Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatmass-credential-exposureransomware-group-operation

Multiple Healthcare and Insurance Data Breaches Impacting Millions

Updated 3mo agoFirst seen Dec 25, 20258 sources

Several major organizations in the healthcare and insurance sectors have disclosed significant data breaches affecting millions of individuals. ARC Community Services reported a ransomware attack by the INC Ransom group, resulting in the exfiltration of sensitive patient data, including health and financial information. Aflac confirmed that a June cyberattack led to the theft of files containing insurance claims, health data, and Social Security numbers for over 22 million customers, with no operational disruption but widespread exposure of personal information. The Louisiana Office of Student Financial Assistance (LOSFA) notified students of unauthorized access to its systems, exposing names and Social Security numbers, though certain savings accounts were not affected. Oklahoma Spine Hospital agreed to a $1.1 million settlement following a July breach that compromised the data of nearly 39,000 patients, including medical and financial details.

These incidents highlight the ongoing threat posed by cybercriminals targeting sensitive data in the healthcare and insurance industries. Victims in these breaches are being offered credit monitoring and identity protection services, and regulatory notifications have been issued. The attacks have prompted legal action, regulatory scrutiny, and, in some cases, leadership changes within affected organizations. Law enforcement and cybersecurity experts have been engaged to investigate and mitigate the impact of these breaches, which are part of a broader trend of targeted attacks against organizations handling large volumes of personal and health-related information.

Share:
Multiple Healthcare and Insurance Data Breaches Impacting Millions
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Feb 12, 20264mo ago

Aflac updates OCR with confirmed PHI impact of at least 13.9 million

By February 2026, Aflac updated regulators to reflect that protected health information of at least 13,924,906 individuals had been exposed or stolen in the June 2025 attack. Reporting at that stage said the overall incident affected approximately 26.5 million people.

Aflac faces class actions, regulatory scrutiny, and Senate attention

Following disclosure of the breach's scale, Aflac became the target of more than 20 class action lawsuits as well as regulatory investigations and bipartisan Senate scrutiny over its security practices and incident response. The legal and regulatory fallout expanded as the confirmed impact grew.

Dec 26, 20256mo ago

Aflac begins victim notifications and offers protection services

After confirming the scale of the breach, Aflac notified affected customers, beneficiaries, employees, and agents and offered 24 months of identity protection and credit monitoring. The company set an enrollment deadline of April 18, 2026 for the services.

Dec 24, 20256mo ago

Oklahoma Spine Hospital reaches $1.1 million settlement

By December 2025, Oklahoma Spine Hospital agreed to a $1.1 million settlement to resolve litigation over its July 2024 breach. The settlement provides credit monitoring, identity theft insurance, and possible cash payments to affected patients, pending final court approval.

Dec 23, 20256mo ago

Investors sue Coupang over delayed breach disclosure

A U.S. federal securities class action lawsuit filed by December 2025 alleged Coupang failed to disclose its November 2024 breach within the SEC's required timeframe. The case is being viewed as a test of the SEC's 2023 cybersecurity disclosure rules.

Students notified of LOSFA data security incident

By December 2025, LOSFA sent notification letters to students warning that an unauthorized party had accessed or removed files from certain systems. The agency said the START Saving Program and 529 savings accounts were not affected and that the investigation was ongoing.

Dec 4, 20257mo ago

Aflac completes investigation into June breach

Aflac concluded its investigation on December 4, 2025, determining that the breach affected about 22.7 million people, with later reporting putting the total at approximately 26.5 million. The stolen data included personal information, insurance claims data, health information, and Social Security numbers.

Oct 1, 20259mo ago

LOSFA says October cyberattack affected student data

LOSFA previously issued a statement about a cyberattack that occurred in October 2025 affecting certain agency systems. The later investigation found unauthorized access to files containing sensitive information such as names and Social Security numbers.

Aug 8, 202511mo ago

Aflac files initial HHS OCR breach report with placeholder count

On August 8, 2025, Aflac reported the breach to the HHS Office for Civil Rights using a placeholder estimate of 500 affected individuals. The filing indicated protected health information may have been compromised while the investigation was still ongoing.

Jun 12, 20251y ago

Aflac breach linked to broader insurance-sector campaign

Reporting tied the Aflac intrusion to a social-engineering campaign consistent with Scattered Spider activity targeting insurance companies, including Erie Insurance, Philadelphia Insurance Companies, and Scania Financial Services. Aflac said the actor may be associated with a known cybercriminal organization, though it did not formally name the group.

Aflac detects and contains cyberattack on U.S. systems

Aflac detected suspicious activity on June 12, 2025 and contained the intrusion within hours with help from external cybersecurity experts and federal law enforcement. The attack involved data theft rather than ransomware and did not disrupt operations.

Dec 16, 20242y ago

Coupang discloses breach to the SEC after 28-day delay

Coupang did not report its November 2024 breach to the SEC until December 16, 2024, beyond the timeframe required under SEC cybersecurity disclosure rules. The delayed disclosure later prompted regulatory scrutiny, executive resignations, and investor litigation.

Nov 18, 20242y ago

Coupang discovers breach tied to ex-employee credentials

Coupang discovered a data breach on November 18, 2024 that exposed personal information from 33.7 million customer accounts. The incident was traced to a former employee who allegedly retained valid authentication credentials after leaving the company.

Nov 1, 20242y ago

ARC Community Services hit by INC Ransom attack

In November 2024, ARC Community Services suffered a ransomware attack attributed to the INC Ransom group, which exfiltrated sensitive personal, financial, and health data. The organization took systems offline, engaged forensic experts, and later chose not to pay the ransom.

Jul 1, 20242y ago

Oklahoma Spine Hospital email breach exposes nearly 39,000 patients

In July 2024, Oklahoma Spine Hospital suffered a breach involving unauthorized access to an email account, exposing personal, financial, and medical information of nearly 39,000 patients. The incident later led to consolidated class action litigation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Threat actors
2 linked
Organizations
17 linked
AflacPhiladelphia Insurance CompaniesAmazon Web ServicesConduentReliaQuestHarrodsUnited Natural FoodsVictoria's SecretGoogleMarks & SpencerWhole Foods MarketCo-opCoupangScania Financial ServicesBaesley AllenErie InsuranceAllianz Life
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multiple Healthcare and Insurance Data Breaches Impacting Millions | Mallory