Allianz Life suffers a data breach via a third-party cloud CRM
Allianz Life reported that an actor gained access via social engineering to a third-party cloud CRM and obtained personal information from a large portion of its clients, financial professionals, and some employees in the United States.

News summary
Allianz Life reported that an actor gained access via social engineering to a third-party cloud CRM and obtained personal information from a large portion of its clients, financial professionals, and some employees in the United States.
An external CRM can be just as critical as an internal server. Its access controls, logs, permissions, and support procedures must be integrated into the same security model.
Source: Reuters — 26 July 2025
What happened
Allianz Life disclosed on 26 July 2025 that an actor had gained access, through social engineering, to a third-party cloud CRM and obtained personal information belonging to the majority of its customers, financial professionals and some employees in the United States, according to Reuters.
Access was not gained by exploiting a technical vulnerability in the CRM but by tricking someone with the ability to obtain access to the system, a common technique in this type of incident.
What it means for a mid-sized business
The case makes clear that a third-party CRM can be as critical as an internal server. Its access, logs, permissions and support procedures must fall under the same security model as the rest of the company's systems, not be treated as a secondary tool.
Many SMEs concentrate customer data in SaaS CRM or marketing platforms without applying the same controls used for internal systems, exposing them to the same type of risk Allianz Life suffered.
What to review
Controls to apply to third-party CRM and SaaS platforms:
- What identity verification procedure the CRM provider requires before granting or resetting access.
- Whether CRM access requires phishing-resistant multi-factor authentication.
- What customer data is stored in the CRM and whether that amount of information is justified.
- Whether an auditable log of access and permission changes exists for the platform.
Frequently Asked Questions
- How did the attackers gain access?
- According to the company, through social engineering aimed at gaining access to a third-party cloud CRM.
- What information was affected?
- Personal information belonging to the majority of the company's customers, financial professionals and some employees in the United States.
- Which measure best reduces this risk?
- Requiring strict identity verification and phishing-resistant two-factor authentication on any SaaS platform handling customer data.
Concepts mentioned in this article: Cloud
This type of news demonstrates that cybersecurity, cloud, and business continuity must be planned together. Seintec can help you achieve this in your organisation; contact us.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.