Aflac Japan said on Jan. 11, 2023, that data on 1,323,468 customers of its cancer insurance products had been posted to a data-breach forum. The records, about 3.2 million in total, held surnames in kana, age, gender, policy numbers, product types, coverage amounts and premiums. The cause, the company said, was a vulnerability in a file transfer server at a U.S.-based subcontractor of a vendor it used for marketing. The contractor had been accessed from Jan. 7; Aflac Japan learned of the posting on Jan. 9.
Zurich Insurance Japan disclosed the same week that a package of data on 757,463 current and former Super Automobile Insurance customers had surfaced on a hacking forum around Jan. 8. Its fields were surname in katakana, gender, birth date, email address, policy number, customer identifier and vehicle details. Zurich also attributed the loss to a third-party contractor and said its own systems were not compromised.
One Contractor, Unnamed Twice
Neither insurer named the vendor. Neither confirmed a connection to the other. Databreaches.net and The Register observed that the same unnamed U.S. contractor appeared to sit behind both, on the same forum, in the same week, and the inference is difficult to avoid. The file carries it as an inference. Both companies reported to Japan’s Financial Services Agency. Have I Been Pwned loaded the Zurich data on Jan. 22 with about 757,000 unique email addresses.
The Sensitivity Argument, Made By The Insurer
Aflac Japan said the leaked items alone could not identify an individual and that the risk of misuse was extremely low. The fields are a surname, an age, a gender and the fact of holding cancer insurance with a stated coverage amount. Whether that identifies someone depends on who is looking and what else they hold, which the corpus filed as the inference problem at 26-0306. An insurer’s assessment of its own breach is an interested one, and this one rested on the absence of a full name.
The Transfer Server, Again
A file transfer server at a marketing subcontractor is where a Japanese insurer’s customer list goes to become a mailing. The corpus recorded the same class of system at scale in the MOVEit campaign filed at 23-0601 five months later. Here the fault was one vendor’s server, reached from the outside, holding two insurers’ customer bases because both had hired the same kind of help. No penalty, ransom or lawsuit was found.
Compiled from both insurers’ disclosures as reported and contemporaneous coverage, listed below. Counts are the companies’. That one contractor served both is a reporters’ inference and is labelled as one. A separate reported Aflac Japan incident in 2026 is not part of this file. Graded high. Corrections: corrections@forensicpost.com.