
COLUMBUS, GA – Aflac Incorporated, a leading supplemental insurance provider, disclosed that its U.S. systems suffered a cyberattack on June 12, 2025, potentially exposing sensitive customer data. The breach was quickly contained, but it may have compromised claims information, health records, Social Security numbers, and other personal identifiers.
What We Know So Far
- Aflac identified unauthorized activity on its U.S. network and triggered its incident response protocols, halting the intrusion within hours.
- The attack did not involve ransomware, and Aflac’s business functions – claims processing, underwriting, customer service – remained fully operational.
- The intrusion appears to be part of a larger wave of cyberattacks on insurance firms, potentially orchestrated by the Scattered Spider hacking collective, known for deploying advanced social engineering tactics.
Potential Data Exposure
- Aflac is reviewing impacted files which may include:
- Health insurance claims and medical records
- Social Security numbers
- Personal and demographic data tied to customers, beneficiaries, employees, and agents.
- The full scope and number of affected individuals remain unknown due to ongoing investigation
Aflac’s Response
- The company immediately engaged third-party cybersecurity experts to assist with investigation and containment efforts.
- A dedicated support line has been opened (1‑855‑361‑0305), where affected individuals can request 24 months of free credit monitoring, identity theft protection, and Medical Shield coverage.
Broader Industry Implications
- Aflac is the latest casualty in a wave of targeted cyberattacks affecting insurers – Philadelphia Insurance Companies and Erie Insurance were similarly breached just days earlier.
- Experts warn that social engineering – where attackers impersonate legitimate personnel to trick employees into granting network access – is the primary tactic used by groups like Scattered Spider.
- The Wall Street Journal has described this group’s activity as putting insurers “under siege,” calling for stronger layered cybersecurity defenses and vigilant staff training.
What Affected Individuals Can Do Now
- Contact Aflac’s call center to enroll in the offered protection services.
- Freeze your credit with Equifax, TransUnion, and Experian to prevent fraud.
- Monitor accounts and statements regularly for unusual activity.
- Be alert to phishing attempts, particularly communications masquerading as Aflac or related to this incident.
- Enable strong password practices and MFA on all online accounts.
Why This Matters
This incident underscores how deeply disruptive – and potentially costly – non-ransomware attacks can be for firms that handle sensitive data. Social engineering attacks, in particular, are stealthy and hard to detect. If your business works with insurers or handles personal data, a proactive cybersecurity posture – multi-layered defenses, staff training, and incident readiness – is critical.

About The Author: John Colascione is Chief Executive Officer of Internet Marketing Services Inc. He specializes in Website Monetization, is a Google AdWords Certified Professional, authored a ‘how to’ book called ”Mastering Your Website‘, and is a key player in several Internet related businesses through his search engine strategy brand Searchen Networks®
Leave a Reply