Código HTML do Conteúdo

Post: Allianz Life Data Breach Exposes Personal Data of 1.1 Million - Against Invaders - Notícias de CyberSecurity para humanos.


<div data-edit-folder-name="text" data-index="0" data-layout-id="2" id="layout-012706ed-e75e-44c1-b7e8-e0c15994b805"> <p>A cyber-attack on Allianz Life in July has exposed the personal information of about 1.1 million customers, according to new data byHave I Been Pwned.</p> <p>The breach targeted a cloud-based customer relationship management (CRM) system and is part of a larger campaign against companies using Salesforce-hosted databases.</p> <p>Allianz Life, a US subsidiary of German insurer Allianz SE, said hackers accessed data from<a href="https://www.infosecurity-magazine.com/news/third-party-breach-allianz/" target="_blank"> </a><a href="https://www.infosecurity-magazine.com/news/third-party-breach-allianz/" target="_blank">&ldquo;the majority&rdquo;of its 1.4 million customers</a>, financial professionals and employees. The company confirmed that attackers obtained personal details but did not provide specific figures at the time.</p> <p>Have I Been Pwned reported that the breach includes:</p> <ul> <li> <p>Names</p> </li> <li> <p>Dates of birth</p> </li> <li> <p>Gender</p> </li> <li> <p>Email addresses</p> </li> <li> <p>Phone numbers</p> </li> <li> <p>Home addresses</p> </li> </ul> <p>In state filings, Allianz also disclosed that Social Security numbers were taken.</p> <p>&ldquo;The stolen personal information of 1.1 million customers is significant,&rdquo;said Jon Abbott, CEO of ThreatAware.</p> <p>&ldquo;The sensitive and valuable information held in CRM tools is exactly why it&rsquo;s targeted by attackers. The data can be used by other cybercriminals for identity theft and phishing campaigns.&rdquo;</p> <h2>Attack Linkedto ShinyHunters</h2> <p>Security researchers have tied the incident to <a href="https://www.infosecurity-magazine.com/news/financial-services-next-line/" target="_blank">ShinyHunters</a>, a hacking group that has recently breached Salesforce systems at Google, Qantas, <a href="https://www.infosecurity-magazine.com/news/workday-reveals-crm-breach/" target="_blank">Workday</a> and several retail brands. The group is known for social engineering tactics that trick employees into providing unauthorized access.</p> <p>&ldquo;Groups such as ShinyHunters rely on fast-moving social engineering tactics &ndash; this typically involves calling and emailing employees of the victim organization and attempting to extort them,&rdquo;Abbott said.</p> <p>&ldquo;If this does not work, they then launch a leak site with the aim of pressuring victims into payment.&rdquo;</p> <p><a href="https://www.infosecurity-magazine.com/news/destructive-attacks-banks-surge-13/" target="_blank"><em>Read more on large-scale cyber-attacks targeting financial services: Destructive Attacks on Financial Institutions Surge</em></a></p> <p>Investigations suggest the attackers used malicious OAuth applications to infiltrate Salesforce instances, then downloaded company databases. In Allianz&rsquo;s case, leaked files reportedly contain millions of records tied not only to policyholders but also to advisors and partner firms.</p> <h2>Company Response and Broader Impact</h2> <p>Allianz Life has not yet commented on the new findings, citing an ongoing investigation. However, the company said it will provide two years of identity monitoring services to affected individuals.</p> <p>Abbott added: &ldquo;This pattern in their [ShinyHunters] attacks is why the security fundamentals are so important. Accurate asset inventories, tamper-proof identity verification and hardened service desk processes are all essential.&rdquo;</p> <p>The Allianz Life breach follows a series of high-profile incidents this year, highlighting <a href="https://www.infosecurity-magazine.com/news/flaw-google-cloud-security-concerns/" target="_blank">concerns about the security of cloud-based systems</a> widely used across the financial and technology sectors.</p> </div>