Data leak

Allianz Life Insurance Data Breach (ShinyHunters/Scattered Spider)

πŸ“… 2025-07-16 🏒 Salesforce CRM
Primary Source β†—

Incident Details

On July 16, 2025, threat actors gained access to a third-party cloud CRM (Salesforce) used by Allianz Life Insurance of North America via social engineering/vishing. Attackers used Salesforce Data Loader to bulk-exfiltrate approximately 2.8 million records. Allianz Life has ~1.4 million customers; the breach is reported to have affected the majority of them. Have I Been Pwned listed 1.1 million affected accounts. Stolen data includes names, addresses, phone numbers, birth dates, Tax IDs, insurance licence details, and firm affiliations. Attack attributed to a ShinyHunters/ScatteredLapsuSp1d3rHunters Telegram channel (alliance of ShinyHunters, Scattered Spider, Lapsus$). Part of a broader insurance industry targeting campaign in 2025.

Technical Details

Initial Attack Vector
Vishing / social engineering: attackers impersonated IT helpdesk to trick an employee or vendor into granting access to a cloud-based Salesforce CRM system; Salesforce Data Loader used to bulk-exfiltrate data
Vendor / Product
Salesforce CRM

Timeline

  1. 2025-07-16 Breach occurred
  2. 2025-07-01 Publicly disclosed
  3. 2025-08-01 Customers notified