, related to customers, beneficiaries, employees, agents, and other individuals in our
Please call our call center at 1-855-361-0305 which will open starting on June 20 at 8:00 a.m. Eastern Time. Our call center will be available Monday through Friday from 9:00 a.m. to 9:00 p.m. Eastern Time, Saturday from 9:00 a.m. to 5:30 p.m. Eastern Time and Sundays from 10:00 a.m. to 4:00 p.m. Eastern Time until the end of June and excluding major
We regret that this incident occurred. We will be working to keep our stakeholders informed as we learn more and continue investigating the incident.
ABOUT AFLAC INCORPORATED
Aflac Incorporated (NYSE: AFL), a Fortune 500 company, has helped provide financial protection and peace of mind for nearly seven decades to millions of policyholders and customers through its subsidiaries in the
1 LIMRA 2023 U.S. Supplemental Health Insurance Total Market Report
Media Contact: mediarelations@aflac.com
View original content to download multimedia:https://www.prnewswire.com/news-releases/aflac-incorporated-discloses-cybersecurity-incident-302487036.html
SOURCE Aflac