Aflac And KDDI Breaches Expose Data
Coverage from SecurityWeek, BleepingComputer, and others
Articles
25
Active Days
31
The Topic

Two major breaches disclosed in June and July 2026 affected millions of people in Japan. Aflac Life Insurance Japan reported the theft of personal, insurance, and some premium-transfer account information belonging to approximately 4.38 million customers and agents, while KDDI reported unauthorized access to shared ISP email infrastructure affecting at least 12.2 million email addresses and 7.6 million passwords. The incidents highlight the impact of centralized systems and third-party software vulnerabilities, while the final scope of both breaches and the extent of downstream misuse remain under investigation.
First Article: 06/28/26
Latest Article: 07/28/26
Summary
- Aflac Life Insurance Japan said approximately 4.38 million customers and agents may be affected by data exfiltration from a policyholder portal and related systems.
- Aflac reported exposure of personal and insurance information, with premium-transfer account data involved for roughly 230,000 people; it said credit card data was not accessed.
- KDDI said a zero-day vulnerability in unnamed third-party software enabled access to email infrastructure shared by five Japanese ISPs.
- KDDI reported compromise of 12.2 million email addresses and 7.6 million passwords, with coordinated mandatory password resets underway.
- The incidents caused service disruption and containment actions, including system suspensions, attacker eviction, and reviews of affected software and infrastructure.
- Both organizations said investigations and notifications to relevant Japanese authorities were ongoing.
History
The update sharpens the scale and attribution of both breaches: Aflac’s affected population is still 4.38 million, but KDDI’s incident is now framed as a confirmed third-party software zero-day attack on shared ISP email infrastructure. It also adds that the systems remain under investigation, with downstream misuse still unresolved.
The story now includes more specific breach mechanics and quantified exposure, especially KDDI’s zero-day exploitation and confirmed password counts, alongside more detailed Aflac data loss. It also adds explicit regulatory notifications and external cybersecurity involvement, making the incidents feel more fully documented and operationally contained.
