Allianz Life confirmed a data breach where a threat actor gained access to a third-party, cloud-based CRM system, exposing personal information of the majority of its 1.4 million customers, financial professionals, and select employees. The breach occurred through a social engineering technique, and the company took immediate action to mitigate the issue. The investigation is ongoing, and the attack is believed to have been conducted by the ShinyHunters extortion group.
TPRM report: https://scoringcyber.rankiteo.com/company/allianz-life
"id": "all550072725",
"linkid": "allianz-life",
"type": "Cyber Attack",
"date": "7/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Majority of 1.4 million '
'customers',
'industry': 'Financial Services',
'location': 'North America',
'name': 'Allianz Life Insurance Company of North '
'America',
'size': '1.4 million customers',
'type': 'Insurance Company'}],
'attack_vector': 'Social Engineering',
'customer_advisories': 'Placeholder notification issued',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': 'Majority of 1.4 million '
'customers',
'personally_identifiable_information': 'Yes',
'type_of_data_compromised': 'Personally Identifiable '
'Information'},
'date_detected': '2025-07-16',
'description': 'Allianz Life Insurance Company of North America experienced a '
'data breach where the personal information of the majority of '
'its 1.4 million customers was exposed due to a malicious '
'threat actor gaining access to a third-party, cloud-based CRM '
'system.',
'impact': {'data_compromised': 'Personally Identifiable Information',
'systems_affected': 'Third-party, cloud-based CRM system'},
'initial_access_broker': {'entry_point': 'Third-party, cloud-based CRM '
'system'},
'investigation_status': 'Ongoing',
'motivation': 'Data Exfiltration',
'references': [{'source': 'BleepingComputer'}],
'regulatory_compliance': {'regulatory_notifications': 'Mandatory filing with '
"Maine's Attorney "
"General's Office"},
'response': {'communication_strategy': 'Process of reaching out to '
'individuals impacted with dedicated '
'resources',
'containment_measures': 'Immediate action to contain and '
'mitigate the issue',
'law_enforcement_notified': 'FBI notified'},
'threat_actor': 'ShinyHunters',
'title': 'Allianz Life Data Breach',
'type': 'Data Breach'}