Allianz Life data breach (2025): what was exposed and what to do

Updated Corrections

September 28, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

Allianz Life data breach (2025): what was exposed and what to do

By Delist Editorial Team · Updated September 28, 2026 · Corrections

September 28, 2026

What happened

Allianz Life Insurance Company of North America (AZLNA), a U.S. life/annuity insurer (Allianz SE’s global parent was described as not impacted), notified regulators and consumers after unauthorized access to a third-party cloud CRM—identified in company AG letters as Salesforce—used by AZLNA and two U.S. affiliates.

Per Iowa Attorney General letters, California OAG consumer-notice samples, and press (BleepingComputer, SecurityWeek):

  • Unauthorized access on July 16, 2025, via social engineering (company September update letter to Iowa AG references threat actors referring to themselves as ShinyHunters).
  • AZLNA became aware on July 17, 2025, and terminated the unauthorized access the same day (Iowa’s July 25 letter timestamps awareness at 12:17 p.m. CDT and termination at 2:17 p.m. CDT).
  • Company statements: the actor did not gain access to AZLNA’s broader company network beyond the CRM instance.
  • Investigation with Mandiant and Kroll; September 29, 2025 update letter to Iowa AG after investigation wrap (Iowa residents cited in that letter: 15,488).
  • Nationwide figure reported via Maine AG / press: 1,497,036 people (customers, financial professionals, and select employees). SecurityWeek and BleepingComputer rounded this as roughly 1.5 million.
  • Consumer mail began as early as August 1, 2025 (Iowa letter), with two years of complimentary identity monitoring (Kroll named in Iowa / California notice materials; California sample lists Kroll at 866-819-7180 for monitoring questions).

Earlier HIBP commentary around ~1.1 million emails reflected an interim researcher view—prefer the later company/AG ~1.50M / 1,497,036 lock for the completed investigation. This page is about the July 2025 Salesforce CRM incident; do not merge it with unrelated older Allianz-brand notice filings (for example, smaller Massachusetts Allianz Life samples that name only policy-number exposure).

Sources

What data was exposed

Company notification letters (Iowa AG PDFs; California OAG sample notice ELN-24798; as summarized by SecurityWeek and BleepingComputer) state personal information obtained from the CRM included:

  • Names
  • Addresses
  • Dates of birth
  • Social Security numbers

Iowa’s July 25, 2025 initial letter also noted queries during the compromise window appeared to reach personal information related to the majority of AZLNA’s customers, financial professionals, and select employees. Exact fields still vary by person—rely on your mailed notice.

Breach details

Detail Value
Breach name Allianz Life Insurance Company of North America (Salesforce CRM)
Date Access July 16, 2025; discovered / contained July 17, 2025; investigation wrap ~Sep 29, 2025
Disclosed Initial AG notices ~July 25, 2025; consumer mail from ~Aug 1, 2025; completed-count press ~Oct 1–2, 2025; CA OAG sample notice filed for Jul 16 breach date
Accounts affected 1,497,036 (Maine AG / company notice materials as reported; ~1.5M in press). Iowa update letter: 15,488 Iowa residents. Earlier ~1.1M HIBP email figure was interim.
Domain allianzlife.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Allianz Life; it reflects a publicly reported security incident.

For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.

What to do now

Because company notices name SSNs and dates of birth:

  • Place a free credit freeze at Equifax, Experian, and TransUnion. See how to freeze your credit.
  • Enroll in the complimentary monitoring offered in your letter (commonly described as two years via Kroll) only through printed channels—not cold “Allianz Life breach support” messages. California sample materials list 866-819-7180 for Kroll monitoring questions.
  • Review annuity/life-policy mail and financial statements for unfamiliar changes; verify any “policy update” call on Allianz Life’s official site.
  • Keep the letter—it is the record of what applied to you.

Short checklist: first 48 hours after a data breach. If the letter is confusing: a company emailed me about a breach.

How this shows up on the open web

Names and addresses are already common people-search fields. After an insurer CRM incident that also involved SSNs, phishing that pretends to be “Allianz Life breach support” can sound more plausible when someone can look up your phone or address online. Run a free open-web scan to see which people-search and broker sites expose your personal data. Delist does not claim to have scanned Allianz Life’s Salesforce instance or this incident’s files, and it does not remove dump copies.

Related reading: 700Credit (2025), AssuranceAmerica (2026), and how to freeze your credit.

Allianz Life said my SSN was in a Salesforce CRM breach—what first?

Freeze credit at all three bureaus. Enroll in the letter’s monitoring only through printed channels. Company notices limited access to the CRM instance—not the broader policy network.

Frequently asked questions

How many people did Allianz Life say were affected?

Company notice materials reported via Maine AG / press cite 1,497,036 people (customers, financial professionals, and select employees)—about 1.5 million. Iowa’s September 29, 2025 update letter cited 15,488 Iowa residents. An earlier ~1.1 million HIBP email figure was interim.

Was Allianz’s core policy admin network breached?

Company AG letters say unauthorized access was limited to the cloud CRM (Salesforce) instance and that the actor did not gain access to additional AZLNA company network systems outside that CRM.

What data types were in the notices?

Iowa AG letters and the California OAG sample notice list names, addresses, dates of birth, and Social Security numbers. Check your mailed notice for what applied to you.

Can Delist remove my record from the Allianz Life CRM files?

No. Delist does not scrub insurer CRM systems or breach dumps. A free scan checks open-web people-search and broker listings only.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.