
Aflac, the largest supplemental insurance provider in the United States, revealed on Friday that it was targeted in a sophisticated cyberattack believed to be part of a broader campaign affecting multiple insurance firms across the country.
In a statement, the Fortune 500 company confirmed that personal and health-related information belonging to customers, employees, and agents may have been compromised. However, Aflac emphasized that the attack did not involve ransomware and that its core systems and operations remain unaffected.
“We promptly initiated our cyber incident response protocols and stopped the intrusion within hours,” Aflac said in a press release. “Our business remains operational, and we continue to serve our customers, underwrite policies, and process claims as usual.”
The breach was reported to the U.S. Securities and Exchange Commission (SEC), with Aflac disclosing that the stolen documents may include sensitive data such as health records, Social Security numbers, and other personally identifiable information. To assist in the investigation, the company has enlisted external cybersecurity experts to assess the full scope of the exposure.
Although Aflac did not attribute the incident to a specific group, security analysts believe the breach aligns with tactics commonly used by Scattered Spider, a notorious cybercrime group also known as 0ktapus, UNC3944, and Muddled Libra. The group has gained notoriety for targeting major corporations through phishing, SIM swapping, and multi-factor authentication (MFA) fatigue attacks.
John Hultquist, Chief Analyst at Google’s Threat Intelligence Group (GTIG), noted that Scattered Spider has recently been focusing on breaching U.S. insurance companies, warning that the sector should be “on high alert.” He advised organizations to bolster defenses against social engineering attempts, particularly at help desks and call centers.
The campaign’s fallout has extended beyond Aflac. In recent weeks, both Philadelphia Insurance Companies and Erie Insurance experienced significant service disruptions after detecting unauthorized access, further suggesting a coordinated assault on the insurance industry.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543