Aflac Reports Data Security Incident to Montana Attorney General
Aflac Incorporated, a prominent insurance provider, confirmed a data security incident to the Montana Attorney General after discovering unauthorized access to its systems. The breach occurred in June 2025, potentially exposing personal information of affected policyholders and others. This report serves to inform individuals who have received notification letters about the incident.
- State
- Montana
- Breach date
- June 12, 2025
- Reported
- December 19, 2025
Aflac Incorporated, known for its supplemental health and life insurance products, has publicly reported a data security incident. The company filed details of the breach with the Montana Attorney General's office on December 19, 2025, confirming that unauthorized access to its systems took place.
The incident began on or around June 12, 2025, when Aflac identified that an unauthorized party had gained access to their network. While the specific nature of the compromised data was not detailed in public filings, the company has indicated that personal information may have been involved.
As an insurance provider, Aflac routinely manages a substantial amount of sensitive personal information. Individuals who have received a direct notification letter from Aflac should carefully review its contents for specific details relevant to their situation.
If you have received a data breach notification from Aflac, it is recommended to remain vigilant. Consider placing a fraud alert or security freeze on your credit reports with the three major credit bureaus. Regularly review your account statements and credit reports for any suspicious activity.
Additionally, be cautious of unsolicited communications, especially those requesting personal information. Phishing attempts often follow data incidents, so verify the legitimacy of any requests directly with Aflac through official channels, not via links in suspicious emails or texts. Protecting your data begins with informed and proactive steps.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- MemberSource Credit Union
- GrayRobinson P.A.
- County of Murray dba Murray County Medical Center
- Total Wireless
- Central Ozarks Medical Center
- Brett Robinson Vacation Rentals
- Standard Sales Company, LP
- Clackamas Community College
- Fortine School District
- TrailWest Bank 2
- Dot Foods, Inc.
- First Federal Savings & Loan Association of Pascagoula Moss Point
- Garten Services, Inc.
- Covenant Health, Inc.