On 20 June 2025, Aflac Incorporated disclosed a cybersecurity incident. Preliminary findings state that an unauthorized party used social engineering to gain network access. That is a workforce identity problem, not a consumer-app story. Public reporting does not name TAP, a spoofed page, or AiTM for Aflac specifically, and Aflac has not publicly named a threat actor. Timing lines up with an insurance-sector helpdesk and call-center social-engineering wave reported with Scattered Spider-style TTPs; treat that as industry context, not a confirmed label on this filing. The same class of failure showed up when helpdesk password-reset social engineering opened a path at M&S earlier in 2025.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did attackers get network access at Aflac?

According to Aflac’s 20 June 2025 newsroom disclosure, an unauthorized party used social engineering to gain network access. That means a human was coached or impersonated until some transferable access path opened. Public reporting does not establish whether the path was a helpdesk reset, recovery re-enrollment, a coached fake login, or another social-engineering route. Aflac’s filing stops at social engineering for network access.

Did Aflac name TAP, AiTM, OTP, or a phishing kit?

No. Aflac’s preliminary findings name social engineering and network access. Public reporting does not name a Temporary Access Pass, OTP relay, push fatigue, a spoofed login page, or an adversary-in-the-middle kit for Aflac specifically. Any article that invents those steps for this company is ahead of the disclosure.

Was this Scattered Spider?

Aflac has not publicly attributed the incident to Scattered Spider or any other named actor. Industry reporting around the same period described an insurance-sector helpdesk and call-center social-engineering wave with Scattered Spider-style TTPs. Timing alignment is real; formal attribution to Aflac is not in the company materials.

Would legacy MFA have stopped this path?

Helpdesk recovery and coached fake login are the same social-engineering class: someone is talked into handing over a transferable factor or approving a lasting workforce login path. Legacy OTP, SMS, email codes, push approvals, and recovery secrets are coachable. A fix exists that removes those transferable factors from enrollment and recovery as well as login; that write-up lives on the companion site. Once a live session already exists, files taken from the network are revoke-and-contain work, not something any MFA undoes after the fact.

What is still unknown about the Aflac incident?

Public reporting does not establish affected record counts, confirmed data exfiltration scope, ransom activity, or a full operational-impact picture. Aflac described the matter as a disclosed cybersecurity incident with evolving scope. Until the company or a regulator publishes those figures, treat them as unknown.