Data leak

Aflac Insurance Data Breach (Scattered Spider)

πŸ“… 2025-06-12
Primary Source β†—

Incident Details

On June 12, 2025, Aflac insurance company’s US network was compromised via social engineering. The attack is attributed to Scattered Spider, a financially motivated English-speaking group known for vishing attacks against IT help desks. The intrusion was detected and contained within hours, preventing ransomware deployment. At least 22.65 million individuals had personal and health data stolen, including names, SSNs, dates of birth, health records, government-issued IDs, and driver’s license details. Aflac stated the attack was part of a broader ‘campaign against the insurance industry.’ HHS OCR breach report listed 13.9 million PHI records. Described as part of a wave of insurance sector social engineering attacks also targeting Allianz Life. No ransom paid.

Technical Details

Initial Attack Vector
Social engineering / vishing (voice phishing): attackers impersonated employees to deceive IT help desk into granting account access

Timeline

  1. 2025-06-12 Breach occurred
  2. 2025-12-23 Publicly disclosed
  3. 2025-12-23 Customers notified