Cybercriminals have breached insurance giant Aflac, potentially stealing sensitive data like Social Security numbers, health information, and insurance claims. This is part of a broader wave of attacks on U.S. insurance companies, including Erie Insurance and Philadelphia Insurance Companies, believed to be carried out by the cybercrime group Scattered Spider.
Aflac confirmed it stopped the intrusion within hours, no ransomware was used, and customer services continue. However, the scale of stolen data remains unclear. The attackers used social engineering tactics—such as impersonating IT support—to access networks, a known method of Scattered Spider.
Scattered Spider is considered especially dangerous due to their speed and aggressive tactics. Linked to major 2023 attacks on MGM Resorts and Caesars Entertainment, they continue to target various industries, including retail. Experts warn companies to stay vigilant, with some calling the group a bigger threat than state-backed hackers.