AFLAC INCORPORATED
ent_019e0d4db7ba8a33bc95cc496dfdb210
Disclosures
24
State AG · HHS OCR · SEC 8-K · 15 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
22,653,844
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AFLAC INCORPORATED
- Normalized
- aflac— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300N0B7DOGLXWPP39
- SEC EDGAR CIK
- 0000004977
- Domain
- aflac.com
Disclosure history (24)newest first
- Texas State AGas victim2025-12-22
Aflac Incorporated based in Columbus, Georgia, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-12-04 and reported on 2025-12-22. 2,055,982 Texas residents were affected. 22,653,844 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Medical Information;Health Insurance Information;Other;Date of Birth. Consumers were notified via Posted at company website or special website;U.S. Mail;Email.
- California State AGas victim2025-12-19
Aflac Incorporated detected a security incident on June 12, 2025, involving unauthorized access to a limited number of systems. The incident was contained within hours. Personal information, potentially including health-related identifiers, may have been accessed. Aflac engaged third-party experts, notified law enforcement, locked impacted accounts, and is offering 24 months of credit and identity monitoring services.
- Rhode Island State AGas victim2025-12-19
Aflac Incorporated filed a supplemental breach notification with the Rhode Island Attorney General regarding a security incident detected on June 12, 2025. The incident impacted approximately 61,869 Rhode Island residents, exposing names, contact info, DOB, SSN/Tax ID, and health/insurance data. Aflac contained the breach, notified law enforcement, and is offering 24 months of credit monitoring. Notifications to residents began December 19, 2025.
- Montana State AGas victim2025-12-19
Aflac Incorporated detected unauthorized access to its systems on June 12, 2025. The incident was contained within hours. Personal information, potentially including health insurance plan numbers and medical record numbers, may have been impacted. Aflac notified law enforcement, reset passwords, and is offering 24 months of credit monitoring and identity theft protection.
- Iowa State AGas victim2025-12-19
Aflac Incorporated filed a supplemental security breach notification with the Iowa Attorney General on December 19, 2025. The incident, initially detected on June 12, 2025, involved unauthorized access to systems containing personal and health information of approximately 239,076 Iowa residents. Data exposed included names, DOBs, SSNs, and PHI. Aflac contained the incident, notified law enforcement, and is offering 24 months of credit monitoring.
- GEORGIAHHS OCRas victim2025-08-08
Aflac Incorporated reported to HHS on 2025-08-08 a Hacking/IT Incident affecting 13,924,906 individuals. Breached information located on Network Server.
- South Carolina State AGas victim2025-07-14
Aflac Incorporated detected a security incident on June 12, 2025, involving unauthorized access to a limited number of systems. An unauthorized actor obtained personal information, including potential health insurance and financial data. The incident was contained within hours. Aflac engaged third-party cybersecurity experts, notified federal law enforcement, locked impacted accounts, and reset passwords. The company is offering 24 months of credit monitoring and identity theft protection to affected individuals. This notice serves as an update to a previous announcement made in June 2025.
- Washington State AGas victim2025-07-11
Aflac Incorporated reported a security incident to the Washington Attorney General on December 19, 2025, supplementing a June 2025 notice. The incident, discovered on June 12, 2025, involved unauthorized access via social engineering/phishing. Approximately 432,025 Washington residents were affected, with data including names, SSNs, DOBs, and PHI. Aflac contained the incident, engaged forensic experts, notified law enforcement, and offered 24 months of credit monitoring.
- Oregon State AGas victim2025-07-11
Aflac Incorporated reported a data breach to the Oregon Attorney General. The breach was reported on 2025-07-11. The breach occurred during 6/12/2025 - 6/12/2025. 1 individuals were affected.
- Illinois State AGas victim2025-07-01
AFLAC INCORPORATED filed a data-breach notice with the Illinois Attorney General in July 2025 (case 25-07-307). The register records the breach as discovered on June 12, 2025. Personal information types reported: drivers license, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Delaware State AGas victim2025-06-20
Aflac Incorporated detected a security incident on June 12, 2025, involving unauthorized access to a limited number of systems. The incident was contained within hours. An unauthorized actor obtained personal information, including potential health-related identifiers, on June 12, 2025. Aflac determined on December 4, 2025, that specific individuals' information was impacted. Response actions included engaging third-party cybersecurity experts, notifying federal law enforcement, locking impacted accounts, and resetting passwords. Aflac is offering 24 months of credit monitoring and identity theft protection services.
- FEDERALSEC 8-Kas victim2025-06-20
Aflac Incorporated filed an 8-K on June 20, 2025, reporting unauthorized network access identified on June 12, 2025. The company believes it contained the intrusion within hours, confirmed no ransomware was involved, and engaged third-party cybersecurity experts. The investigation into the scope is ongoing, but potentially impacted files include claims data, health information, and Social Security Numbers for customers, employees, and agents in the U.S. Free credit monitoring is being offered.
- Massachusetts State AGas victim2021-03-03
Aflac Incorporated reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-03-03. 9 Massachusetts residents were affected. The report records the breach type as paper.
- Indiana State AGas victim2021-03-01
Aflac Incorporated reported a data breach to the Indiana Attorney General. The breach occurred on 2021-01-29 and was reported on 2021-03-01. 7 Indiana residents were affected. 2,635 individuals affected in total.
- Illinois State AGas victim2021-01-01
AFLAC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-458). The register records the breach as discovered on November 8, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2021-01-01
AFLAC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-530). The register records the breach as discovered on November 8, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GEORGIAHHS OCRas victim2019-12-16
AFLAC reported to HHS on 2019-12-16 a Unauthorized Access/Disclosure affecting 1601 individuals. Breached information located on Network Server. A technical error allowed PHI to be viewable on its online web portal.
- Illinois State AGas victim2019-01-01
AFLAC filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-093). The register records the breach as discovered on May 29, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2019-01-01
AFLAC filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-500). The register records the breach as discovered on August 30, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2018-09-28
Aflac reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-09-28. 3 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2018-09-28
Aflac notified the NH Attorney General of unauthorized access to third-party hosted Office365 accounts between Sept 2017 and May 2018. Discovered Aug 2018. Affected data included names, addresses, DOB, SSNs, and policy info. 11 NH residents notified on Sept 28, 2018, offered credit monitoring.
- GEORGIAHHS OCRas victim2018-05-29
AFLAC (Health Plan, GA) reported to HHS on 2018-05-29 a Hacking/IT Incident affecting 10,396 individuals. Multiple business associates were victims of an email phishing scheme that compromised ePHI including names, addresses, birthdates, Social Security numbers, clinical information, claims data, and health insurance information. A forensic investigation was conducted; free credit monitoring was offered. OCR provided technical assistance and obtained corrective-action assurances. Breached information located on Email.
- Massachusetts State AGas victim2016-12-22
Aflac reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-12-22. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Massachusetts State AGas victim2016-10-03
Aflac reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2016-10-03. 1 Massachusetts residents were affected. The report records the breach type as electronic.