{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:17.825Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Aflac breached in insurance-sector social engineering campaign; 22.6M affected","date":"2025-06-12","date_precision":"day","victim_org":"Aflac","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No public reporting attributes AI-generated voice to the Aflac intrusion.","outcomes":["Data Breach","Identity Theft"],"loss_usd":null,"loss_note":"No loss figure disclosed; Aflac offered 24 months of credit monitoring, identity theft and medical fraud protection.","records_affected":22650000,"threat_actor":"Not confirmed by Aflac; reporting points to Scattered Spider's 2025 insurance-sector campaign","summary":"Aflac detected suspicious activity on a limited number of systems on 12 June 2025 and disclosed the incident on 20 June, saying it was part of a cybercrime campaign against the insurance industry and that no ransomware was involved. The company later confirmed roughly 22.65 million individuals were affected, including customers, beneficiaries, employees and agents, with exposed data spanning names, Social Security numbers, dates of birth, driver's licence and government ID numbers, claims data and health information.","how_it_worked":"Aflac has not published the intrusion mechanics beyond describing a sophisticated cybercrime group and an industry-wide campaign, so the vector here is characterised from the campaign rather than from Aflac's own disclosure. Google Threat Intelligence, warning insurers during the same weeks, told the sector to pay particular attention to social engineering attempts against help desks and call centres, the route the same crews had used against retail and hospitality: a phone call impersonating staff to obtain credential or MFA resets, then rapid data collection with no malware deployed.","lessons":"Identity verification standards for help desks and call centres, applied to both employee and customer channels, is the control the sector was explicitly warned to strengthen.","confidence":"Confirmed","sources":[{"title":"Aflac discloses breach amidst Scattered Spider insurance attacks","url":"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/","publisher":"BleepingComputer"},{"title":"22M Affected by Aflac Data Breach","url":"https://www.securityweek.com/22-million-affected-by-aflac-data-breach/","publisher":"SecurityWeek"},{"title":"Aflac confirms June data breach affecting over 22 million customers","url":"https://securityaffairs.com/186144/data-breach/aflac-confirms-june-data-breach-affecting-over-22-million-customers.html","publisher":"Security Affairs"},{"title":"Aflac Data Breach: PHI of At Least 13.9 Million Individuals Compromised","url":"https://www.hipaajournal.com/aflac-data-breach/","publisher":"The HIPAA Journal"},{"title":"3 key takeaways from the Scattered Spider attacks on insurance firms","url":"https://www.bleepingcomputer.com/news/security/3-key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/","publisher":"BleepingComputer"}],"entry_type":"incident","slug":"2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-aflac-breached-in-insurance-sector-social-engineering-campaign-22-6m-aff"}]}