Allianz, headquartered in Minneapolis, has 1.4 million customers across the United States.
Allianz started sending notices regarding the breach to affected customers on Aug. 1.
In an emailed statement to The Epoch Times, Brett Weinberg, assistant vice president of communications at Allianz Life, said that the company’s investigation into the breach was ongoing.
“While we are not able to offer any additional comment at this time, Allianz Life will be providing dedicated resources, including two years of identity monitoring services, to assist impacted individuals,” he said.
Other victims of such attacks include Adidas, Qantas Airways, Air France–KLM, Cartier, Google, Louis Vuitton, Cisco, Pandora, Dior, and Chanel, the post said.
According to SOCRadar, ShinyHunters does not have a single coordinated team. Instead, it functions as a “decentralized, extortion-as-a-service collective.” and relies on social engineering tactics to access systems rather than exploiting flaws in Salesforce’s infrastructure.
According to Google, the group specializes in voice phishing campaigns designed to compromise organizations’ Salesforce environments.
“Over the past several months, UNC6040 has demonstrated repeated success in breaching networks by having its operators impersonate IT support personnel in convincing telephone-based social engineering engagements,” the post said.
Social Engineering Attacks
A social engineering attack involves deceiving targets to gain control over their computer systems. This may be done by manipulating targets to reveal sensitive information like passwords, and enticing them to download malware or to click on malicious links.“Similar to other social engineering techniques, vishing is effective because it targets human weakness or error rather than a flaw in software or an operating system,” it said.
In most vishing campaigns of 2024, the threat actors impersonated IT support staff while contacting targets, falsely claiming they would resolve connectivity or security issues, according to the report.
Hackers are also increasingly adopting help desk social engineering tactics, CrowdStrike said.
In such campaigns, threat actors impersonate an employee of a company and contact the organization’s IT help desk, seeking to reset passwords and multifactor authentication (MFA).
“IT help desks often require employees seeking password and MFA resets to provide their full name, date of birth, employee ID, and manager name or answer a previously determined security question. However, eCrime actors attempting to socially engineer help desk personnel often accurately respond to these questions,” the report said.
“Much of this information is not necessarily privileged and can be found in public resources and social media sites. Identity data that is typically confidential, such as a Social Security number, is often advertised in underground markets.”







