Aflac, one of the USA’s largest insurers, is the latest to fall “under siege” to hackers

Aflac, one of the USA's largest insurers, is the latest to fall "under siege" to hackers

The Wall Street Journal reports that Aflac is investigating a breach that may have exposed claims information, health details, Social Security numbers, and other personal data.

That’s the kind of sensitive personal information you would expect your insurer to protect, not accidentally hand over to cybercriminals.

According to Aflac, the attack came from a “highly sophisticated and well-known group that has the insurance industry under siege”

Sign up to our free newsletter.
Security news, advice, and tips.

Under siege? Sounds like they’ve been watching too many Steven Seagal movies (note to self: one Steven Seagal movie is too many…)

But what’s more upsetting than that is the claim that the hackers are “highly sophisticated.”

Is that because they exploited a zero day vulnerability? No.

Is it because they have an evil genius on their team who created some undetectable malware? Nope.

Chances are that this is the same hacking gang (Scattered Spider) behind recent data breaches at Marks & Spencer, Victoria’s Secret and other retailers, as well as attacks targeting insurance firms across the USA.

Scattered Spider uses the “highly sophisticated” method of phoning a support desk claiming to be a locked out employee, and asking to be granted access to the network. Maybe with a slice of phishing, SIM swapping, and multi-factor authentication (MFA) bombing.

Really not that sophisticated at all…


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and hosts the popular "Smashing Security" podcast. Follow him on LinkedIn, Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.