Aflac And KDDI Breaches Expose Data
Coverage from BleepingComputer, Captain Compliance, and others

Two major breaches disclosed in June and July 2026 affected millions of people in Japan.
Aflac Life Insurance Japan reported the theft of personal, insurance, and some premium-transfer account information belonging to approximately 4.38 million customers and agents, while KDDI reported unauthorized access to shared ISP email infrastructure affecting at least 12.2 million email addresses and 7.6 million passwords. The incidents highlight the impact of centralized systems and third-party software vulnerabilities, while the final scope of both breaches and the extent of downstream misuse remain under investigation.
The update sharpens the scale and attribution of both breaches: Aflac’s affected population is still 4.38 million, but KDDI’s incident is now framed as a confirmed third-party software zero-day attack on shared ISP email infrastructure. It also adds that the systems remain under investigation, with downstream misuse still unresolved.
The story now includes more specific breach mechanics and quantified exposure, especially KDDI’s zero-day exploitation and confirmed password counts, alongside more detailed Aflac data loss. It also adds explicit regulatory notifications and external cybersecurity involvement, making the incidents feel more fully documented and operationally contained.
