Allianz Life reported that a threat actor accessed a third-party customer relationship management system on 16 July 2025 using social engineering, affecting 1,497,036 individuals across customers, financial professionals and some employees. Separately, researchers analysing the published data identified approximately 1.1 million unique records.
Two Numbers, Both Correct, Measuring Different Things
The company’s figure is the notified population: everyone whose data was in the reachable set, which is the standard on which notification obligations are discharged. The researchers’ figure is the count of distinct records actually present in what was published.
The gap has ordinary explanations — duplicates, records the attacker did not publish, individuals appearing in more than one role. What matters is that the corpus routinely quotes one number as though it were the other.
This desk filed the same problem at 25-1105, where "potentially affected" described records that were reachable rather than taken. Reachable, taken, and published are three populations, and almost every affected count in this database is one of the three without saying which.
The Route Is The Campaign’s Signature
Social engineering into a third-party CRM is exactly the mechanism at 25-0806, where callers impersonating IT walked employees through authorising a connected application, and at 25-0813, where operators enrolled their own second factor.
No vulnerability in the platform. No credential defeated by force. A conversation, and an authorisation granted on the real site.
And An Insurer Holds The Join Nobody Else Has
This desk argued at 25-0409 that a health insurer sees the whole care pathway. A life insurer sees a different but comparable set: financial position, dependants, health disclosures made at underwriting, and beneficiary designations.
The affected population here also includes financial professionals — intermediaries whose own client relationships are described in the same records. It is the workforce-data gap at 25-0704 appearing inside a customer breach.
Compiled from public reporting and company disclosures, listed below. The two figures come from different sources measuring different populations and we give both. Corrections: corrections@forensicpost.com.