AFLAC INCORPORATED
ent_019e0d4db7ba8a33bc95cc496dfdb210
Disclosures
12
SEC 10-K Item 1C · State AG · SEC 8-K · HHS OCR · 10 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
2,055,982
as filed · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AFLAC INCORPORATED
- Normalized
- aflac— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N0B7DOGLXWPP39
- SEC EDGAR CIK
- 0000004977
- Domain
- aflac.com
Disclosure history (12)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-25
Item 1C disclosure describes the registrant's cybersecurity risk management, strategy, and governance. The Board delegates oversight to the Audit and Risk Committee. The GCISO manages the global information security program, which includes an incident response plan, annual risk assessments, and third-party risk reviews. No specific cybersecurity incident or breach is reported in this filing.
- ⭐Texas State AGas victim2025-12-22
Aflac Incorporated based in Columbus, Georgia, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-12-04 and reported on 2025-12-22. 2,055,982 Texas residents were affected. 22,653,844 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Medical Information;Health Insurance Information;Other;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail;Email.
- 🐻California State AGas victim2025-12-19
Aflac Incorporated detected a security incident on June 12, 2025, involving unauthorized access to a limited number of systems. The incident was contained within hours. Personal information, potentially including health-related identifiers, may have been accessed. Aflac engaged third-party experts, notified law enforcement, locked impacted accounts, and is offering 24 months of credit and identity monitoring services.
- 🦬Montana State AGas victim2025-12-19
Aflac Incorporated reported a data breach to the Montana Attorney General. The breach was reported on 2025-12-19. The breach occurred on 06/12/2025. 118,478 Montana residents were affected.
- 🌽Iowa State AGas victim2025-12-19
Aflac Incorporated, a financial services sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-12-19.
- 🌴South Carolina State AGas victim2025-07-14
Aflac Incorporated reported a security incident detected on June 12, 2025, involving unauthorized access to a limited number of systems. The breach impacted personal information of policyholders, including identity and health data. Aflac contained the incident within hours, notified federal law enforcement, engaged third-party cybersecurity experts, and offered 24 months of credit monitoring and identity theft protection services to affected individuals.
- 🌲Washington State AGas victim2025-07-11
Aflac Incorporated, a business sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2025-06-12 and filed notice on 2025-07-11. 432,025 Washington residents were affected. 29 days elapsed between awareness and notification.
- 🦫Oregon State AGas victim2025-07-11
Aflac Incorporated reported a data breach to the Oregon Attorney General. The breach was reported on 2025-07-11. The breach occurred during 6/12/2025 - 6/12/2025. 1 individuals were affected.
- 💎Delaware State AGas victim2025-06-20
Aflac Incorporated reports a security incident detected on June 12, 2025, involving unauthorized access to a limited number of systems. The incident was contained within hours. Aflac notified federal law enforcement and engaged third-party cybersecurity experts. Affected individuals may have had personal information, including government IDs and health data, exposed. Aflac is offering 24 months of free credit monitoring and identity theft protection via CyEx Medical Shield. This filing serves as a supplemental notice to prior communications.
- FEDERALSEC 8-Kas victim2025-06-20
Aflac Incorporated (CIK 0000004977) filed an 8-K on June 20, 2025, reporting unauthorized network access identified on June 12, 2025. The company contained the intrusion within hours, confirmed no ransomware was involved, and engaged third-party cybersecurity experts. The investigation into the scope is ongoing, but potentially impacted files include claims data, health information, and Social Security Numbers for customers, employees, and agents in the U.S. Free credit monitoring is being offered.
- GAHHS OCRas victim2018-05-29
AFLAC (Health Plan, GA) reported to HHS on 2018-05-29 a Hacking/IT Incident affecting 10,396 individuals. Multiple business associates were victims of an email phishing scheme that compromised ePHI including names, addresses, birthdates, Social Security numbers, clinical information, claims data, and health insurance information. A forensic investigation was conducted; free credit monitoring was offered. OCR provided technical assistance and obtained corrective-action assurances. Breached information located on Email.
- GAHHS OCRas victim2016-05-20
Aflac reported to HHS on 2016-05-20 a Unauthorized Access/Disclosure affecting 930 individuals. Breached information located on Paper/Films. Due to a vendor error, Aflac erroneously sent correspondence containing PHI (names, policy numbers, coverage types, premiums, and 6 SSNs) to the wrong customers. Aflac retrained employees, revised policies, sanctioned the responsible manager, terminated vendor contracts, and notified HHS and affected individuals.