If you are an Allianz Life Insurance Company of North America customer, treat the 2025–2026 CRM breach as a full-identity exposure and act now: freeze your credit at all three bureaus, enroll in the 24 months of free monitoring Allianz Life is offering, watch financial and insurance accounts for unauthorized activity, expect targeted phishing that references your policy details, and remove your personal information from data broker sites so attackers cannot combine it with the leaked records. Below is exactly how to do each step.
What Happened in the Allianz Life Breach
Allianz Life Insurance Company of North America — a Minneapolis-based subsidiary of the German insurance giant — disclosed a major data breach after attackers used social engineering against a cloud-based CRM vendor on July 16, 2025. The company detected the intrusion the next day and later confirmed that the majority of its roughly 1.4 million U.S. customers had personal information exposed, along with data belonging to some financial professionals and select employees. Independent analysis of the leaked archive on Have I Been Pwned identified approximately 1.1 million unique records.
The intrusion has been publicly linked to ShinyHunters, the same extortion group behind a broader 2025–2026 wave of attacks on Salesforce-hosted customer relationship management systems at Google, Qantas, Workday, and multiple retail brands. The pattern is consistent: voice-phishing (vishing) of employees, OAuth or session-token abuse to reach the CRM, then bulk export of customer records.
What Information Was Exposed?
According to Allianz Life's disclosures and independent analysis of the leaked archive, exposed fields include:
- Full names
- Home addresses
- Dates of birth
- Social Security numbers
- Phone numbers and email addresses (for some records)
- Financial-professional identifiers for a subset of records
Allianz Life has stated that its own core policy administration and financial systems were not accessed — the exposure is limited to the customer information stored in the third-party CRM. That distinction matters legally, but not practically: the exposed fields alone are enough for full identity theft.
This Is a Full-Identity Breach
SSN + date of birth + address is the exact recipe for opening credit lines, filing fraudulent tax refunds, and building synthetic identities. Treat any Allianz Life notification as if your Social Security number were leaked directly — because it was.
Step 1: Confirm You Were Affected
- Watch your mail and email. Allianz Life began sending notification letters in waves following the disclosure. If you have not received one, check spam and use only the callback numbers on the letter itself — never phone numbers in an email.
- Check Have I Been Pwned. The Allianz Life dataset was added to haveibeenpwned.com. Enter the email addresses you have used with the company to check for a match.
- Call Allianz Life directly. If you are or were a customer of Allianz Life Insurance Company of North America (this is the U.S. life-insurance subsidiary — not Allianz's European property/casualty operations) and have not received a notice, call member services to confirm.
Step 2: Enroll in the Free Monitoring Allianz Life Is Offering
Allianz Life is providing affected individuals with 24 months of free identity theft protection and credit monitoring. Follow the enrollment instructions in your notification letter — the enrollment code has a deadline and is worth using even if you already have identity protection elsewhere. Free monitoring is a supplement, not a substitute, for the steps below.
Step 3: Freeze Your Credit at All Three Bureaus
Because Social Security numbers were exposed, a credit freeze is the single most effective step you can take. It is free, takes about 15 minutes, and blocks anyone — including you — from opening new credit in your name without lifting the freeze first.
- Equifax: equifax.com/personal/credit-report-services/credit-freeze/
- Experian: experian.com/freeze/center.html
- TransUnion: transunion.com/credit-freeze
Also place a fraud alert at any one of the three — it automatically applies to the other two — so lenders take extra steps to verify identity before opening new accounts.
Step 4: Watch Insurance and Retirement Accounts
Allianz Life sells life insurance, fixed and variable annuities, and retirement products. Attackers with your identity can attempt policy loans, address changes, beneficiary substitutions, or unauthorized annuity withdrawals. Take three specific steps:
- Log into your Allianz Life account portal and confirm that the address, email, phone number, and beneficiaries on file are correct.
- Change your Allianz Life password and enable two-factor authentication if you have not already.
- Call your financial professional if you use one — establish a verbal password so they can verify future requests are legitimately from you.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 5: Move 2FA Off SMS
A leaked full-identity record makes SIM-swap attacks realistic. Once an attacker owns your phone number, SMS 2FA stops protecting you. Switch your email, bank, and insurance-portal 2FA to an authenticator app (Authy, Google Authenticator, 1Password) or a hardware key (YubiKey). Keep SMS as a fallback only.
Step 6: Watch for Targeted Phishing
Attackers with your full name, address, and financial context can craft phishing that looks disturbingly authentic. Expect:
- Fake Allianz Life "breach response" emails asking you to "verify identity" or "claim your free monitoring"
- Calls from people who know you own an Allianz Life annuity or policy and try to "confirm" account details
- Text messages about premium changes, payouts, or policy reviews
- Emails offering free credit monitoring from a company Allianz Life did not name
Never click a link in a breach-related email. Go to Allianz Life's official site directly, and only enroll in monitoring through the code printed in your mailed letter.
Step 7: File Complaints if You See Misuse
- Report identity theft at IdentityTheft.gov to get an FTC recovery plan and affidavit
- File a state insurance-department complaint if unauthorized account changes are made
- File a police report if fraudulent accounts or loans are opened in your name — you will need the report number to dispute fraud with creditors
Step 8: Remove Your Data From People-Search Sites
Data brokers like Spokeo, BeenVerified, WhitePages, and Radaris publish your name, address, phone, relatives, and employer for free. When combined with the Allianz Life leak, this gives attackers everything they need to impersonate you or to spin up convincing pretexts targeting your bank, your insurance company, or your family.
PrivacyOn removes your personal information from 100+ data broker sites, monitors the dark web for exposures like the Allianz Life leak, and keeps re-submitting removal requests when brokers relist your data — which they routinely do. Reducing your public footprint is the one long-term step that actually stays effective after a breach.
Why ShinyHunters Keeps Winning in 2026
The Allianz Life breach is one of the largest in a running string of ShinyHunters CRM attacks that also produced the 2026 Salesloft Drift supply-chain breach and the McKesson patient-record theft. The pattern is nearly identical: a support agent or IT admin is targeted via phone, tricked into approving a malicious app or revealing a session token, and the attackers then quietly export the entire CRM. Consumer data ends up on ShinyHunters' leak site, in HIBP, and in the tool-kits of downstream fraud rings — a cycle that keeps making full-identity data effectively permanent.
How PrivacyOn Helps After the Allianz Life Breach
- Dark web monitoring alerts you when your Allianz Life data appears for sale or in new dumps
- Data broker removal pulls your personal information from 100+ people-search sites — reducing the ammunition for identity thieves
- 24/7 continuous monitoring catches new exposures as they happen, not months later
- Family plans cover up to 5 people, so your household is protected together
- Starts at $8.33/month — a fraction of the cost of restoring a stolen identity
Take Action Today
PrivacyOn's dark web monitoring and data broker removal are the long-term protection layer breaches like Allianz Life require. Start protecting your family today — plans from $8.33/month.
Frequently Asked Questions
How many people were affected by the Allianz Life data breach?
Allianz Life confirmed that the majority of its roughly 1.4 million U.S. customers had personal information exposed, along with some financial professionals and select employees. Independent analysis of the leaked archive identified approximately 1.1 million unique records.
Was my Social Security number exposed?
Yes. Confirmed exposed fields include names, addresses, dates of birth, and Social Security numbers, plus phone numbers and email addresses for some records. Treat it as a full-identity leak and freeze your credit immediately.
Did the Allianz Life breach affect my insurance policy or annuity?
Allianz Life has stated that its core policy administration systems were not accessed — the exposure was limited to a third-party CRM. Your policy itself is intact, but the personal information attackers now hold is enough to attempt unauthorized changes (address, beneficiary, loan). Log into your Allianz Life account, confirm your details, change your password, and enable 2FA.
Is the free credit monitoring from Allianz Life enough?
The 24 months of free monitoring is worth enrolling in, but it is not enough on its own. Credit monitoring alerts you after suspicious activity occurs. A credit freeze prevents new accounts from being opened in the first place, and data broker removal shrinks the personal information attackers can use to impersonate you. Use all three.
Is Allianz Life the same company as Allianz in Europe?
Allianz Life Insurance Company of North America is the U.S. life-insurance and annuity subsidiary of the German Allianz Group. The 2025–2026 breach specifically affected the U.S. subsidiary's customer data stored in a third-party CRM. Allianz's European property/casualty operations were not affected by this incident.
What is the best long-term protection after this breach?
Because the Allianz Life data will circulate on the dark web indefinitely, the highest-value long-term steps are (1) keeping credit frozen except when you actively apply for credit, (2) moving 2FA off SMS and onto an authenticator app or hardware key, and (3) subscribing to a data broker removal service like PrivacyOn that continuously removes your personal information from people-search sites so attackers cannot easily combine it with the leaked records.