Company Details
farmersinsurance-group
59
231
81
farmers.com
0
FAR_9185127
In-progress


Farmers Insurance Group Company CyberSecurity Posture
farmers.comFarmers Insurance Group is an American insurer group of automobiles, homes and small businesses and also provides other insurance and financial services products. Farmers Insurance has more than 48,000 exclusive and independent agents and approximately 21,000 employees.
Company Details
farmersinsurance-group
59
231
81
farmers.com
0
FAR_9185127
In-progress
Between 750 and 799

FIG Global Score (TPRM)XXXX

Description: Salesforce Customer Farmers Insurance Hit by Major Data Breach Affecting 1.1 Million Farmers Insurance, a U.S.-based provider, confirmed a data breach impacting 1.1 million customers after an unauthorized actor accessed a third-party database in May 2024. The exposed data included names, addresses, birth dates, driver’s license details, and partial Social Security numbers. The company detected the incident shortly after the intrusion and launched an investigation, notifying law enforcement. Affected individuals were informed on August 22, with regulators confirming the total number of impacted records. While Farmers Insurance did not disclose the compromised vendor, reports from Bleeping Computer indicate the breach involved Salesforce, a frequent target of cybercriminal groups. ShinyHunters, in collaboration with Scattered Spider, claimed responsibility, stating they exploited initial access provided by Scattered Spider to exfiltrate data from Salesforce CRM instances similar to their recent attacks on Google (2.5M records) and suspected breaches at Workday, Qantas, Allianz Life, and Adidas. The attackers used social engineering tactics, tricking employees into approving malicious OAuth apps to gain access to Salesforce systems. This method highlights the growing threat to CRM platforms, which store vast amounts of sensitive data and are increasingly targeted due to their high-value information. Cybersecurity experts noted that the breach underscores vulnerabilities in third-party supply chains, emphasizing the need for continuous vendor risk assessments, zero-trust security models, and proactive monitoring to mitigate similar attacks. The incident also reinforces concerns about human-driven exploits as a primary attack vector, even in otherwise secure enterprise systems.


No incidents recorded for Farmers Insurance Group in 2026.
No incidents recorded for Farmers Insurance Group in 2026.
No incidents recorded for Farmers Insurance Group in 2026.
FIG cyber incidents detection timeline including parent company and subsidiaries

Farmers Insurance Group is an American insurer group of automobiles, homes and small businesses and also provides other insurance and financial services products. Farmers Insurance has more than 48,000 exclusive and independent agents and approximately 21,000 employees.


The RPSG Group is one of India's fastest growing conglomerates with a significant global presence. The Group's businesses include power and energy, carbon black manufacturing, retail, IT-enabled services, FMCG, media and entertainment, and agriculture. In the last few years, the group has grown exp

Connecting businesses with consumers is the heart of commercial prosperity and the cornerstone of Australia Post's commitment to Australian businesses. As connectivity transforms our lives, Australia Post is evolving to meet the future needs of businesses by providing trusted service solutions in et

The Rentokil and Terminix family of brands have come together to form the world’s leading pest control company. With our shared vision, we’ll be expanding our products, services, and technology. And with our combined resources, we’ll do more to power innovation and develop sustainable solutions for

Verisure is the leading provider of peace of mind and protection to residential and small business customers across Europe and Latin America. We deliver professionally-monitored security services to over 6 million customers in 18 countries across Europe and Latin America, with a team of more than

Fosun was founded in 1992. After more than 30 years of development, Fosun has become a global innovation-driven consumer group. Adhering to the mission of creating happier lives for families worldwide, Fosun is committed to creating a global happiness ecosystem fulfilling the needs for families in h

At Rover, everyone has ownership of their work and the opportunity to make a true impact. We believe that being diverse and inclusive is key to our success and encourage every employee to share their unique perspective while being their true self. We believe everyone deserves the unconditional lov

Established in Minneapolis in 1982, Great Clips has grown to be the world's largest and fastest growing salon brand. There are more than 4,400 salons throughout the United States and Canada -- all of them owned by franchisees. Visit us at www.greatclips.com Employment Information for Corporate Empl

Glovo is a pioneering multi-category app connecting users with businesses, and couriers, offering on-demand services from local restaurants, grocers and supermarkets, and high street retail stores. Glovo’s vision is to give everyone easy access to everything within their city, so that our users can
HelloFresh is on a mission to change the way people eat, forever! From our 2011 founding in Europe’s vibrant tech hub Berlin, we’re evolving from the world’s leading meal kit company to the world's leading food solutions group. We delivered 243.3 million meals and reached 7.5 million active custome
.png)
2025 was a big year for cybersecurity, with cyberattacks, data breaches, threat groups reaching new notoriety levels, and, of course,...
Choosing the right insurance provider is a critical decision for anyone seeking reliable coverage and long-term value in Massachusetts.
New York State is securing more than $19 million in penalties from eight auto insurance providers for violations of the state's...
New York State Department of Financial Services (DFS) Superintendent Adrienne A. Harris has collected more than $19 million in penalties for...
Eight auto insurers failed to meet the requirements of New York's cybersecurity regulations during widespread online attacks in 2021 and...
New York DFS fined eight auto insurers and agencies $19 mn for weak cybersecurity controls that exposed personal data through online quoting...
Security failures exposed consumers' personal data collected through insurers' online apps and agent portals used to deliver online auto...
American Family Mutual Insurance, State Auto Mutual Insurance, Metromile, Liberty Mutual, Hagerty Insurance Agency, Farmers Insurance,...
Car insurance price-quote tools that auto-populated with people's sensitive data allowed cybercriminals to commit fraud elsewhere,...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Farmers Insurance Group is http://www.farmers.com.
According to Rankiteo, Farmers Insurance Group’s AI-generated cybersecurity score is 751, reflecting their Fair security posture.
According to Rankiteo, Farmers Insurance Group currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Farmers Insurance Group has been affected by a supply chain cyber incident involving Salesforce, with the incident ID SALFAR1767922939.
According to Rankiteo, Farmers Insurance Group is not certified under SOC 2 Type 1.
According to Rankiteo, Farmers Insurance Group does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Farmers Insurance Group is not listed as GDPR compliant.
According to Rankiteo, Farmers Insurance Group does not currently maintain PCI DSS compliance.
According to Rankiteo, Farmers Insurance Group is not compliant with HIPAA regulations.
According to Rankiteo,Farmers Insurance Group is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Farmers Insurance Group operates primarily in the Consumer Services industry.
Farmers Insurance Group employs approximately 59 people worldwide.
Farmers Insurance Group presently has no subsidiaries across any sectors.
Farmers Insurance Group’s official LinkedIn profile has approximately 231 followers.
Farmers Insurance Group is classified under the NAICS code 81, which corresponds to Other Services (except Public Administration).
No, Farmers Insurance Group does not have a profile on Crunchbase.
Yes, Farmers Insurance Group maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/farmersinsurance-group.
As of January 24, 2026, Rankiteo reports that Farmers Insurance Group has experienced 1 cybersecurity incidents.
Farmers Insurance Group has an estimated 6,261 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Vulnerability.
Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes, and law enforcement notified with yes, and containment measures with investigation launched, unauthorized access contained, and communication strategy with public disclosure on company website, regulator notifications..
Title: Farmers Insurance Data Breach
Description: Farmers Insurance, a U.S.-based insurance provider, was the victim of a significant data breach affecting 1.1 million customers. An unauthorized actor gained access to a third-party database containing sensitive customer information, including names, addresses, birth dates, driver’s license information, and fragments of Social Security numbers. The breach was attributed to the cybercrime groups ShinyHunters and Scattered Spider, who exploited a rogue OAuth app via social engineering to infiltrate Salesforce CRM systems.
Date Detected: May 2024
Date Publicly Disclosed: August 22, 2024
Type: Data Breach
Attack Vector: Social Engineering (Rogue OAuth App)
Vulnerability Exploited: Third-party Salesforce CRM integration
Threat Actor: ShinyHuntersScattered Spider
Motivation: Data Exfiltration and Extortion
Common Attack Types: The most common types of attacks the company has faced is Vulnerability.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Rogue OAuth app via social engineering.

Data Compromised: 1,111,386 records
Systems Affected: Third-party Salesforce CRM database
Brand Reputation Impact: High
Identity Theft Risk: High
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Addresses, Birth Dates, Driver’S License Information, Fragments Of Social Security Numbers and .

Entity Name: Farmers Insurance
Entity Type: Insurance Provider
Industry: Insurance
Location: United States
Customers Affected: 1,111,386

Incident Response Plan Activated: Yes
Law Enforcement Notified: Yes
Containment Measures: Investigation launched, unauthorized access contained
Communication Strategy: Public disclosure on company website, regulator notifications
Incident Response Plan: The company's incident response plan is described as Yes.

Type of Data Compromised: Names, Addresses, Birth dates, Driver’s license information, Fragments of social security numbers
Number of Records Exposed: 1,111,386
Sensitivity of Data: High
Data Exfiltration: Yes
Personally Identifiable Information: Yes
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by investigation launched and unauthorized access contained.

Data Exfiltration: Yes

Regulatory Notifications: Yes

Lessons Learned: The breach highlights the risks of third-party vendor vulnerabilities, particularly in CRM systems like Salesforce. Social engineering remains a primary attack vector, emphasizing the need for robust vendor risk management, zero-trust security models, and ongoing security awareness training. Organizations must also ensure isolation, token rotation, and IP allowlists for third-party integrations.

Recommendations: Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.
Key Lessons Learned: The key lessons learned from past incidents are The breach highlights the risks of third-party vendor vulnerabilities, particularly in CRM systems like Salesforce. Social engineering remains a primary attack vector, emphasizing the need for robust vendor risk management, zero-trust security models, and ongoing security awareness training. Organizations must also ensure isolation, token rotation, and IP allowlists for third-party integrations.

Source: Farmers Insurance Website

Source: Bleeping Computer
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Farmers Insurance Website, and Source: Bleeping Computer.

Investigation Status: Ongoing
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public disclosure on company website and regulator notifications.

Stakeholder Advisories: Monitor for fraud on affected datasets; prepare communications and FAQs for regulators and customers.
Customer Advisories: Affected customers were notified on August 22, 2024, regarding the exposure of their personal information.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Monitor for fraud on affected datasets; prepare communications and FAQs for regulators and customers., Affected customers were notified on August 22, 2024 and regarding the exposure of their personal information..

Entry Point: Rogue OAuth app via social engineering
High Value Targets: Salesforce CRM instances
Data Sold on Dark Web: Salesforce CRM instances

Root Causes: Exploitation of third-party Salesforce CRM integration via social engineering (rogue OAuth app). Lack of sufficient vendor risk management and security controls for third-party access.
Corrective Actions: Enhance vendor risk management, implement zero-trust security models, improve incident response readiness, and conduct ongoing security awareness training.
Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Enhance vendor risk management, implement zero-trust security models, improve incident response readiness, and conduct ongoing security awareness training..
Last Attacking Group: The attacking group in the last incident was an ShinyHuntersScattered Spider.
Most Recent Incident Detected: The most recent incident detected was on May 2024.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on August 22, 2024.
Most Significant Data Compromised: The most significant data compromised in an incident were 1,111 and386 records.
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident were Investigation launched and unauthorized access contained.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were 1,111 and386 records.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.1M.
Most Significant Lesson Learned: The most significant lesson learned from past incidents was The breach highlights the risks of third-party vendor vulnerabilities, particularly in CRM systems like Salesforce. Social engineering remains a primary attack vector, emphasizing the need for robust vendor risk management, zero-trust security models, and ongoing security awareness training. Organizations must also ensure isolation, token rotation, and IP allowlists for third-party integrations.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Adopt zero-trust security models as a standard practice., Treat security awareness as an ongoing discipline to mitigate social engineering risks., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Monitor for fraud on affected datasets and prepare regulatory notifications., Implement robust vendor risk management with ongoing scrutiny of third-party connections. and Enhance incident response readiness with rapid detection and transparent communication..
Most Recent Source: The most recent source of information about an incident are Farmers Insurance Website and Bleeping Computer.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Monitor for fraud on affected datasets; prepare communications and FAQs for regulators and customers., .
Most Recent Customer Advisory: The most recent customer advisory issued were an Affected customers were notified on August 22, 2024 and regarding the exposure of their personal information.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Rogue OAuth app via social engineering.
.png)
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.