On July 16, 2025, Allianz Life Insurance Company of North America experienced a significant data breach involving a third-party, cloud-based customer relationship management (CRM) system. According to the company, a malicious threat actor used a social engineering technique to gain unauthorized access to the CRM platform.
The breach was discovered the next day, July 17, 2025, at 12:17 PM CDT, when suspicious activity was detected within the system. Allianz Life terminated access exactly two hours later, at 2:17 PM CDT, to the compromised accounts and began an internal investigation.
Based on the information provided to state regulators and public statements, the threat actor was able to obtain personally identifiable information (PII) related to the majority of Allianz Life’s 1.4 million customers, financial professionals, and select employees.
The exposed data includes names, addresses, dates of birth and Social Security numbers.
The breach was reported to several state attorney general offices, including Maine, Texas, Massachusetts, California, New Hampshire, Washington and Iowa.
Allianz Life responded quickly after discovering the breach. The company immediately terminated access to the affected CRM accounts and launched an internal investigation, supported by a leading cyber forensic consultant. They contacted the FBI and have been working with federal law enforcement throughout the process.
Additionally, Allianz Life temporarily shut down its secure customer and financial professional website over the weekend of July 19 and 20 to implement heightened security monitoring.
The company has also put in place stricter controls for payments and customer account changes, as well as enhanced analysis and authentication for any transactions initiated since the incident. Allianz Life is in the process of notifying affected individuals and is offering two years of complimentary identity monitoring services to those impacted.
Given the nature of the breach—where Social Security numbers, dates of birth and other sensitive PII were exposed—affected individuals should remain vigilant.
It is recommended to:
The company’s investigation is ongoing and additional updates will be provided as more information becomes available.
For more information about the company, visit Allianz Life’s website.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.