LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Aflac Japan Discloses Breach Impacting 4.38M Customers

CRITICAL severityReportedHow we verify

Aflac Japan Discloses Breach Impacting 4.38M Customers: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 30, 2026
Aflac Japan Discloses Breach Impacting 4.38M Customers

Reported June 30, 2026. Approximately 4.38M people affected.

CRITICAL
Severity
4.38M
People affected
7
Data types exposed
June 30, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Aflac Japan disclosed a data breach on June 30, 2026, that exposed the personal information of 4.38 million customers, including names, addresses, phone numbers, and dates of birth. Customers are advised to check their accounts or contact Aflac Japan to confirm whether their information was affected and to monitor for any unauthorized activity.

Severity & verification
CRITICAL severityReported
Exposes financial data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
4.38M accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Aflac Japan disclosed on June 30, 2026, that unauthorized access to its systems between June 15 and June 25 affected policyholder portal data for approximately 4.38 million customers and agents. The company stated that the incident involved personal information, names, addresses, phone numbers, dates of birth, insurance account information, and bank account information. No ransomware was reported, and the firm has notified authorities while beginning direct contact with affected individuals.

The scale of the incident places it among larger known exposures in the Japanese insurance sector. Public details remain limited to the access window, the number of records involved, and the categories of data listed by the company.

Breaking down the breach

Aflac Japan reported that attackers gained access to its Japan subsidiary systems over a ten-day period in June 2026. The breach centered on the policyholder portal and touched records belonging to roughly 4.38 million customers and agents. The company has confirmed that the listed data categories were present in the accessed systems but has not released further technical details such as entry method or volume of data removed.

Authorities were notified, and the company began outreach to individuals whose information was stored in the portal. No additional claims about data publication or further access have been made public at this stage.

How a breach like this happens

Incidents involving unauthorized access to customer portals commonly begin with the exploitation of remote services, stolen credentials, or unpatched software that allows initial entry. Once inside, an actor may move laterally to reach databases or file stores that hold account records.

Insurance platforms frequently maintain large volumes of structured customer data in centralized systems to support policy management and claims processing. Access to such portals can therefore expose multiple categories of personal and financial information in a single event.

Aflac Japan and its sector

Aflac Japan operates as a major provider of insurance products in Japan, maintaining records for millions of policyholders. Organizations in this sector routinely collect and store names, contact details, dates of birth, policy numbers, and linked bank account information to administer coverage and process payments.

A breach at this scale is consequential because the data types involved support identity verification and financial transactions. Japanese insurers are subject to data-protection expectations that require notification when such records are accessed without authorization.

What was likely exposed

Aflac Japan has stated that the accessed systems contained personal information including names, addresses, phone numbers, dates of birth, insurance account information, and bank account information. The company has not published a more granular inventory of fields or confirmed whether every record included every listed element.

Exact contents of any extracted files therefore remain unconfirmed beyond the categories already disclosed. Organizations of this type typically retain additional internal fields such as policy terms or claim histories, but those specifics have not been released in connection with this incident.

The real-world impact

Individuals whose records were accessed face the possibility of increased unsolicited contact and the potential for misuse of bank or insurance details in fraudulent transactions. Monitoring account statements and credit reports can surface activity that requires follow-up with the relevant institutions.

For the organization, the incident triggers regulatory notifications and direct customer communication, along with the operational cost of reviewing access logs and strengthening portal controls. Long-term effects depend on whether the data appears in later public disclosures, which has not been reported to date.

Were you affected?

Aflac Japan has indicated it is contacting affected customers and agents directly. Individuals who hold policies with the company can review any correspondence received and verify account activity through official channels.

Running a free exposure scan of your email address against known breach data provides one way to check whether your information has appeared in publicly discussed incidents. Additional steps include reviewing bank and insurance statements for anomalies and updating passwords on any linked accounts.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyAflac Japan security record
68/100
DoxxScan™ · Moderate doxx risk
D+ 59Weak record

1 reported incident on record.

See Aflac Japan’s full breach history →

More recent breaches

DentaQuest Data Breach (2026)May 23, 2026BWH Hotels (Best Western) Discloses 6-Month Reservation System BreachMay 8, 2026Medtronic Notifies 3.8M+ on ShinyHunters BreachApril 24, 2026AssuranceAmerica Breach Exposes 6.9M Driver's LicensesJuly 8, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Aflac Japan Discloses Breach Impacting 4.38M Customers →

Source: BleepingComputer

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram