22 Million Affected By Aflac Data Breach (securityweek.com) 26
An anonymous reader quotes a report from SecurityWeek: Insurance giant Aflac is notifying roughly 22.65 million people that their personal information was stolen from its systems in June 2025. The company disclosed the intrusion on June 20, saying it had identified suspicious activity on its network in the US on June 12 and blaming it on a sophisticated cybercrime group. The company said it immediately contained the attack and engaged with third-party cybersecurity experts to help with incident response. Aflac's operations were not affected, as file-encrypting ransomware was not deployed.
[...] The compromised information, the insurance giant says, includes names, addresses, Social Security numbers, dates of birth, driver's license numbers, government ID numbers, medical and health insurance information, and other data. "The review of the potentially impacted files determined personal information associated with customers, beneficiaries, employees, agents, and other individuals related to Aflac was involved," Aflac said in a notification (PDF) on its website. The company is providing the affected individuals with 24 months of free credit monitoring, identity theft protection, and medical fraud protection services.
[...] The compromised information, the insurance giant says, includes names, addresses, Social Security numbers, dates of birth, driver's license numbers, government ID numbers, medical and health insurance information, and other data. "The review of the potentially impacted files determined personal information associated with customers, beneficiaries, employees, agents, and other individuals related to Aflac was involved," Aflac said in a notification (PDF) on its website. The company is providing the affected individuals with 24 months of free credit monitoring, identity theft protection, and medical fraud protection services.
Re: Obligatory... (Score:2)
Re: (Score:2)
*waves to rsilvergun*
press 9 (Score:2)
Re:press 9 to hear a duck (Score:1)
Moooo
"Damned hackers!"
Does aflac cover data breaches? (Score:3)
I know if I break my arm aflac will come give me a check, but will it give me a check when it breaks my privacy?
Re: (Score:2)
I know if I break my arm aflac will come give me a check,
They might not, have you ever tried?
Re: (Score:2)
I'm just saying that's their whole sales pitch. I personally decline this kind of insurance as I believe it is not a wise investment when compared to the risk you are hedging against.
Re: Does aflac cover data breaches? (Score:2)
How much are thry getting from insurance against data breaches?
Re: (Score:2)
With data breeches and identity theft, if you break your arm, someone else is getting your check.
I'm sure there must be: (Score:1)
B. Some kind of tax.
C. Some government backed costly certification.
D. A new, costly, proprietary AI tool
E. All of the above.
... that we can hurriedly slap in place to fix the internets!
Re: (Score:1)
F. Kick them in the duck
It was a sophisticated cyberattack (Score:2)
Why only 24 months of monitoring (Score:2)
when the information that was stolen cannot be changed. This should be a lifetime of free monitoring even after you move to a new insurance company.
Re: (Score:2)
These "credit monitoring" services they offer with every data breach are completely worthless. So after you lost my personal information, your solution is to tell me to have a different third party monitor my information? It's a fig-leaf to avoid actually paying for damages.
I also get data breach notices on a close to annual basis these days. I'm sure the personal info of almost every adult in the Western world is out there on the dark web by now.
Re: (Score:2)
I have a lifetime of monitoring. Every year someone gets breached and gives me monitoring.
Re: (Score:2)
Too late (Score:2)
Re: (Score:2)
Re: (Score:1)
No, they took 6 months to publicise the event.
However, they still took over a week to disclose the breach to appropriate bodies, which I'm sure is 5 days more than it should have been. At least, that's what the law is in UK.
No one's said it yet? (Score:2)
Palantir already has all of that information (Score:3)
I don't think this will make our surveillance state any worse.
What does Aflac run on? (Score:2)
Aflac Drives Consolidation with the Falcon Platform, Eliminating 15 Point Security Tools in Three Years [crowdstrike.com]
Is it not illegal to use SSN as authentication? (Score:2)