JAFLAC A.I CyberSecurity Scoring
JAFLAC
Company Information
Website:http://www.jaflac.com.au
Employees number:1
Number of followers:31
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:jaflac.com.au
JAFLAC Risk Score (AI oriented)
Between 600 and 649
JAFLACIT Services and IT Consulting
Updated:
31/07/2026
31/07/2026
647/1000
Poor
Caa
JAFLAC Global Score (TPRM)
xxxx
JAFLACIT Services and IT Consulting
Score locked

JAFLACPoor
Current Score
647Caa (POOR)
01000
1 incidents
-105 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
649
AUGUST 2026
649
JULY 2026
750
Breach
30 Jun 2026 • JAFLAC
Aflac Life Insurance Japan Ltd.: Aflac Data Breach: Japan Arm Hit for 4.38M in 2026
Aflac Japan Suffers Second Major Data Breach in 13 Months, Exposing 4.38 Million Customers
645
CRITICAL-105
JAF1785487197
Aflac Japan Suffers Second Major Data Breach in 13 Months, Exposing 4.38 Million Customers
Aflac’s Japanese subsidiary, Aflac Life Insurance Japan Ltd., disclosed a cyberattack on June 30, 2026, revealing that hackers accessed its systems for ten days from June 15 to June 25 before detection. The breach compromised the personal data of 4.38 million customers, marking the second major cyber incident for the insurance giant in just over a year.
### Scope and Impact of the Breach
The attack targeted Aflac Yoriso Net, the company’s customer portal, along with connected systems. Exposed data includes:
- Personal identifiers: Names, addresses, phone numbers, dates of birth, and gender
- Account details: Security credentials and insurance policy information
- Financial data: Bank account numbers for a subset of customers
Aflac confirmed that no misuse of the stolen data has been detected, though the company is still mapping the full extent of the exposure. Affected individuals will receive notification letters once the investigation concludes.
### Timeline of the Attack
- June 10–15, 2026: Earliest reported unauthorized access
- June 15–25, 2026: Confirmed intrusion window
- June 25, 2026: Aflac Japan discovers the breach, suspends affected systems
- June 25–30, 2026: Internal investigation with third-party cybersecurity experts
- June 30, 2026: Public disclosure via SEC filing and Japanese customer notice
The five-day gap between discovery and disclosure aligns with Japan’s regulatory framework, which does not impose a fixed public notification deadline like the EU’s GDPR.
### Regulatory and Legal Fallout
As a U.S.-listed company, Aflac filed a Form 8-K with the SEC, emphasizing that the breach was confined to its Japanese operations. The company also notified Japan’s Financial Services Agency (FSA), though no fines or enforcement actions have been announced.
The incident follows Aflac’s 2025 U.S. breach, which exposed 22.65 million records five times the scale of the Japan attack through a social engineering attack. While Aflac has not attributed the 2026 breach to a specific group, reporting links the 2025 incident to Scattered Spider, a cybercrime collective known for targeting insurers via MFA fatigue and help-desk impersonation.
### Broader Industry Implications
The breach underscores persistent vulnerabilities in the insurance sector, where decentralized IT systems and high-pressure customer service environments create opportunities for social engineering attacks. With Scattered Spider and similar groups actively targeting insurers, the incident raises questions about the effectiveness of existing defenses, even for well-resourced companies.
Aflac’s stock has not shown a confirmed reaction to the disclosure, but the reputational and legal risks remain significant. The company’s $17.16 billion in 2025 revenue and 50 million policyholders in Japan make it a prime target, and the breach could accelerate regulatory scrutiny in Japan and beyond.
### Comparison to Other 2026 Breaches
While substantial, the Aflac Japan breach is smaller than some of 2026’s largest incidents, including:
- KDDI (Japan): 12.2 million email addresses and 7.6 million passwords exposed via a third-party zero-day
- AT&T (2024): 73 million records leaked, leading to a $177 million class-action settlement
The Aflac breach’s inclusion of bank account details heightens the risk of follow-up fraud, particularly through phishing and unauthorized withdrawals.
### Unanswered Questions
- Attribution: No group has been officially named, though circumstantial evidence points to Scattered Spider’s playbook.
- Financial Impact: Aflac has not disclosed potential costs, but litigation and remediation expenses could align with the $4.44 million global average for data breaches (per IBM’s 2025 report).
- Long-Term Response: The FSA may tighten reporting requirements for Japanese insurers, while U.S. regulators could scrutinize Aflac’s security posture in future filings.
The incident serves as a reminder of the insurance sector’s appeal to cybercriminals and the challenges of defending against attacks that exploit human, rather than technical, vulnerabilities.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for JAFLAC ??
What was JAFLAC's A.I Rankiteo Cyber Score in August 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in July 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in June 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in May 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in April 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in March 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in February 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in January 2026 ??
What was JAFLAC's A.I Rankiteo Cyber Score in December 2025 ??
What was JAFLAC's A.I Rankiteo Cyber Score in November 2025 ??
What was JAFLAC's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on JAFLAC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with JAFLAC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view JAFLAC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?