Allianz Life Insurance Company of North America suffered a significant data breach in July 2025, impacting approximately 1.5 million individuals, including customers, financial professionals, and employees. The breach was traced to a third-party cloud-based Customer Relationship Management (CRM) system, specifically a Salesforce instance, used by Allianz Life’s U.S. operations. Attackers gained access to the CRM on July 16, 2025, by employing social engineering tactics, impersonating IT helpdesk staff to deceive an employee into granting access. Once inside the CRM environment, the threat actors utilized Salesforce’s Data Loader tool to rapidly extract sensitive data. The compromised information included full names, mailing and email addresses, dates of birth, Social Security numbers, phone numbers, and insurance policy details. The exposure of Social Security numbers heightened the risk of identity theft and fraud for those affected. Allianz Life detected the breach the following day and immediately notified federal authorities, including the FBI, and began an internal investigation. The company emphasized that there was no evidence of unauthorized access to its internal network or critical systems, such as its policy administration system. Allianz Life started notifying affected individuals on August 1, 2025, and offered two years of complimentary identity theft monitoring and credit restoration services through Kroll. Dedicated support channels were established to assist impacted customers and professionals. The breach is believed to be linked to the ShinyHunters hacking group, which, along with other groups like Scattered Spider and Lapsus$, claimed responsibility and leaked databases stolen from Allianz Life’s Salesforce instances. The leaked files reportedly included Salesforce “Accounts” and “Contacts” tables, containing about 2.8 million records of individual customers and businesses. The incident underscores the growing risks associated with third-party service providers and the importance of robust security controls and employee awareness training. Allianz Life’s swift response and cooperation with law enforcement aimed to mitigate the impact and prevent further exploitation of the stolen data. The investigation into the full scope and attribution of the breach remains ongoing. The company has not confirmed the exact number of affected individuals, but external sources estimate the impact to be between 1.1 and 1.5 million people. The breach has drawn attention to the need for enhanced monitoring of cloud-based platforms and the criticality of rapid incident detection and response. Allianz Life’s transparency and support measures have been commended, but the long-term consequences for affected individuals and the company’s reputation are still unfolding.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On October 2, 2025, Allianz Life publicly disclosed the July breach, and a notice filed with the Maine Attorney General's Office said 1,497,036 individuals were affected in its North America branch. The company also began notifying affected individuals and offered two years of free Kroll identity monitoring.
Reporting indicated the incident may be linked to ShinyHunters, and threat actors claimed to have leaked databases from Allianz Life Salesforce instances containing millions of records. This public claim connected the breach to a known threat actor and suggested large-scale data exposure.
After discovering the breach, Allianz Life said it contained and mitigated the incident and notified the FBI. The company stated its investigation into the intrusion remained ongoing.
In July 2025, Allianz Life said a threat actor used social engineering to gain access to a third-party cloud CRM system and steal sensitive personal data. The company said there was no evidence its internal network or critical systems, including policy administration, were accessed.
4 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcethecyberthrone.in
Open sourceforbes.com
Open sourcecyber.nj.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.