aflacsecurityincident.com

by CodingAsik January 13, 2026

AflacSecurityIncident.com is a real Aflac breach-response address, but the published deadline for its free protection service passed on April 18, 2026.

What is AflacSecurityIncident.com?

AflacSecurityIncident.com was created to help people affected by Aflac’s June 2025 cybersecurity incident enroll in identity and credit protection.

The strongest proof that the domain is official appears in the breach notice filed with the California Attorney General, which tells recipients to visit this exact address and enter the unique code printed in their letter.

The domain currently redirects visitors to an activation page on app.medicalshield.cyex.com, which is operated by CyEx, Aflac’s chosen incident-response provider.

This is not Aflac’s normal insurance website, customer portal, claims system, or payment page.

Its purpose is limited to activating protection services related to the security incident.

Why was this special website created?

Aflac detected unauthorized access to part of its United States network on June 12, 2025.

The company said it contained the intrusion within hours, kept its main business services running, and found no ransomware on its systems.

Aflac later found that an unauthorized person had obtained files containing personal information.

On December 4, 2025, Aflac decided that the affected information probably required formal notices under applicable laws.

Its December 2025 public update said information connected to about 22.65 million people was involved.

The affected group included customers, beneficiaries, employees, insurance agents, and other people connected to Aflac’s American business.

The files could contain names, contact details, claims information, health information, Social Security numbers, and other personal records, although each person may have had different information exposed.

Is AflacSecurityIncident.com legitimate?

The available evidence strongly supports that the exact domain is legitimate.

A government-hosted breach notice names it directly, Aflac’s official documents identify CyEx Medical Shield as the protection provider, and the domain redirects to CyEx’s enrollment system.

However, a legitimate incident can still lead to fake emails, calls, letters, and lookalike websites.

Users should type the domain carefully instead of opening a link from an unexpected message.

A fake address may add a hyphen, change one letter, use another ending, or place “aflac” somewhere inside a longer domain name.

A real enrollment code should also be kept private because it was issued to a specific person.

What protection did the website offer?

Aflac offered 24 months of CyEx Medical Shield at no charge to eligible people.

The package included Experian credit monitoring, identity-theft support, medical fraud monitoring, dark-web monitoring, high-risk transaction alerts, security-freeze help, and identity-theft insurance subject to policy terms.

The service went beyond basic credit checks because stolen health and insurance information can be used for medical identity fraud.

For example, someone may try to receive treatment, buy medical products, or submit an insurance claim using another person’s details.

Aflac’s published material set April 18, 2026 as the final general enrollment deadline.

That date is already past as of August 5, 2026, even though the domain still redirects to the activation system.

A person with an unused code should not assume it remains valid and should confirm available options through contact information published on Aflac’s official website or formal breach notice.

What should affected people do now?

People who received a notice should review their credit reports, financial accounts, insurance statements, and medical claim records for activity they do not recognize.

The Federal Trade Commission’s data-breach guide recommends checking credit reports and freezing credit when sensitive information may have been exposed.

A credit freeze is free, does not lower a credit score, and can help stop criminals from opening new credit accounts.

The freeze must normally be placed separately with Equifax, Experian, and TransUnion.

People can obtain reports through AnnualCreditReport.com, the official website established for federally authorized free credit reports.

Anyone who finds fraud can report it through IdentityTheft.gov and receive a recovery plan.

Is this connected to Aflac’s 2026 incident in Japan?

The AflacSecurityIncident.com program relates to the June 2025 incident involving Aflac’s United States business.

It should not be confused with a separate incident announced by Aflac Japan in June and July 2026.

Aflac Japan’s official July 2026 information describes unauthorized access occurring between June 10 and June 25, 2026, with information relating to about 4.4 million customers identified at that stage.

The dates, affected systems, notices, support channels, and customer groups are different.

What is the final verdict?

AflacSecurityIncident.com is an official, narrow-purpose enrollment domain connected to Aflac’s large 2025 United States data breach.

Its unusual name and third-party redirect can look suspicious, but both are supported by Aflac documents and a government-posted notification.

The main concern today is not whether the exact domain was real, but whether enrollment codes still work after the April 18, 2026 deadline.

Affected people should verify all messages through official Aflac sources and use independent tools such as credit freezes, credit reports, account alerts, and insurance-record checks.