Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Aflac

Aflac Vendor Cyber Rating & Cyber Score

aflac.com

Over 50 Million people worldwide have chosen Aflac because of our commitment to providing customers with the confidence that comes from knowing they have assistance in being prepared for whatever life may bring. With Aflac, whether you're a large business or a small one, you can provide your employees with the kind of benefits they’d expect from a bigger company, helping your business stand out from the crowd. Hundreds of thousands of businesses across the United States already make Aflac available to their employees—at no direct cost to their company. Choose from a wide range of products that can help your employees with health events—from accidents, to disability, to cancer, to life insurance. Your employees enjoy benefits from Aflac,


Aflac A.I CyberSecurity Scoring

Aflac
Company Information
Website:https://www.aflac.com
Employees number:18,043
Number of followers:168,536
NAICS:524
Industry Type:Insurance
Homepage:aflac.com
Aflac Risk Score (AI oriented)
Between 0 and 549
logo
AflacInsurance
Updated:
01/04/2026
491/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Aflac Global Score (TPRM)
xxxx
logo
AflacInsurance
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Aflac
AflacCritical
Current Score
491C (CRITICAL)
01000
7 incidents
-71.6 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
504Before Incident
MAY 2026
500Before Incident
APRIL 2026
496Before Incident
MARCH 2026
487Before Incident
FEBRUARY 2026
480Before Incident
JANUARY 2026
546Before Incident
Cyber Attack
13 Jan 2026Aflac
Aflac, Jaguar Land Rover and Nucor: Major automaker hit by cyberattack, says incident 'severely disrupted' operations

Jaguar Land Rover Ransomware Attack

476After Incident
CRITICAL-70
AFLJAGNUC1768389868
Ransomware Attack Disrupts Jaguar Land Rover Operations as Cyber Threats Surge Across Industries Jaguar Land Rover (JLR), the UK-based automaker owned by India’s Tata Motors, confirmed a ransomware attack that severely disrupted its retail and production operations. In a statement released Tuesday, the company revealed it had taken immediate action to contain the incident by proactively shutting down systems. While JLR reported no evidence of customer data theft, it is working to restore global applications in a controlled manner. The attack is part of a broader wave of cyber incidents targeting critical industries. U.S. steelmaker Nucor also recently experienced a cybersecurity breach, forcing a shutdown of some production lines. The insurance sector has been particularly hard hit, with Aflac, Philadelphia Insurance Companies, and Erie Insurance all falling victim to attacks this summer. Grocery supply chains have not been spared United Natural Foods Inc. (UNFI), a distributor for Whole Foods and other retailers, disclosed a cyber incident in July that temporarily disrupted operations. Meanwhile, the FBI issued a warning last month about the cybercriminal group "Scattered Spider," which has been targeting airlines. Hawaiian Airlines confirmed a June cybersecurity event affecting its IT systems, while Air France and KLM reported a data breach in their customer service platform. The surge in attacks underscores the growing sophistication of threat actors and the widespread impact of ransomware on global operations.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: No evidence of customer data stolenSystems Affected: Global applicationsOperational Impact: Severely disrupted retail and production activities
DATA BREACH
Data Exfiltration: No evidence of data exfiltration
DECEMBER 2025
631Before Incident
Breach
29 Dec 2025Aflac
Aflac: Insurance Giant Aflac Confirms 22.65 Million Individuals Affected by June Cyberattack

Aflac Cyberattack and Data Breach

544After Incident
CRITICAL-87
AFL1768391547
Aflac Confirms Massive Data Breach Affecting 22.65 Million Individuals in June 2025 Cyberattack Insurance giant Aflac has confirmed that a June 2025 cyberattack compromised the personal and sensitive data of approximately 22.65 million individuals far exceeding the initial placeholder figure of 500 reported to the HHS’ Office for Civil Rights on August 8, 2025. The breach, detected on June 12, 2025, was contained within hours, but investigations later revealed that a threat actor gained access to multiple systems through social engineering attacks on user accounts. Aflac, a Fortune 500 company specializing in supplemental health insurance with 50 million customers worldwide, operates subsidiaries in the U.S. and Japan. The compromised data includes names, addresses, dates of birth, government-issued IDs (passport, driver’s license, Social Security numbers), medical information, and health insurance details affecting customers, beneficiaries, employees, and agents in its U.S. business. While no misuse of the stolen data has been reported, Aflac is offering 24 months of complimentary credit monitoring and identity theft protection to affected individuals. The attack is suspected to be the work of Scattered Spider, a financially motivated hacking group known for targeting critical sectors, including healthcare, insurance, and retail. The group, composed of young English-speaking hackers primarily based in the U.S. and U.K., has previously conducted social engineering campaigns against IT help desks and managed service providers (MSPs). The HHS’ Health Sector Cybersecurity Coordination Center (HC3) issued a warning about the group in October 2024, citing its growing threat to the healthcare and public health sectors. This breach ranks among the largest U.S. healthcare data breaches of 2025, with over 20 class action lawsuits filed and regulatory investigations underway to assess Aflac’s compliance with data privacy laws. The incident follows similar attacks on other insurers, including Erie Insurance Group and Philadelphia Insurance Companies, suggesting a coordinated campaign against the industry. On August 28, 2025, Senators Bill Cassidy (R-La.) and Margaret Wood Hassan (D-N.H.) demanded further transparency from Aflac, requesting details on pre-attack security measures, federal notifications, and steps taken to improve cybersecurity protocols. Aflac has until September 5, 2025, to respond. While ransomware was not deployed in this attack, Scattered Spider’s shift toward data theft and extortion signals an evolving threat to the insurance sector. The breach underscores the group’s ability to exploit social engineering for initial access, even against large, well-resourced organizations.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Names, addresses, dates of birth, government-issued ID numbers (passport, state ID, driver’s license), Social Security numbers, medical information, health insurance informationSystems Affected: Multiple Aflac systemsOperational Impact: No impact on business operations; continued underwriting policies, reviewing claims, and servicing customersBrand Reputation Impact: Significant (over 20 class action lawsuits filed)Legal Liabilities: Regulatory investigations initiated; potential fines under state and federal data privacy lawsIdentity Theft Risk: High (complimentary credit monitoring and identity theft protection services offered for 24 months)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Number Of Records Exposed: 22,650,000Sensitivity Of Data: High (government-issued IDs, Social Security numbers, medical information)Data Exfiltration: YesData Encryption: NoPersonally Identifiable Information: Names, addresses, dates of birth, government-issued ID numbers, Social Security numbers
NOVEMBER 2025
575Before Incident
OCTOBER 2025
652Before Incident
Breach
14 Oct 2025Aflac
Aflac

NC Woman Charged with 170 Felonies in Insurance Fraud and Identity Theft Involving Stolen GLP-1 Drugs

569After Incident
HIGH-83
AFL2462024101425
Aflac, a supplemental insurance provider, fell victim to a large-scale fraud scheme orchestrated by Heather Ann Robinson, who exploited stolen personal and financial information to file fraudulent insurance claims. Robinson, posing as a medical professional without credentials, illegally obtained and administered GLP-1 weight-loss drugs (e.g., Ozempic, Wegovy) while submitting false claims to Aflac and Colonial Life, defrauding them of $87,415—with an additional attempted theft of $157,300. The breach involved identity theft, including siphoning $46,614 from victims’ 401K accounts using compromised data, some sourced from family members. Investigators seized her devices, uncovering extensive evidence after a six-month analysis. While the article does not specify a direct cyberattack, the systematic misuse of stolen credentials and financial data—coupled with prior embezzlement allegations against Robinson—highlights vulnerabilities in Aflac’s fraud detection and customer data protection mechanisms. The incident underscores risks of insider-enabled fraud and third-party exploitation of sensitive policyholder information.
INCIDENT DETAILS -
TYPE
FraudIdentity TheftInsurance FraudFinancial Crime
MOTIVATION
Financial GainFraudulent Insurance ClaimsTheft of Retirement Funds
IMPACT
Financial Loss: $134,014 (Insurance: $87,415 + 401K: $46,614)Personally Identifiable Information (PII)Financial Data (Credit Cards, 401K Access)Medical/Insurance Claims DataRevenue Loss: $87,415 (Fraudulent Claims Paid) + $157,300 (Attempted)Tips Received by DOI (Triggered Investigation)Potential Trust Erosion in Aflac/Colonial Life (Insurance Providers)Negative Publicity for GLP-1 Drug Misuse170 Felony Charges (Insurance Fraud, Identity Theft, Credit Card Fraud)High (Stolen PII Used for 401K Theft)High (Credit Card Fraud Charges)
DATA BREACH
PII (Family Members/Victims)Financial Data (401K, Credit Cards)Insurance Claims DataSensitivity Of Data: High (Financial, Medical, PII)Physical (Laptop/Cellphone Seizure)Unauthorized Access to 401K AccountsNamesFinancial Account DetailsInsurance Policy Information
SEPTEMBER 2025
651Before Incident
AUGUST 2025
648Before Incident
JULY 2025
646Before Incident
JUNE 2025
701Before Incident
Breach
16 Jun 2025Aflac
Aflac

Transition to Passwordless Authentication with Passkeys and Security Implications

642After Incident
HIGH-59
AFL4392343092525
Aflac, a leading US insurance provider, became the first major insurance company to adopt passkeys as part of its passwordless authentication strategy. While the transition significantly improved security—reducing password recovery requests by 32% and eliminating 30,000 identity-related support calls monthly—the article highlights broader industry risks tied to stolen credentials, which remain a dominant attack vector. Verizon’s 2025 Data Breach Investigations Report reveals that 88% of breaches involve compromised credentials, often obtained via phishing, brute force, or credential stuffing. The shift to passkeys mitigates such risks by eliminating password-based vulnerabilities, but the article implies that legacy systems, hybrid authentication models, or incomplete adoption could still expose Aflac to residual threats. For instance, if passkey implementation faces device dependency issues, compatibility gaps with older systems, or user resistance, attackers might exploit fallback password mechanisms or unpatched vulnerabilities in transitional infrastructure. While Aflac’s proactive move reduces attack surfaces, the potential for credential-theft-driven breaches persists in hybrid environments, particularly if employees or third-party vendors rely on traditional authentication for certain services.
INCIDENT DETAILS -
TYPE
Authentication Security ImprovementCybersecurity Trend Analysis
MOTIVATION
Improving Security PostureReducing Support CostsEnhancing User Experience
IMPACT
Reduction in Password Recovery Requests (32% drop for Aflac)Decrease in Identity-Related Support Calls (~30,000 fewer calls monthly for Aflac)Positive perception of enhanced security measuresReduced due to elimination of password-based vulnerabilities
JUNE 2025
760Before Incident
Breach
12 Jun 2025Aflac
Aflac: Aflac hit by cyberattack amid broader insurance sector targeting

Aflac Cybersecurity Breach Linked to Scattered Spider

701After Incident
CRITICAL-59
AFL1770237527
Aflac Hit by Cyberattack as Scattered Spider Targets Insurance Sector Aflac, a major U.S. insurance provider, disclosed a cybersecurity breach on June 12, linking the incident to the cybercrime group Scattered Spider. Known for its advanced social engineering tactics, the group has increasingly targeted financial services and insurance firms, with recent attacks also affecting Erie Insurance, which now faces a proposed class-action lawsuit over alleged inadequate security measures. The breach at Aflac was detected and contained within hours, though the investigation supported by external cybersecurity experts remains ongoing. Initial findings suggest the attackers gained access through social engineering rather than ransomware. While Aflac’s core operations, including claims processing and customer service, remain unaffected, the exposed data may include claims records, health details, Social Security numbers, and personal information tied to policyholders, beneficiaries, employees, and agents. Aflac has not yet determined the full scope of the breach or the number of affected individuals but is offering 24 months of complimentary credit monitoring, identity theft protection, and Medical Shield coverage to those who contact its call center. The incident reflects a broader trend of cyber threats exploiting both malicious attacks and internal vulnerabilities, such as software misconfigurations. The breach follows a pattern of recent intrusions against insurers, underscoring the sector’s growing appeal to sophisticated threat actors. Aflac continues to assess the impact and will provide updates as the investigation progresses.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Claims records, health details, Social Security numbers, personal informationOperational Impact: Core operations (claims processing and customer service) remain unaffectedIdentity Theft Risk: High
DATA BREACH
Claims recordsHealth detailsSocial Security numbersPersonal informationSensitivity Of Data: HighPersonally Identifiable Information: Yes
MAY 2018
730Before Incident
Breach
01 May 2018Aflac
Aflac

Aflac Insurance Company Data Breach

671After Incident
MEDIUM-59
AFL17551822
Aflac insurance company has encountered a breach of personal data that has exposed the email accounts belonging to a small number of independent contractor sales agents. Clients' personal information such as names, addresses, dates of birth, policy numbers, social security numbers, and bank account information may have been exposed. The unauthorized access to email accounts happened between Jan. 17 and April 2. The company took immediate action by resetting passwords, isolating specific email accounts and contacting the affected insurance agents. Aflac has stated that they are unaware of any misuse of personal or health information at this time.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesaddressesdates of birthpolicy numberssocial security numbersbank account informationSystems Affected: Email Accounts
DATA BREACH
personal informationhealth informationSensitivity Of Data: Highnamesaddressesdates of birthpolicy numberssocial security numbersbank account information
SEPTEMBER 2017
778Before Incident
Breach
01 Sep 2017Aflac
American Family Life Assurance Company of Columbus and Continental American Insurance Company

Aflac Data Breach Involving Microsoft Office 365 Email Accounts

722After Incident
CRITICAL-56
AFL230090725
The California Office of the Attorney General disclosed a data breach at Aflac, where unauthorized actors potentially accessed Microsoft Office 365 email accounts of some sales agents. The breach spanned from September 8, 2017, to May 9, 2018, though the exact number of affected individuals remains undetermined. The compromised data may have included highly sensitive personal and financial information, such as names, addresses, dates of birth, policy numbers, and Social Security numbers (SSNs). The prolonged exposure period increases the risk of identity theft, financial fraud, or misuse of the stolen data. While the breach was limited to sales agents' accounts, the nature of the exposed information—particularly SSNs—poses significant long-term risks to both employees and customers whose data may have been stored or transmitted via these accounts. The incident underscores vulnerabilities in third-party email systems and the critical need for robust monitoring to detect and mitigate unauthorized access promptly.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesaddressesdates of birthpolicy numberssocial security numbersMicrosoft Office 365 email accountsIdentity Theft Risk: High (PII exposed)
DATA BREACH
PII (Personally Identifiable Information)Number Of Records Exposed: UnknownSensitivity Of Data: HighData Exfiltration: Possiblenamesaddressesdates of birthpolicy numberssocial security numbers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Aflac ?
?
What was Aflac's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Aflac's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Aflac's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Aflac's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Aflac's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Aflac's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Aflac's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Aflac's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Aflac's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Aflac's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Aflac's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Aflac's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Aflac ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Aflac's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?