Aflac Data Breach Lawsuit Survives Motion to Dismiss, Heads to Discovery
On August 12, 2026, Judge Clay D. Land of the U.S. District Court for the Middle District of Georgia handed down an order Aflac had been fighting to avoid. The court largely denied Aflac’s motion to dismiss the consolidated class action stemming from the June 2025 data breach. Core claims survive, and the case heads to discovery.
What Happened in the Breach
Attackers used social engineering on June 12, 2025, to talk their way into Aflac’s network. The intrusion was detected and contained within hours. No ransomware, no file encryption, no operational disruption. While they had access, the attackers exfiltrated files containing names, Social Security numbers, dates of birth, driver’s license numbers, government-issued IDs, and medical and health insurance information. While mean-time-to-detect (MTTD) is often a useful metric, this shows the value of improving mean-time-to-respond (MTTR), where faster response means less damage.
Aflac disclosed the incident publicly on June 20, eight days later, but didn’t complete its data review until December 4. Notification letters started going out on December 23. In their December 19, 2025 update, Aflac confirmed the breach affected approximately 22.65 million individuals globally. The HHS OCR portal currently lists the breach as affecting only 13,924,906 individuals (search for “Aflac” in the HIPAA breach investigation reports), a figure that captures only the U.S. HIPAA-covered population. The roughly 8.7 million gap between that number and Aflac’s 22.65 million global tally underscores how much of the exposure fell outside U.S. regulatory reporting.
The Court’s Ruling at a Glance
Judge Land split the motion to dismiss into distinct holdings, granting some and denying others based on the pleading standards under Rule 12(b)(6).
| Claim | Status | Why |
|---|---|---|
| Negligence | Denied (survives) | Duty to protect data + plausible breach via inadequate security controls |
| Negligence Per Se | Denied (survives) | Federal statutes can define state-law duties under Georgia law |
| Breach of Implied Contract | Denied (survives) | Insurance bargain includes implied promise to protect customer data |
| Unjust Enrichment | Denied (survives) | Premiums allegedly funded security that never materialized |
| Bad Faith (O.C.G.A. § 13-6-11) | Denied (survives) | Alleged “knowing” deficiency exceeds mere negligence threshold |
| Equitable Relief (DJA) | Denied (survives) | Plaintiffs face substantial likelihood of future harm |
| CCPA | Granted (dismissed) | PHI exemption applies for HIPAA-covered entities |
| CMIA / GUDTPA | Granted (dismissed w/o prejudice) | Voluntarily withdrawn by plaintiffs |
Standing Survives, With One Caveat
Aflac argued that plaintiffs lacked Article III standing because a data breach alone doesn’t create injury. The court disagreed, citing the Eleventh Circuit’s decision in In re Equifax Inc. Customer Data Sec. Breach Litig. Threat actors stealing a massive trove of sensitive data including SSNs and medical records creates a substantial risk of identity theft. That risk constitutes a concrete injury under current precedent. Several plaintiffs went further, alleging dark web monitoring alerts, unauthorized account openings, and fraudulent transactions.
Aflac’s factual challenge to standing didn’t get resolved, though. Aflac submitted expert testimony claiming none of the plaintiffs’ data appears on the dark web, plus an exhibit showing one plaintiff’s email was compromised in numerous unrelated breaches. The court declined to resolve this factual dispute because it overlaps directly with the merits of the negligence claims. Discovery will sort this out.
What Gets Dissected in Discovery
Two threads look especially live heading into discovery. The first is the six-month notification delay. Roughly 190 days passed between detection on June 12 and the first notification letters on December 23 – a timeline that could feed both the bad faith claim and any regulatory scrutiny from HHS.
Aflac will try to prove the plaintiffs’ alleged injuries came from other sources, not this breach. Plaintiffs will try to connect their data specifically to the Aflac incident. Given that the FBI had been warning about Scattered Spider since 2023 – and that the group hit Erie Insurance, Philadelphia Insurance, and Allianz Life around the same time – the foreseeability argument looks strong for the negligence claim.
The broader context matters too. Two Scattered Spider members have since been arrested in the U.K., and a DOJ complaint unsealed in September 2025 revealed the group extorted at least $115 million from victims over three years. That gives plaintiffs a rich evidentiary record to work from when proving future harm.
There’s no settlement, trial date, or resolution on the horizon. Just the case moving forward, with 22.65 million people watching.