INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Allianz Life data breach compromised by sophisticated cyber attack tools
| 2025-08-20 10:40 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
The Allianz Life data breach, which occurred on July 16 and was discovered a day later, involved a social engineering attack that impersonated IT support staff. The attackers used malicious OAuth applications to infiltrate Salesforce instances before downloading the company's databases, resulting in the exposure of sensitive information including dates of birth, email addresses, genders, names, phone numbers, physical addresses, Social Security numbers, and data from 1.4 million customers in the North America region, as well as financial professionals and some Allianz Life employees. The leaked credential notification site Have I Been Pwned reported that over 1.1 million accounts were affected, with more than seven-in-ten of the exposed email addresses having already been targeted by previously-disclosed data breaches.
Technical Mitigations AI-generated
• Patch Salesforce instances using malicious OAuth applications to prevent data exfiltration.
• Implement accurate asset inventories and hardened service desk processes to detect social engineering tactics.
• Use tamper-proof identity verification techniques to block or hunt for attackers impersonating IT support staff.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
Global Scope
Incident Timeline
2025/08/20
Threat actors, believed to be affiliated with the ShinyHunters group and possibly overlapping with Scattered Spider and Lapsus groups, used social engineering tactics involving impersonated IT support staff to target Allianz Life.
Click on any entity below to view its context and source!
victims
1.4 customers
The numbers represent the vast majority of the company's 1.4 million customers in the North America region, along with the data of financial professionals and some Allianz Life employees contained in Salesforce Accounts and Contacts databases.
threat_actor
Scattered Spider
The attack has since been claimed by
the notorious ShinyHunters threat group
, which is believed to overlap with the
Scattered Spider
and Lapsus groups.
Tactical Metrics
Metrics
victims
1,400,000
Customers
Click for context!
The numbers represent the vast majority of the company's 1.4 million customers in the North America region, along with the data of financial professionals and some Allianz Life employees contained in Salesforce Accounts and Contacts databases.
Intelligence Sources
IT Pro
2025-08-20
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T08:02
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
Allianz Life
entity
4x
tactic
Cyber Operation Type
Data Breach
tactic
4x
timeline
Temporal Reference
July 16
date
Contextual Telemetry
Context Block
5 METRICS
source region
Origin Region
NORTH_AMERICA
region
victims
Customers
1,400,000
customers
general metric
Future Focus
2,025
future focus
general metric
Senior Executives
700
senior executives
threat actor
APT Group
Scattered Spider
actor
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.