Week 27 | The Insurance Industry Had a Very Bad Month
June 26 — July 2, 2026 · 5 stories
Week 27 | The Insurance Industry Had a Very Bad Month
June 26 — July 2, 2026 · 5 stories

This Week in 30 Seconds
📌 Aflac Japan confirmed that hackers stole personal and banking data from 4.38 million policyholders, disrupting claims services and marking Aflac’s second major breach in twelve months.
📌 A forgotten test password at competitive intelligence vendor Klue let attackers walk into the Salesforce systems of nearly 200 companies, including cybersecurity firms that sell protection for a living.
📌 Ransomware groups pulled in an estimated $529 million in the first quarter of 2026, a 39% jump from last year, with the industry now operating less like crime and more like franchising.
Aflac Japan: 4.38 Million Insurance Customers Had Their Data Stolen Over 10 Days
What happened?
Aflac Life Insurance Japan disclosed a significant data breach on June 30, exposing the personal information of approximately 4.38 million policyholders. The incident, detected on June 25, involved unauthorized access to the company’s policyholder portal, a website where customers manage their insurance contracts and policy changes. The attackers accessed the systems several times until June 25, when the company discovered the incident.
Who’s affected?
Insurance customers in Japan, insurance agencies, and anyone watching the pattern forming around global insurers. Around 230,000 records included bank account numbers used for premium payments. The breach also exposed contact information for roughly 40,000 insurance agencies. This is the second time in roughly a year that a major Aflac breach has been confirmed, following a June 2025 incident at the company’s US business that exposed data on more than 22 million individuals.
Business impact
Aflac took portions of its policyholder portal and internal systems offline, redirecting claims processing to phone and alternative channels. At least five services have been disrupted as a result of the incident. For an insurer, shutting down your customer portal is the equivalent of a retailer locking the front door during a sale. The two events place one of the world’s largest supplemental insurers at the centre of a broader wave of attacks against the sector. Two breaches in twelve months makes the next cyber insurance renewal conversation very uncomfortable.
Takeaway for you
Ask your insurance broker whether your policy provider has experienced a data breach in the past 24 months, and whether any of your company’s premium payment details may have been exposed. If your business holds insurance with Aflac or any recently breached insurer, confirm with your finance team that bank account details used for premium transfers have not been reused elsewhere.
Source: SecurityWeek
— -
Klue Breach: One Forgotten Password Unlocked 200 Companies’ Sales Data
What happened?
On June 11, 2026, a threat actor compromised backend systems at Klue, a market intelligence platform that hundreds of enterprise organizations use to sync competitive battlecard data with their CRM environments. The attackers didn’t find a software flaw. The threat actor gained initial access through a dormant credential rather than a phishing campaign or a vulnerability exploit. Klue had created the credential for a prototype integration and never decommissioned it. From there, they stole digital keys called OAuth tokens (think of these as VIP passes that let one app talk to another) and used them to extract data directly from customer Salesforce accounts.
Who’s affected?
The breach resulted in the compromise of OAuth tokens and subsequent data exfiltration from nearly 200 organizations, including major cybersecurity vendors such as Huntress, Recorded Future, Tanium, and Jamf. Any business using Klue’s integration with Salesforce, HubSpot, Gong, or similar platforms was potentially exposed. The stolen data primarily consists of business contacts, sales communications, pricing information, and opportunity notes from customer Salesforce instances.
Business impact
This is a supply chain breach. SaaS supply chain breaches are accelerating. Threat actors have shifted from targeting individual organizations to targeting the SaaS vendors those organizations trust, because compromising one vendor means access to hundreds of enterprise environments at once. The stolen CRM data, including deal pipelines and client contacts, is a ready-made toolkit for targeted phishing and corporate espionage. Salesforce disabled the Klue Battlecards app integration within its platform in response. For affected companies, the competitive intelligence stored in their CRM is now in criminal hands.
Takeaway for you
Ask your sales operations or IT team to pull a list of every third-party app currently connected to your CRM (Salesforce, HubSpot, or similar). Look specifically for integrations that were set up as tests and never removed. If any app on that list is no longer actively used, disable it this week.
Source: The Hacker News
KDDI: One Software Flaw Exposed 14.2 Million Email Logins Across Six Providers
What happened?
Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. The investigation determined that the hackers exploited a vulnerability in an unnamed third-party software that KDDI Corporation used on its system. This is potentially one of the largest email credential breaches in Japan’s history.
Who’s affected?
Up to 14.2 million email addresses and passwords may have been exposed, affecting current, former, and inactive customers of the impacted ISPs. The affected service providers include STNet, JCOM, Chubu Telecommunications, Nifty, Biglobe and KDDI Web Communications. The business lesson extends globally: any company using a shared service operated by a third party faces the same architectural risk.
Business impact
Non-compliance with Japan’s APPI can result in fines of up to ¥100 million (approximately $700,000) and, in severe cases, criminal prosecution. Shared infrastructure delivers efficiency, yet it also concentrates risk. One vulnerability in third-party software became a problem for six brands simultaneously. For companies relying on outsourced email, hosted IT, or shared cloud platforms, this is a case study in concentration risk.
Takeaway for you
If your company uses a managed email or cloud service operated by a third party, ask your provider this week whether they can confirm the last time they patched their underlying platform software. A non-answer or vague response tells you something important about how that provider manages risk on your behalf.
Source: BleepingComputer
America’s Insurance Regulator Breached via Oracle PeopleSoft Zero-Day
What happened?
The National Association of Insurance Commissioners (NAIC) has confirmed it was targeted in the recent hacking campaign that exploited an Oracle PeopleSoft zero-day vulnerability. A zero-day is a flaw in software that the vendor doesn’t know about yet, meaning no fix exists when attackers strike. ShinyHunters claimed the attack and leaked the stolen data after the organization refused to pay a ransom.
Who’s affected?
The NAIC coordinates insurance regulation across all 50 US states. S&P Global and Moody’s have said they suspended data feeds to NAIC, and the NAIC has temporarily suspended assigning designations to insurer investments. This disruption touches the regulatory plumbing of the entire US insurance sector. The cybercriminals claim to have targeted more than 100 organizations in the Oracle PeopleSoft campaign.
Business impact
While NAIC says no personal or financial data was stolen, the operational fallout is real. Credit rating agencies pausing their data feeds to a regulator is without precedent. Security experts warn that infrastructure files, configuration data, and production backups could provide the extortion group with a roadmap of the organization’s internal environment. The broader lesson: when a regulator gets breached, the ripple effects touch every company in the regulated industry.
Takeaway for you
If your business files regulatory reports or shares data with any industry regulator, check whether that regulator has issued a security advisory in the past 30 days. For insurance-sector firms specifically, confirm with your compliance team whether NAIC’s operational disruptions affect any pending filings, rate approvals, or investment designations.
Source: SecurityWeek
Novo Nordisk Refuses $25 Million Ransom. Hackers Now Selling Ozempic Maker’s Drug Research
What happened?
A cyber extortion group claimed to have stolen more than a terabyte of data from pharmaceutical giant Novo Nordisk. FulcrumSec said it spent more than two months in Novo Nordisk’s networks. It said that data included company source code, proprietary information on released and unreleased drugs, trial data, employee and patient data, and internal AI model information. FulcrumSec attempted to negotiate a ransom payment of $25 million. Novo did not comply with payment.
Who’s affected?
Novo Nordisk’s GLP-1 drug portfolio (Ozempic, Wegovy) generates tens of billions in annual revenue. FulcrumSec claims to have stolen 1.3TB of data, including source code, proprietary drug compound data, 30 trained AI models, and records from 11,500 pseudonymized clinical trial participants. Patients, healthcare providers, pharmaceutical competitors, and investors all have a stake in what happens to this data.
Business impact
FulcrumSec said that after Novo Nordisk refused to pay $25 million, it was “exploring private sales” for some of the data related to certain drugs and other internal data. That phrase, “private sales,” is new territory. This isn’t about locking systems for ransom. It is about selling a company’s competitive advantage to the highest bidder. For any company whose value depends on proprietary research, AI models, or trade secrets, this breach redefines what is at risk.
Takeaway for you
Ask your development or engineering lead whether any API keys, access tokens, or credentials are stored in code that is accessible from the public internet. FulcrumSec gained initial access through secrets left in client-side JavaScript on two Novo Nordisk subdomains, specifically an Azure container registry credential and a GitHub personal access token embedded directly in front-end code. This is one of the most preventable breach entry points that exists.
Source: Reuters (via GV Wire)
🌐 Weekly Trend Observation
Three things jumped out at me this week. The first is the insurance sector’s sudden visibility as a target. Between Aflac Japan losing 4.38 million policyholder records, America’s insurance regulator getting breached through a PeopleSoft zero-day, and credit rating agencies suspending their data feeds in response, we are watching an entire industry’s trust architecture get tested in real time. Insurers hold the exact combination of personal data, financial details, and high-trust relationships that make them ideal targets for social engineering and fraud.
The second signal is the supply chain pattern. Both the Klue breach and the KDDI breach share the same underlying story: a single point of compromise in shared infrastructure cascading outward to hundreds of downstream victims. At Klue, it was a forgotten test credential. At KDDI, it was unpatched third-party software. In both cases, the victim organizations did nothing wrong themselves. Their vendor did. This is the risk that keeps growing, and most vendor contracts still don’t meaningfully address it.
Looking ahead, I expect cyber insurance underwriting to tighten significantly in the next 60 to 90 days. Ransomware revenue climbing 39% in a single quarter, combined with insurers themselves getting breached, creates pressure on both sides of the equation. Companies renewing cyber insurance policies in Q3 and Q4 of 2026 will face harder questions, narrower coverage, and higher premiums. The companies that prepare answers now, rather than at renewal time, will be the ones that come out ahead.
Cybersecurity, TRANSLATED. Written weekly for business leaders who want to understand cyber risk without needing a technical degree. If this was useful, follow for next week’s edition.
메타데이터
- post_id
- 04955090a8e2
- slug
- week-27-the-insurance-industry-had-a-very-bad-month-04955090a8e2
- url
- https://medium.com/cybersecurity-translated/week-27-the-insurance-industry-had-a-very-bad-month-04955090a8e2
- canonical_url
- https://medium.com/cybersecurity-translated/week-27-the-insurance-industry-had-a-very-bad-month-04955090a8e2
- author_url
- https://medium.com/@arianchen0827
- status
- ok
- fetched_at
- 2026-07-08 05:49:34