{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"Allianz Life Breach: 2.8 Million Records Leaked in Salesforce Hack","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/6d2f0ad0\"></iframe>","width":"100%","height":180,"duration":2899,"description":"On July 16, 2025, Allianz Life Insurance Company of North America confirmed a major data breach that exposed up to 2.8 million sensitive records belonging to customers, financial professionals, business partners, and even some employees. But the company’s internal systems weren’t the target — instead, attackers compromised a third-party, cloud-based CRM platform, widely reported to be Salesforce, through a sophisticated social engineering (vishing) attack.\nInvestigators link the breach to the ShinyHunters hacking group, operating alongside Scattered Spider, both notorious for large-scale data thefts. The hackers reportedly impersonated IT support over the phone, tricking staff into granting access to malicious applications or entering connection codes into Salesforce Data Loader — a classic human-focused intrusion with massive fallout.\nThe stolen data is extensive and includes:\nFull names, addresses, dates of birth\nSocial Security numbers / Tax Identification Numbers\nPolicy and contract details\nPhone numbers, emails\nProfessional credentials, firm affiliations, and product approvals for financial professionals\nWhile Allianz insists its internal policy administration systems remained secure, the leak’s scale and sensitivity raise serious concerns about third-party risk management in the insurance and financial sectors.\nThis attack isn’t an isolated case. It’s part of a broader wave of Salesforce-targeted breaches affecting multiple industries — including tech giants like Google and luxury brands like LVMH — all using the same social-engineering playbook. Security researchers warn that once attackers infiltrate a CRM, they often gain access to the full breadth of customer and partner data it holds.\nAllianz responded by notifying affected individuals, law enforcement, and regulators, offering two years of free credit monitoring and identity theft protection. But the company is already facing a class-action lawsuit alleging insufficient safeguards and slow...","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}