Last Update: 08/01/2026 at 2:00 PM EST

Aflac And KDDI Breaches Expose Data

Coverage from SecurityWeek, BleepingComputer, and others

Articles

25

Active Days

31

The Topic

Aflac And KDDI Breaches Expose Data topic image

Two major breaches disclosed in June and July 2026 affected millions of people in Japan. Aflac Life Insurance Japan reported the theft of personal, insurance, and some premium-transfer account information belonging to approximately 4.38 million customers and agents, while KDDI reported unauthorized access to shared ISP email infrastructure affecting at least 12.2 million email addresses and 7.6 million passwords. The incidents highlight the impact of centralized systems and third-party software vulnerabilities, while the final scope of both breaches and the extent of downstream misuse remain under investigation.

First Article: 06/28/26

Latest Article: 07/28/26

History

07/23/20260 new articles

The update sharpens the scale and attribution of both breaches: Aflac’s affected population is still 4.38 million, but KDDI’s incident is now framed as a confirmed third-party software zero-day attack on shared ISP email infrastructure. It also adds that the systems remain under investigation, with downstream misuse still unresolved.

07/22/20260 new articles

The story now includes more specific breach mechanics and quantified exposure, especially KDDI’s zero-day exploitation and confirmed password counts, alongside more detailed Aflac data loss. It also adds explicit regulatory notifications and external cybersecurity involvement, making the incidents feel more fully documented and operationally contained.

  • KDDI said a zero-day in third-party software was exploited.
  • KDDI confirmed 12.2 million email addresses and 7.6 million passwords were exposed.
  • Aflac Japan estimated 4.38 million customers and agents may be affected.
  • Aflac reported some bank-account information was exfiltrated.
  • External cybersecurity support and regulator notices are now explicit.
07/21/202618 new articles

The story has broadened from a single KDDI breach to a larger Japan-focused breach wave, with Aflac Japan now a co-equal incident and regulators explicitly in the frame. The main change is a stronger emphasis on parallel, large-scale customer data exposure and response across multiple organizations.

  • Aflac Japan disclosed a separate policyholder-portal breach.
  • Japanese regulators are now explicitly involved in the disclosures.
  • Both incidents are framed as exposing personal data and login credentials.
  • Operational response now includes suspending affected services.
  • The reporting highlights unresolved uncertainty about misuse and exposure details.
06/29/20260 new articles

No material change is evident between the two versions. The breach description, scope, response steps, and affected entities are unchanged.

06/29/20260 new articles

No material change is evident between the two versions. The breach details, affected scale, response steps, and regulatory notification remain the same.

06/29/20263 new articles

The main update is that KDDI now explicitly told affected users to reset passwords and turn on two-factor authentication, making the remediation guidance more direct and urgent. The story also expands slightly with named affected ISPs and confirmation of contact with those providers.

06/29/2026Topic Formed

KDDI disclosed a breach in a shared email system used by multiple Japanese internet service providers, with up to 14.2 million email accounts and passwords potentially exposed. The company said attackers exploited a vulnerability in third-party software, then blocked the intrusion, notified regulators, and began working with affected ISPs. The incident matters because it spans several providers and could enable account compromise if exposed credentials were usable.