Allianz – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Fri, 22 Aug 2025 06:58:51 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Allianz – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Allianz endorses Bitcoin as a ‘credible store of value,’ shifting from 2019 anti-crypto stance https://earlybirdsinvest.com/allianz-endorses-bitcoin-as-a-credible-store-of-value-shifting-from-2019-anti-crypto-stance/ https://earlybirdsinvest.com/allianz-endorses-bitcoin-as-a-credible-store-of-value-shifting-from-2019-anti-crypto-stance/#respond Fri, 22 Aug 2025 06:58:51 +0000 https://earlybirdsinvest.com/allianz-endorses-bitcoin-as-a-credible-store-of-value-shifting-from-2019-anti-crypto-stance/

Allianz declared Bitcoin (BTC) a “credible store of value” in a recent investment report, marking the first time the $2.5 trillion asset manager has endorsed digital assets as a legitimate institutional investment.

The report, titled “Bitcoin and Cryptocurrencies: The Future of Finance,” represents a dramatic shift from Allianz’s 2019 policy against Bitcoin investments. 

The German investment giant now characterizes Bitcoin’s evolution from “an experimental protocol into a credible store of value” as fundamental to modern portfolio construction.

The report stated:

“Bitcoin’s deflationary design, decentralised governance, and low correlation to traditional markets have made it an attractive hedge and long-duration asset.” 

Allianz highlighted Bitcoin’s 0.12 correlation with the S&P 500 and negative 0.04 correlation with gold, positioning it as an effective portfolio diversifier.

Institutional adoption drives recognition

Allianz cited accelerating institutional adoption as a key factor in Bitcoin’s legitimization. The report noted that corporate treasuries surpassed exchange-traded funds (ETFs) in Bitcoin purchases for three consecutive quarters through the second quarter, with public companies acquiring approximately 131,000 BTC in the second quarter alone.

The asset manager emphasized university endowments’ emerging crypto strategies, highlighting Emory University as the first U.S. institution to disclose significant Bitcoin investments publicly. 

Allianz characterized this trend as signaling “the integration of digital assets into both operational and investment strategies across higher education.”

Federal Reserve Chairman Jerome Powell’s recent acknowledgment of Bitcoin as a “digital counterpart to gold” further validated institutional acceptance, according to the report. 

Allianz noted that regulatory clarity improvements globally have eliminated major barriers to institutional participation.

Infrastructure maturation enables access

The report credited infrastructure development with facilitating institutional entry. Regulated exchanges like Coinbase, institutional-grade custodians including Fidelity Digital Assets, and SEC-approved spot Bitcoin ETFs have “bridged the gap between traditional finance and crypto.”

Allianz described Bitcoin’s transformation as “one of the most profound shifts in modern finance,” predicting continued integration into mainstream portfolios. 

The firm expects real-world asset tokenization and decentralized finance to “substantially expand crypto’s total addressable market.”

The endorsement carries significant weight given Allianz’s status as one of Europe’s largest asset managers. A piece from the company’s policy issued in 2019 explicitly avoided crypto investments due to regulatory uncertainty and volatility concerns.

Allianz concluded that “barring any unforeseen calamity or global collapse due to technological flaws,” Bitcoin represents a permanent addition to the financial system rather than a speculative trend.

It further stated that digital assets are “not just a complement to but a cornerstone of our global financial future.”

Mentioned in this article
]]>
https://earlybirdsinvest.com/allianz-endorses-bitcoin-as-a-credible-store-of-value-shifting-from-2019-anti-crypto-stance/feed/ 0 54501
ShinyHunters behind Salesforce data theft attacks at Qantas, Allianz Life, and LVMH https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/ https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/#respond Thu, 31 Jul 2025 08:07:00 +0000 https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/

Smiley face hacker

A wave of data breaches impacting companies like Qantas, Allianz Life, LVMH, and Adidas has been linked to the ShinyHunters extortion group, which has been using voice phishing attacks to steal data from Salesforce CRM instances.

In June, Google’s Threat Intelligence Group (GTIG) warned that threat actors tracked as UNC6040 were targeting Salesforce customers in social engineering attacks.

In these attacks, the threat actors impersonated IT support staff in phone calls to targeted employees, attempting to persuade them into visiting Salesforce’s connected app setup page. On this page, they were told to enter a “connection code”, which linked a malicious version of Salesforce’s Data Loader OAuth app to the target’s Salesforce environment.

In some cases, the Data Loader component was renamed to “My Ticket Portal,” to make it more convincing in the attacks.

Prompt to enter connection code
Prompt to enter connection code
Source: Google

GTIG says that these attacks were usually conducted through vishing (voice phishing), but credentials and MFA tokens were also stolen through phishing pages that impersonated Okta login pages.

Around the time of this report, multiple companies reported data breaches involving third-party customer service or cloud-based CRM systems.

LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co. each disclosed unauthorized access to a customer information database, with Tiffany Korea notifying customers the attackers breached a “vendor platform used for managing customer data.”

Adidas, Qantas, and Allianz Life also reported breaches involving third-party systems, with Allianz confirming it was a third-party customer relationship management platform.

“On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life),” an Allianz Life spokesperson told BleepingComputer.

While BleepingComputer has learned that the Qantas data breach also involved a third-party customer relationship management platform, the company will not confirm it is Salesforce. However, previous reporting from local media claims the data was stolen from Qantas’ Salesforce instance.

Furthermore, court documents state that the threat actors targeted “Accounts” and “Contacts” database tables, both of which are Salesforce objects.

While none of these companies have publicly named Salesforce, BleepingComputer has since confirmed that all were targeted in the same campaign detailed by Google.

The attacks have not led to public extortion or data leaks yet, with BleepingComputer learning that the threat actors are attempting to privately extort companies over email, where they name themselves as ShinyHunters.

It is believed that when these extortion attempts fail, the threat actors will release stolen information in a long wave of leaks, similar to ShinyHunter’s previous Snowflake attacks.

Who is ShinyHunters

The breaches have caused confusion among the cybersecurity community and the media, including BleepingComputer, with the attacks attributed to Scattered Spider (tracked by Mandiant as UNC3944), as those threat actors were also targeting the aviation, retail, and insurance sectors around the same time and demonstrated similar tactics.

However, threat actors associated with Scattered Spider tend to perform full-blown network breaches, culminating with data theft and, sometimes, ransomware. ShinyHunters, tracked as UNC6040, on the other hand, tends to focus more on data-theft extortion attacks targeting a particular cloud platform or web application.

It is BleepingComputer’s and some security researchers’ belief that both UNC6040 and UNC3944 consist of overlapping members that communicate within the same online communities. The threat group is also believed to overlap with “The Com,” a network of experienced English-speaking cybercriminals.

“According to Recorded Future intelligence, the overlapping TTPs between known Scattered Spider and ShinyHunters attacks indicate likely some crossover between the two groups,” Allan Liska, an Intelligence Analyst for Recorded Future, told BleepingComputer.

Other researchers have told BleepingComputer that ShinyHunters and Scattered Spider appear to be operating in lockstep, targeting the same industries at the same time, making it harder to attribute attacks.

Some also believe that both groups have ties to threat actors from the now-defunct Lapsus$ hacking group, with reports indicating that one of the recently arrested Scattered Spider hackers was also in Lapsus$.

Another theory is that ShinyHunters is acting as an extortion-as-a-service, where they extort companies on behalf of other threat actors in exchange for a revenue share, similar to how ransomware-as-a-service gangs operate.

This theory is supported by previous conversations BleepingComputer has had with ShinyHunters, where they claimed not to be behind a breach, but just acting as the seller of the stolen data.

These breaches include PowerSchool, Oracle Cloud, the Snowflake data-theft attacks, AT&T, NitroPDF, Wattpad, MathWay, and many more.

ShinyHunters leaking attempting to sell AT&T data breach
ShinyHunters leaking attempting to sell AT&T data breach
Source: BleepingComputer

To muddy the waters further, there have been numerous arrests of people linked to the name “ShinyHunters,” including those who have been arrested for the Snowflake data-theft attacks, breaches at PowerSchool, and the operation of the Breached v2 hacking forum.

Yet even after these arrests, new attacks occur with companies receiving extortion emails stating, “We are ShinyHunters,” referring to themselves as a “collective.”

Protecting Salesforce instances from attacks

In a statement to BleepingComputer, Salesforce emphasized that the platform itself was not compromised, but rather, customers’ accounts are being breached via social engineering.

“Salesforce has not been compromised, and the issues described are not due to any known vulnerability in our platform. While Salesforce builds enterprise-grade security into everything we do, customers also play a critical role in keeping their data safe — especially amid a rise in sophisticated phishing and social engineering attacks,” Salesforce told BleepingComputer.

“We continue to encourage all customers to follow security best practices, including enabling multi-factor authentication (MFA), enforcing the principle of least privilege, and carefully managing connected applications. For more information, please visit: https://www.salesforce.com/blog/protect-against-social-engineering/.”

Salesforce is urging customers to strengthen their security posture by:

  • Enforcing trusted IP ranges for logins
  • Following the principle of least privilege for app permissions
  • Enabling multi-factor authentication (MFA)
  • Restricting use of connected apps and managing access policies
  • Using Salesforce Shield for advanced threat detection, event monitoring, and transaction policies
  • Adding a designated Security Contact for incident communication

Further details on these mitigations can be found in Salesforce’s guidance linked above.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/shinyhunters-behind-salesforce-data-theft-attacks-at-qantas-allianz-life-and-lvmh/feed/ 0 50648
Allianz Life confirms data breach impacts majority of 1.4 million customers https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/ https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/#respond Sun, 27 Jul 2025 07:36:22 +0000 https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/

Allianz logo

Insurance company Allianz Life has confirmed that the personal information for the “majority” of its 1.4 million customers was exposed in a data breach that occurred earlier this month.

“On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life),” an Allianz Life spokesperson told BleepingComputer.

“The threat actor was able to obtain personally identifiable data related to the majority of Allianz Life’s customers, financial professionals, and select Allianz Life employees, using a social engineering technique.”

“We took immediate action to contain and mitigate the issue and notified the FBI. Based on our investigation to-date, there is no evidence the Allianz Life network or other company systems were accessed, including our policy administration system.”

“Our investigation is ongoing and we began the process of reaching out to individuals impacted with dedicated resources to assist them. This incident is related only to Allianz Life, which currently has 1.4 million customers.”

Allianz Life is a US-based provider of annuities and life insurance for over 1.4 million Americans. The company is owned by Allianz SE, a global financial services group headquartered in Germany, serving more than 128 million customers.

The company first revealed the breach in a mandatory filing with Maine’s Attorney General’s Office on Saturday, issuing a placeholder notification alerting of the breach.

“The consumer notice will be provided once Allianz has identified the affected individuals,” reads the placeholder notification.

While Allianz Life declined to answer questions about the threat actor and whether they were being extorted, BleepingComputer has learned that the attack is believed to have been conducted by the ShinyHunters extortion group.

ShinyHunters is a group of threat actors who are linked to multiple high-profile data breaches and attacks, including those against PowerSchool and the SnowFlake attacks, which impacted Santander, Ticketmaster, AT&T, Advance Auto Parts, Neiman Marcus, and Cylance.

While multiple ShinyHunters members have been arrested over the past few years, including a recent arrest in France, the hacking group continues to conduct attacks.

Last month, Mandiant warned that ShinyHunters had begun to target Salesforce CRM customers in social engineering attacks.

During these attacks, the hackers impersonate IT support personnel, requesting the targeted employee accept a connection to Salesforce Data Loader, a client application that allows users to import, export, update, or delete data within Salesforce environments.

Once the connection is accepted, the threat actors use Salesforce Data Loader to exfiltrate data from Salesforce, which is then used to extort the company.

BleepingComputer asked Allianz Life if the CRM is Salesforce, but the spokesperson declined to comment.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/allianz-life-confirms-data-breach-impacts-majority-of-1-4-million-customers/feed/ 0 49912