SHINDO6

Aflac

Financial & payment~220,000peopleof ~4.4M people affected in total

LEAK CONFIRMEDBank account / Date of birthUnauthorized access · Recovering

Open in the live monitor ▶
Disclosed
Jun 30, 2026
Detected
Jun 25, 2026 06:30 JST
Detection to disclosure
5 days
Leak
Leak confirmed
Type
Unauthorized access
Status
Recovering
Security spend
Not checked yet
Compensation
Not announced

What leaked

IdentityFull name, Date of birth, Gender
ContactAddress, Phone number
Transactions & activityPolicy number and coverage details
Family & private lifeInsured-person data, beneficiary names, secondary contacts
Financial & paymentPremium-debit bank account data (about 220,000 people)

Not leaked

  • My Number, credit card data and email addresses were not included
  • My Number, credit card data and email addresses were not included

How many

  • Customers (corrected figure) ~4.4M people
  • Of which customers whose premium-debit bank account data was included ~220,000 people
  • Sales agencies ~40,000 organizations

Who is affected

  • Customers (policyholders)
  • Insured persons, beneficiaries and secondary contacts
  • Sales agencies

Cause

In the Online consultation and Yorisou Net systems, controls against unauthorized access and data queries were insufficient, and monitoring and control for bulk data queries were also lacking

Timeline

  1. Intrusion began
  2. Contained
  3. Detected
  4. First disclosure
  5. Received an order to submit a report from the FSA
  6. Company issued an update
  7. Company issued an update
  8. Company issued an update

Response

  • Blocked the entry point
  • Service stopped
  • MFA
  • More monitoring
  • Vulnerability testing
  • Red team
  • Governance / committee

Blocked the access and stopped the system. Four prevention measures: stronger authentication and authorization, stronger monitoring and control of bulk access, more security reviews and penetration testing, stronger information security management. Shared affected account data with financial institutions (8/24)

What you should do

  1. Scammers who know your account number pose as refund staff. No bank or company asks for your PIN
  2. Treat refund or apology calls and texts as scams. Call back only on the number from the official site
  3. Watch for unexpected mail or invoices; your address is hard to change
  4. You can be affected without ever using this service (parcel recipients etc.). Check any notice you receive
  5. Check the company's notice to see if you're affected

Lessons for companies

  1. Patch internet-facing servers, VPNs and admin panels first. Exploits follow disclosure within days
  2. Never sit on a known defect. Test every change before production
  3. Don't keep ID or bank data: delete after checks or use a KYC provider
  4. Report to the PPC: preliminary in 3–5 days, final in 30 (60 if malicious)
  5. Run red teaming and AI-assisted hardening, and publish how much you invest

Sources