← Incident database

aflac-japan-2026 · Disclosed 2026-06-30

Aflac Japan: ordinary-looking requests and bulk data queries

Aflac reported missed detection of ordinary-looking requests and inadequate bulk-query controls. Personal information of about 4.4 million customers leaked, including bank-account information for about 220,000 of them.

Implementation

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Aflac described insufficient access and query controls; reviews and penetration tests had not anticipated the method.

    [s1]4. 発生原因
  • Reported fact

    The disclosed scope was about 4.4 million customers, including about 220,000 with bank-account information, and about 40,000 agencies. The customer subsets are not additive.

    [s1]2. 漏えいした個人情報

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Aflac suspended related systems on June 25 and announced stronger authentication, query authorization, bulk-access controls, and security testing.

    [s1]1. 経緯 / 5. 再発防止策

Evidence relevant to prevention

Operational controls to inspect

Inspect server-side query authorization and retrieval limits, and test detection of abnormal volume with synthetic data.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Specific requests, products, and CVEs are undisclosed; this does not establish neglected library patches or a specific SQL-injection technique.

Sources

  1. [s1] アフラック生命保険 · Primary source

    当社システムに対する不正アクセスの発生および情報漏えいに関する調査結果と再発防止策について ↗

    Published 2026-07-31 · Reviewed 2026-10-02