Aflac Life Insurance leaked personal information of approximately 4.38 million customers through unauthorized access to a policyholder-only site. Behind this are the company’s large-scale security incidents that recur over short periods, as well as structural vulnerabilities in supply chain management across the insurance industry.
- The Background of Unauthorized Access and the Scale of Damage
- Details of the leaked information and its impact on agencies
- The third major incident and the mere formality of defense
- Inadequate management system that took 10 days to detect attacks
- Limitations of supply chain attacks and subcontractor management
- Compensation for Policyholders and Rebuilding Cyber Measures Across the Industry
The Background of Unauthorized Access and the Scale of Damage
On June 30, 2026, Afrac Life Insurance announced that systems operated by its policyholder-only site, such as ‘Afrac Yoroso Net,’ had been accessed by unauthorized third-party users, resulting in the leakage of customers’ personal information. This incident occurred continuously over 10 days until June 25, 2026, when the first unauthorized access occurred and the company detected an anomaly and blocked access.
The scale of the damage was extremely large, with approximately 4.38 million customers leaving. This calculation means that about one in five people out of the approximately 22.18 million contracts held by the company is affected, making it one of the largest data breaches ever among domestic insurance companies. The diagram below shows the timeline from the occurrence of unauthorized access to its publication and the extent of the damage.

The company has already reported to the Financial Services Agency and the police, and is currently working with external specialized agencies to investigate the cause. At this point, no unauthorized use of information has been confirmed, but the fact that it took as long as ten days to come to light highlights vulnerabilities in the company’s system oversight system.
Details of the leaked information and its impact on agencies
One particularly serious aspect of this information leak is that bank account information was included among the leaked items. Of all approximately 4.38 million eligible individuals, about 230,000 had their insurance premium transfer account information (financial institution name, branch name, account number, account name) illegally accessed. Although My Number and credit card information are not included, leaking account information can lead to secondary damage such as bank transfer fraud, and anxiety is rapidly spreading among policyholders.
Common leaked items include the following:
-
Name
-
Date of birth
-
Age and Gender
-
Address, phone number
-
Policy Number and Coverage Details
Furthermore, the damage was not limited to policyholders; about 40,000 pieces of information related to agencies were leaked. This included the name, address, and phone number of the agency representative, and even included information about agencies that had already completed their outsourced work. Insurance agents play a crucial role in the supply chain for insurance companies, and any leak of such information can significantly impact trust with agents and business operations.
Corporate stance amid repeated information leaks
The third major incident and the mere formality of defense
For Aflac, this is not the first large-scale information breach. In just over three years, the company has experienced three major leak incidents, including this one. In January 2023, a U.S. company that outsourced its operations suffered unauthorized access, resulting in the leakage of information on approximately 1.3 million cancer insurance policyholders. Additionally, it was announced that in June 2025, the U.S. headquarters was hit by a cyberattack, potentially stealing information from approximately 22.65 million customers and employees.
In response to such a rapid occurrence of large-scale incidents in a short period, voices of anger and disappointment from policyholders have been pouring in on social media. In particular, users who have experienced past leaks have strongly criticized the lack of effective measures to prevent recurrence. The following figure compares Aflac’s history of information leaks.

In the 2023 case, an external contractor was targeted, but this time, the system operated by Aflac itself was directly attacked, raising suspicions that the security system had become a mere formality. Although the company repeatedly states that it will “further strengthen its security system,” the management stance is being seriously questioned whether effective measures have been implemented.
Inadequate management system that took 10 days to detect attacks
In this case, the fact that the attack began on June 15, 2026, until the company detected it for 10 days suggests a critical flaw in cybersecurity measures. As cyberattacks become more sophisticated, even when it is difficult to completely prevent intrusions, “resilience” is emphasized—detecting early and minimizing damage—but Aflac has also fallen into dysfunction in this regard.
Normally, financial institution systems are equipped with mechanisms to monitor unauthorized login attempts and large volumes of data access, but in this case, the attacker repeatedly entered the system over 10 days and continued unauthorized browsing. This suggests that the company’s monitoring alert settings and log verification processes may have been inadequate.
The Financial Services Agency has long positioned cybersecurity as a key management issue and has called for responses at the management level. The fact that a company with a massive customer base like Aflac missed such an attack for such a long time is not just a technical mistake, but a matter that should be rigorously examined as a matter of governance itself.
Structural vulnerabilities common to the insurance industry
Limitations of supply chain attacks and subcontractor management
Aflac’s case goes beyond individual corporate issues but highlights structural vulnerabilities in supply chain management across the entire insurance industry. Insurance companies operate supported by an extensive supply chain including system development firms, maintenance and management firms, and countless insurance agents. These small contractors and agencies often lack the budget and personnel for security measures compared to large corporations, making them prime targets for cyber attackers.
The diagram below illustrates a typical supply chain in the insurance industry and the concept of “supply chain attacks” aimed at it.

In recent years, rather than directly targeting headquarters with strong security, it has become common to infiltrate by using the networks of weakly defended related companies or contractors as footholds. For example, threats like the malware ‘Emotet,’ which exploit clients’ email information to spread infections, are becoming increasingly serious. Just as Aflac’s 2023 case was directly handled by an external contractor, the entire industry needs to reaffirm the risk that a single breach can directly harm the entire group and, consequently, millions of customers.
The path to restoring trust and future highlights
Compensation for Policyholders and Rebuilding Cyber Measures Across the Industry
The biggest focus going forward will be how Aflac can restore the lost trust and implement effective measures to prevent recurrence. The company stated it would issue written apologies and notifications to all affected policyholders, but attention is focused on how much specific compensation and support measures to prevent secondary damage, including the 230,000 people whose account information was leaked, will be provided. In the United States, class-action lawsuits related to cyberattacks are already underway, and the risk of legal liability and compensation may increase within Japan as well.
On the other hand, it has also become clear that the efforts of individual companies alone have their limits. Specialized organizations such as the Japan Actuaries Association have proposed establishing a “mutual aid organization (information sharing consortium)” specialized in the insurance industry. This concept aims to standardize risk assessments of contractors and agents independently conducted by each company, consolidate specialized personnel, and handle them collectively, thereby enhancing the objectivity and efficiency of evaluations.
The Financial Services Agency also issued a document in December 2025 calling for thorough management of outsourced subcontractors, calling for in-depth due diligence beyond mere checklists. Triggered by the Aflac case, whether the insurance industry as a whole can abandon the old mindset of “just protecting oneself” and build a new security model that comprehensively protects the entire supply chain will determine the reliability of Japan’s financial infrastructure going forward.
[#アフラック #情報漏洩 #サイバーセキュリティ #サプライチェーン攻撃 #金融庁 #経済ニュース #個人情報保護]


コメント