Breach report
Financial ServicesAllianz Life Insurance Company of North America
Allianz Life confirms data breach impacts majority of 1.4 million customers
Hackers tied to the ShinyHunters and Scattered Spider ecosystem tricked their way into Allianz Life's cloud CRM and stole personal data, including Social Security numbers, on most of its 1.4 million U.S. customers.
Reported by BleepingComputer
Records exposed
1.5M
About 1.5 million people
Scale vs. largest on file
- When
- 2025
- How they got in
- Social engineering of employees to access a third-party cloud CRM (Salesforce)
- Sector
- Financial Services
On July 16, 2025, a criminal gained access to a third-party, cloud-based customer relationship management system used by Allianz Life Insurance Company of North America, the Minneapolis-based U.S. arm of German insurer Allianz. The company disclosed the incident in late July, saying the attacker used social engineering and obtained personal information on the majority of its roughly 1.4 million customers, as well as financial professionals and some employees. Allianz Life is one of the largest sellers of annuities in the United States.
Allianz Life said its own network and core policy systems were not accessed. The breach was part of a broad campaign in which hackers phoned employees at large companies while posing as IT support, persuading them to authorize a malicious connected app or hand over access to Salesforce environments. BleepingComputer and other outlets linked the campaign to the ShinyHunters extortion group, which overlaps with the loosely organized Scattered Spider community. Victims of the same wave included Google, Cisco, Qantas, Adidas and several luxury brands.
The stolen records included names, addresses, phone numbers, email addresses, dates of birth and Social Security numbers, along with licensing details for financial professionals. In August 2025, the hackers published data they said came from Allianz Life, containing millions of records of customers, advisers and contacts. Regulatory filings later put the number of people being notified at about 1.5 million, and the company offered two years of identity theft protection and credit monitoring.
Class-action lawsuits were filed soon after the disclosure, arguing the insurer failed to safeguard sensitive information held with a vendor. The breach also came during a concentrated run of attacks on the insurance industry in mid-2025, including incidents at Aflac, Erie Insurance and Philadelphia Insurance, which security researchers attributed to the same social engineering playbook.
The case underscores that cloud platforms are often only as secure as the people with access to them. Attackers did not need a software vulnerability; they needed a convincing phone call. For insurers and other companies holding Social Security numbers, the lesson is to restrict which connected apps can reach customer data, verify help-desk requests out of band and monitor large data exports from SaaS platforms.