Insurance giant Aflac discloses data breach after subsidiary hack
2026-06-30T13:23:36Z•f835b963ad2c8c1c5add6625f01cbbb6cfffed69758525c0652a155073e3e475
AflacBlackfieldBlueHammerCISACVE-2026-46817CVE-2026-48558Djinn-StealerMicrosoft-DefenderNidecNissanOracle-EBSOracle-PeopleSoftShinyHuntersSimpleHelpUNC4221UNC5792data-breachinformation-stealerransomwarevulnerability-exploitationzero-day
What happened
Multiple active incidents and exploited vulnerabilities reported: Aflac disclosed a data breach after its Japan subsidiary was hacked and personal/bank data were stolen; Nissan reported employee data theft tied to Oracle PeopleSoft zero-day activity linked to ShinyHunters (NAIC says only public/outdated data were taken). Threat actors and ransomware gangs are actively exploiting recently disclosed flaws — notably a critical SimpleHelp vulnerability (CVE-2026-48558) used to deploy the cross‑platform Djinn Stealer and a critical Oracle E-Business Suite vulnerability (CVE-2026-46817) now seen in襲
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f835b963ad2c8c1c5add6625f01cbbb6cfffed69758525c0652a155073e3e475
- Enrichment time
- 2026-06-30T13:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.