HackingCustomer Data InvolvedEmployee Data InvolvedPIIIDENTITY_BASICHEALTH_BASICLowContained
AFLAC INCORPORATED
bd_548ca82777ea0c3a · schema v1 · pii pii-v1
Full breach record for AFLAC INCORPORATED →Aflac Incorporated detected a security incident on June 12, 2025, involving unauthorized access to a limited number of systems. The incident was contained within hours. Personal information, potentially including health-related identifiers, may have been accessed. Aflac engaged third-party experts, notified law enforcement, locked impacted accounts, and is offering 24 months of credit and identity monitoring services.
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a23cab5d40b7f640Montana State AGfiled 2025-12-19Verified
- bd_f5f14337d4045dd3Iowa State AGfiled 2025-12-19Verified
- bd_0cb64704c1e4bbbfTexas State AGfiled 2025-12-22(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-616010
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2025
- Raw hash
- d103ee5aabee7469d49c5947229cfcc074366d234e20b220b4c78594e0a4f3b5
Reporting entity
- Name
- AFLAC INCORPORATEDnorm: aflac
- Domain
- aflac.com
Victim entity
- Name
- AFLAC INCORPORATEDnorm: aflac
- Domain
- aflac.com
Incident
- Discovered
- Jun 12, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement
Compliance
- Time to disclose
- 27 weeks(190 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.