TechCrunch News 15小时前
Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

美国保险巨头安联人寿(Allianz Life)已确认,在七月中旬发生的一次数据泄露事件中,其大部分客户、财务专业人士及部分员工的个人信息被黑客窃取。公司通过向缅因州总检察长提交的法律文件披露了此次事件,但未立即公布受影响的客户数量。安联人寿发言人证实,一名恶意威胁行为者通过社交工程技术,访问了该公司使用的第三方云端客户关系管理(CRM)系统,并获取了相关人员的个人身份信息。目前,公司已通知联邦调查局(FBI),并表示无证据显示公司网络其他系统受到影响。此次事件发生在保险行业数据泄露频发的大背景下,安全专家指出“Scattered Spider”黑客组织可能与此类攻击有关,该组织擅长利用社交工程手段获取网络访问权限。

🛡️ **客户及员工信息大规模泄露**:安联人寿确认,在七月中旬的一次网络攻击中,其大部分客户、财务专业人士以及部分员工的个人信息被黑客窃取。此次攻击是通过一个第三方云端客户关系管理(CRM)系统进行的,黑客利用了社交工程技术获取了访问权限。

🔍 **事件披露与影响范围**:安联人寿在法律要求下向缅因州总检察长提交了数据泄露报告,但具体受影响的客户数量尚未公布。其母公司安联在全球拥有超过1.25亿客户。公司计划从8月1日起开始通知受影响的个人。

🔒 **安全响应与潜在威胁**:安联人寿已通知FBI,并声明没有证据表明公司网络上的其他系统受到此次攻击的影响。尽管公司未直接归咎于特定黑客组织,但安全研究人员将近期针对保险行业的类似攻击与“Scattered Spider”黑客组织联系起来,该组织以擅长利用社交工程手段(如欺骗性电话)来获取公司网络访问权限而闻名。

U.S. insurance giant Allianz Life has confirmed to TechCrunch that hackers stole the personal information of the “majority” of its customers, financial professionals, and employees during a mid-July data breach.

The company disclosed the data breach on Saturday in a legally required filing with Maine’s attorney general, but did not immediately provide a number of how many Allianz Life customers are affected. Its parent company, Allianz, has more than 125 million private and corporate customers worldwide, according to its website.

When reached by TechCrunch, Allianz Life spokesperson Brett Weinberg confirmed the breach.

“On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life,” referring to a customer relationship management (CRM) database containing information on its customers. “The threat actor was able to obtain personally identifiable data related to the majority of Allianz Life’s customers, financial professionals, and select Allianz Life employees, using a social engineering technique,” the spokesperson said.

Allianz Life said it notified the FBI, and added it had “no evidence” that any other systems on its network were compromised. 

The insurance giant would not say if it had received any communication from the hackers, such as a ransom note. The company also would not attribute the breach to a hacking group. 

Allianz Life is the latest company in the past month to have been hacked during a wave of data breaches targeting the wider insurance industry, including Aflac, a major provider of supplementary health insurance. Security researchers at Google said in June that they were “aware of multiple intrusions” across the insurance sector attributed to Scattered Spider, a collective of hackers and techniques that rely on social engineering techniques, such as deceptively calling and tricking helpdesks into granting them access to a company’s network. 

Prior to targeting insurance companies, the Scattered Spider hackers were seen targeting the U.K. retail industry, as well as the aviation and transportation sectors, and are historically known for hacks targeting Silicon Valley technology giants.

Per the Maine filing, Allianz plans to begin notifying affected individuals around August 1.

Do you know more about the Allianz Life cyberattack? Are you an affected customer or employee? Securely contact this reporter via encrypted message at zackwhittaker.1337 on Signal.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

安联人寿 数据泄露 网络攻击 客户信息 社交工程
相关文章