Data Breaches

1.5 Million Impacted by Allianz Life Data Breach

In July, hackers stole files containing names, addresses, dates of birth, and Social Security numbers from a cloud-based CRM.

Allianz data breach hack

Insurance giant Allianz subsidiary Allianz Life Insurance Company of North America is notifying roughly 1.5 million people that their personal information was stolen in a July data breach.

The incident occurred on July 16 and involved a third-party cloud-based customer relationship management (CRM) system used by Allianz Life, the company told SecurityWeek in July.

Only Allianz Life in the US was impacted, the company said, adding that most of its roughly 1.4 million customers were likely affected, without sharing an exact number.

This week, however, the company notified the Maine Attorney General’s Office that the breach affects the data of 1,497,036 “Allianz Life customers, financial professionals, and select Allianz Life employees”.

The stolen personal information includes names, addresses, dates of birth, and Social Security numbers, the insurer notes in the notification letter sent to the affected people.

Allianz Life is providing the affected individuals with two years of free identity theft restoration and credit monitoring services.

Advertisement. Scroll to continue reading.

The company also said it has contained and mitigated the issue, and that the incident was limited to the third-party CRM, as none of its systems were accessed.

While Allianz Life did not share details on the compromised CRM, the attack was attributed to the infamous Scattered Spider cybercrime group, which conducted a large-scale campaign targeting the Salesforce instances of major companies.

Adidas, Cisco, Dior, Louis Vuitton, Google, Air France/KLM, and Workday are also believed to have been targeted in the campaign.

Scattered Spider and its recent partner-in-crime ShinyHunters, a hacking group specializing in extortion, announced in mid-September their retirement, but cybersecurity specialists remain skeptical of their disappearance from the threat landscape.

Related: Canadian Airline WestJet Says Hackers Stole Customer Data

Related: Automotive Titan Stellantis Discloses Data Breach

Related: Salesforce AI Hack Enabled CRM Data Theft

Related: 33 Attorneys General Send Letter to FTC on Commercial Surveillance Rules

Related Content

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Data Breaches

The data breach was initially believed to affect roughly 350,000 people, but the HHS breach tracker shows a far bigger impact.

Data Breaches

Hackers stole names, addresses, phone numbers, Social Security numbers, and financial information from a third-party platform.

Data Breaches

Hackers used compromised credentials to access enterprise and personal tax-related data.

Data Breaches

Hackers exploited a vulnerability in the order-tracking function of a plugin to access SafePal customer information.

Data Breaches

The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.

Data Breaches

The root cause of the incident is believed to be a compromised AWS access key that was exposed in publicly available JavaScript build artifacts.

Data Breaches

Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version