aflac-japan-2026 · Disclosed 2026-06-30
Aflac Japan: ordinary-looking requests and bulk data queries
Aflac reported missed detection of ordinary-looking requests and inadequate bulk-query controls. Personal information of about 4.4 million customers leaked, including bank-account information for about 220,000 of them.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Aflac described insufficient access and query controls; reviews and penetration tests had not anticipated the method.
[s1]4. 発生原因 - Reported fact
The disclosed scope was about 4.4 million customers, including about 220,000 with bank-account information, and about 40,000 agencies. The customer subsets are not additive.
[s1]2. 漏えいした個人情報
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Aflac suspended related systems on June 25 and announced stronger authentication, query authorization, bulk-access controls, and security testing.
[s1]1. 経緯 / 5. 再発防止策
Evidence relevant to prevention
Operational controls to inspect
Inspect server-side query authorization and retrieval limits, and test detection of abnormal volume with synthetic data.
Editorial assessment; not a determination of liability. [s1]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
Specific requests, products, and CVEs are undisclosed; this does not establish neglected library patches or a specific SQL-injection technique.
Sources
[s1] アフラック生命保険 · Primary source
当社システムに対する不正アクセスの発生および情報漏えいに関する調査結果と再発防止策について ↗Published 2026-07-31 · Reviewed 2026-10-02