Personal info of customers compromised? Insurer Aflac probes data breach incident by 'sophisticated cybercrime group'

Aflac said it was unable to determine the total number of affected individuals until a review, which is in its early stages, is completed

Sudeshna Ghoshal
Updated20 Jun 2025, 10:07 PM IST
Personal info of customers compromised? Insurer Aflac probes data breach incident by 'sophisticated cybercrime group'
Personal info of customers compromised? Insurer Aflac probes data breach incident by 'sophisticated cybercrime group'(AP)

Aflac revealed on Friday that it had experienced a cybersecurity breach by a “sophisticated cybercrime group,” in which personal information of its customers may have been compromised, making it the latest insurer to fall victim to a cyberattack.

Without specifying a name, the health and life insurance company, in its statement said the breach — detected on June 12 — was carried out by a “sophisticated cybercrime group,” that used "social engineering tactics".

Also Read | $90 million gone: Who hacked Nobitex, Iran’s largest cryptocurrency exchange?

Health insurers have been facing increased cybersecurity risks recently with UnitedHealth's breach being the most notable example impacting 100 million people last year.

What is 'social engineering tactic'?

“Social engineering tactic” which Aflac claimed has been used by hackers to worm their way into the insurer's network, involves tricking someone into sharing security details to break into a network. It’s a hallmark of Scattered Spider attackers, who are known to pose as tech support to infiltrate big corporations, mentions a report by CNN.

How many people are affected in Aflac cybersecurity breach?

While Aflac said it was unable to determine the total number of affected individuals, it noted that claims information, health information, Social Security numbers and other personal information might have been compromised.

Also Read | Hackers say they wiped out USD 90 million from Iran crypto-currency exchange

The insurer, also claimed it was able to stop the intrusion within hours and has reached out to third-party cybersecurity experts to investigate into the incident.

“We promptly initiated our cyber incident response protocols and stopped the intrusion within hours,” CBS News reported, citing Aflac's statement.

'Cybercrime campaign against the insurance industry'

Earlier this month, two insurers, Erie Insurance and Philadelphia Insurance Companies had announced that their networks were hacked.

Aflac's cybersecurity breach is the latest case in the list of health insurance companies facing security breaches.

"This was part of a cybercrime campaign against the insurance industry," Aflac said in its statement issued on Friday.

Also Read | Google uncovers malware campaign by China-linked hackers using Calendar events

Aflac is one of the largest providers of supplemental health insurance in the US for medical expenses that the primary provider does not cover.

Stay updated with the latest Trending, India , World and United States news. Follow all the latest updates on Israel Iran Conflict here on Livemint.

Business NewsNewsUs NewsPersonal info of customers compromised? Insurer Aflac probes data breach incident by 'sophisticated cybercrime group'
MoreLess