Desk live·
ForensicPost
Breaches/Insurance/File 25-0618

Aflac Confirms 13.9 Million Affected in the Largest Healthcare Breach of 2025

Aflac confirmed protected health information belonging to at least 13,924,906 individuals was exposed — the largest confirmed healthcare data breach of 2025, at an insurer.

Constructed geometry · not a chart of case data
TargetAflac
ActorScattered Spider
D. Kennedy12 min readConfidence: high2 sources reviewed

Aflac confirmed that protected health information belonging to at least 13,924,906 individuals was exposed or stolen, making it the largest confirmed healthcare data breach reported in 2025. Reporting links the incident to the social-engineering campaign recorded across this corpus.

The Largest Health Breach Of The Year Was Not At A Health Provider

The corpus filed at 25-0801 that the biggest healthcare exposure of the year happened at a company with no patients, and treated it as a pattern rather than an observation.

This is the same finding with a bigger number and a named company. Yale New Haven, a large regional health system, reported 5,556,702 at 25-0308. An insurance company reported nearly fourteen million.

A provider holds the patients it treated. A supplemental insurer holds the claim records of everyone it covered across every employer group — which is a wider population, assembled for adjudication rather than for care.

And It Sits In The Wrong Regulatory Frame

The healthcare register at 25-0630 exists because US health organisations are compelled to file. That obligation follows the data class, which is why this incident appears in healthcare breach tables at all.

What does not follow the data class is the security supervision — the argument at 25-0601, where an insurer’s regulator examines solvency and conduct rather than the third-party platforms its sales estate runs on.

The reporting duty tracks the sensitivity of the record. The security expectation tracks the sector of the company. For an insurer holding health data those two point in different directions.

Supplemental Insurance Data Is Unusually Revealing

Aflac’s products pay on diagnosis of specific conditions. A claim record therefore states not that somebody sought care but that they were diagnosed with something the policy names — cancer, a critical illness, an accident with defined injuries.

That is a more directly interpretable health disclosure than most clinical records, and the permanence argument at 25-1010 applies in full. There is no equivalent of a credit freeze for a leaked diagnosis.

How we reported this

Compiled from public reporting and company disclosure, listed below. The figure is the company’s confirmed count as reported and is described as a minimum. Attribution follows published research assessments. Corrections: corrections@forensicpost.com.

Sources
  1. Aflac data breach: PHI of at least 13.9 million individuals compromisedHIPAA Journal
  2. Scattered Spider targets Aflac, other insurance companiesSecurity Boulevard
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary