Badge
11,371 badges added since 01 January 2025
ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Farmers Insurance Group is an American insurer group of automobiles, homes and small businesses and also provides other insurance and financial services products. Farmers Insurance has more than 48,000 exclusive and independent agents and approximately 21,000 employees.

Farmers Insurance Group A.I CyberSecurity Scoring

FIG

Company Details

Linkedin ID:

farmersinsurance-group

Employees number:

59

Number of followers:

231

NAICS:

81

Industry Type:

Consumer Services

Homepage:

farmers.com

IP Addresses:

0

Company ID:

FAR_9185127

Scan Status:

In-progress

AI scoreFIG Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/farmersinsurance-group.jpeg
FIG Consumer Services
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreFIG Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/farmersinsurance-group.jpeg
FIG Consumer Services
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

FIG Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsSupply Chain SourceIncident DetailsView
Farmers Insurance GroupVulnerability10058/2025SalesforceSalesforce
Rankiteo Explanation :
Attack threatening the organization's existence

Description: Salesforce Customer Farmers Insurance Hit by Major Data Breach Affecting 1.1 Million Farmers Insurance, a U.S.-based provider, confirmed a data breach impacting 1.1 million customers after an unauthorized actor accessed a third-party database in May 2024. The exposed data included names, addresses, birth dates, driver’s license details, and partial Social Security numbers. The company detected the incident shortly after the intrusion and launched an investigation, notifying law enforcement. Affected individuals were informed on August 22, with regulators confirming the total number of impacted records. While Farmers Insurance did not disclose the compromised vendor, reports from Bleeping Computer indicate the breach involved Salesforce, a frequent target of cybercriminal groups. ShinyHunters, in collaboration with Scattered Spider, claimed responsibility, stating they exploited initial access provided by Scattered Spider to exfiltrate data from Salesforce CRM instances similar to their recent attacks on Google (2.5M records) and suspected breaches at Workday, Qantas, Allianz Life, and Adidas. The attackers used social engineering tactics, tricking employees into approving malicious OAuth apps to gain access to Salesforce systems. This method highlights the growing threat to CRM platforms, which store vast amounts of sensitive data and are increasingly targeted due to their high-value information. Cybersecurity experts noted that the breach underscores vulnerabilities in third-party supply chains, emphasizing the need for continuous vendor risk assessments, zero-trust security models, and proactive monitoring to mitigate similar attacks. The incident also reinforces concerns about human-driven exploits as a primary attack vector, even in otherwise secure enterprise systems.

Salesforce and Farmers Insurance: Over a Million Records Stolen in Latest CRM Breach After Google & Workday Incidents
Vulnerability
Severity: 100
Impact: 5
Seen: 8/2025
Blog:
Supply Chain Source: SalesforceSalesforce
Rankiteo Explanation
Attack threatening the organization's existence

Description: Salesforce Customer Farmers Insurance Hit by Major Data Breach Affecting 1.1 Million Farmers Insurance, a U.S.-based provider, confirmed a data breach impacting 1.1 million customers after an unauthorized actor accessed a third-party database in May 2024. The exposed data included names, addresses, birth dates, driver’s license details, and partial Social Security numbers. The company detected the incident shortly after the intrusion and launched an investigation, notifying law enforcement. Affected individuals were informed on August 22, with regulators confirming the total number of impacted records. While Farmers Insurance did not disclose the compromised vendor, reports from Bleeping Computer indicate the breach involved Salesforce, a frequent target of cybercriminal groups. ShinyHunters, in collaboration with Scattered Spider, claimed responsibility, stating they exploited initial access provided by Scattered Spider to exfiltrate data from Salesforce CRM instances similar to their recent attacks on Google (2.5M records) and suspected breaches at Workday, Qantas, Allianz Life, and Adidas. The attackers used social engineering tactics, tricking employees into approving malicious OAuth apps to gain access to Salesforce systems. This method highlights the growing threat to CRM platforms, which store vast amounts of sensitive data and are increasingly targeted due to their high-value information. Cybersecurity experts noted that the breach underscores vulnerabilities in third-party supply chains, emphasizing the need for continuous vendor risk assessments, zero-trust security models, and proactive monitoring to mitigate similar attacks. The incident also reinforces concerns about human-driven exploits as a primary attack vector, even in otherwise secure enterprise systems.

Ailogo

FIG Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for FIG

Incidents vs Consumer Services Industry Average (This Year)

No incidents recorded for Farmers Insurance Group in 2026.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Farmers Insurance Group in 2026.

Incident Types FIG vs Consumer Services Industry Avg (This Year)

No incidents recorded for Farmers Insurance Group in 2026.

Incident History — FIG (X = Date, Y = Severity)

FIG cyber incidents detection timeline including parent company and subsidiaries

FIG Company Subsidiaries

SubsidiaryImage

Farmers Insurance Group is an American insurer group of automobiles, homes and small businesses and also provides other insurance and financial services products. Farmers Insurance has more than 48,000 exclusive and independent agents and approximately 21,000 employees.

Loading...
similarCompanies

FIG Similar Companies

RP Sanjiv Goenka Group

The RPSG Group is one of India's fastest growing conglomerates with a significant global presence. The Group's businesses include power and energy, carbon black manufacturing, retail, IT-enabled services, FMCG, media and entertainment, and agriculture. In the last few years, the group has grown exp

Australia Post

Connecting businesses with consumers is the heart of commercial prosperity and the cornerstone of Australia Post's commitment to Australian businesses. As connectivity transforms our lives, Australia Post is evolving to meet the future needs of businesses by providing trusted service solutions in et

Rentokil Terminix

The Rentokil and Terminix family of brands have come together to form the world’s leading pest control company. With our shared vision, we’ll be expanding our products, services, and technology. And with our combined resources, we’ll do more to power innovation and develop sustainable solutions for

Verisure

Verisure is the leading provider of peace of mind and protection to residential and small business customers across Europe and Latin America. We deliver professionally-monitored security services to over 6 million customers in 18 countries across Europe and Latin America, with a team of more than

Fosun 复星

Fosun was founded in 1992. After more than 30 years of development, Fosun has become a global innovation-driven consumer group. Adhering to the mission of creating happier lives for families worldwide, Fosun is committed to creating a global happiness ecosystem fulfilling the needs for families in h

Rover.com

At Rover, everyone has ownership of their work and the opportunity to make a true impact. We believe that being diverse and inclusive is key to our success and encourage every employee to share their unique perspective while being their true self. We believe everyone deserves the unconditional lov

Great Clips Inc.

Established in Minneapolis in 1982, Great Clips has grown to be the world's largest and fastest growing salon brand. There are more than 4,400 salons throughout the United States and Canada -- all of them owned by franchisees. Visit us at www.greatclips.com Employment Information for Corporate Empl

Glovo is a pioneering multi-category app connecting users with businesses, and couriers, offering on-demand services from local restaurants, grocers and supermarkets, and high street retail stores. Glovo’s vision is to give everyone easy access to everything within their city, so that our users can

HelloFresh

HelloFresh is on a mission to change the way people eat, forever! From our 2011 founding in Europe’s vibrant tech hub Berlin, we’re evolving from the world’s leading meal kit company to the world's leading food solutions group. We delivered 243.3 million meals and reached 7.5 million active custome

newsone

FIG CyberSecurity News

January 01, 2026 08:00 AM
The biggest cybersecurity and cyberattack stories of 2025

2025 was a big year for cybersecurity, with cyberattacks, data breaches, threat groups reaching new notoriety levels, and, of course,...

December 01, 2025 08:00 AM
10 biggest insurance companies in Massachusetts by market share

Choosing the right insurance provider is a critical decision for anyone seeking reliable coverage and long-term value in Massachusetts.

November 03, 2025 08:00 AM
8 Auto Insurance Providers to Pay $19M Over Data Breaches

New York State is securing more than $19 million in penalties from eight auto insurance providers for violations of the state's...

October 22, 2025 07:00 AM
New York fines eight auto insurers $19 million over cybersecurity violations

New York State Department of Financial Services (DFS) Superintendent Adrienne A. Harris has collected more than $19 million in penalties for...

October 21, 2025 07:00 AM
NY auto insurers on the hook for $19M for cybersecurity violations

Eight auto insurers failed to meet the requirements of New York's cybersecurity regulations during widespread online attacks in 2021 and...

October 21, 2025 07:00 AM
New York fines 8 auto insurers $19 mn over cybersecurity violations, data breaches

New York DFS fined eight auto insurers and agencies $19 mn for weak cybersecurity controls that exposed personal data through online quoting...

October 16, 2025 07:00 AM
New York Fines Auto Insurers $19M Over Cyber Lapses

Security failures exposed consumers' personal data collected through insurers' online apps and agent portals used to deliver online auto...

October 16, 2025 07:00 AM
Over half a dozen insurers fined by New York over data breaches

American Family Mutual Insurance, State Auto Mutual Insurance, Metromile, Liberty Mutual, Hagerty Insurance Agency, Farmers Insurance,...

October 15, 2025 07:00 AM
New York secures $14 million in fines from 8 car insurance companies after data breaches

Car insurance price-quote tools that auto-populated with people's sensitive data allowed cybercriminals to commit fraud elsewhere,...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

FIG CyberSecurity History Information

Official Website of Farmers Insurance Group

The official website of Farmers Insurance Group is http://www.farmers.com.

Farmers Insurance Group’s AI-Generated Cybersecurity Score

According to Rankiteo, Farmers Insurance Group’s AI-generated cybersecurity score is 751, reflecting their Fair security posture.

How many security badges does Farmers Insurance Group’ have ?

According to Rankiteo, Farmers Insurance Group currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Has Farmers Insurance Group been affected by any supply chain cyber incidents ?

According to Rankiteo, Farmers Insurance Group has been affected by a supply chain cyber incident involving Salesforce, with the incident ID SALFAR1767922939.

Does Farmers Insurance Group have SOC 2 Type 1 certification ?

According to Rankiteo, Farmers Insurance Group is not certified under SOC 2 Type 1.

Does Farmers Insurance Group have SOC 2 Type 2 certification ?

According to Rankiteo, Farmers Insurance Group does not hold a SOC 2 Type 2 certification.

Does Farmers Insurance Group comply with GDPR ?

According to Rankiteo, Farmers Insurance Group is not listed as GDPR compliant.

Does Farmers Insurance Group have PCI DSS certification ?

According to Rankiteo, Farmers Insurance Group does not currently maintain PCI DSS compliance.

Does Farmers Insurance Group comply with HIPAA ?

According to Rankiteo, Farmers Insurance Group is not compliant with HIPAA regulations.

Does Farmers Insurance Group have ISO 27001 certification ?

According to Rankiteo,Farmers Insurance Group is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Farmers Insurance Group

Farmers Insurance Group operates primarily in the Consumer Services industry.

Number of Employees at Farmers Insurance Group

Farmers Insurance Group employs approximately 59 people worldwide.

Subsidiaries Owned by Farmers Insurance Group

Farmers Insurance Group presently has no subsidiaries across any sectors.

Farmers Insurance Group’s LinkedIn Followers

Farmers Insurance Group’s official LinkedIn profile has approximately 231 followers.

NAICS Classification of Farmers Insurance Group

Farmers Insurance Group is classified under the NAICS code 81, which corresponds to Other Services (except Public Administration).

Farmers Insurance Group’s Presence on Crunchbase

No, Farmers Insurance Group does not have a profile on Crunchbase.

Farmers Insurance Group’s Presence on LinkedIn

Yes, Farmers Insurance Group maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/farmersinsurance-group.

Cybersecurity Incidents Involving Farmers Insurance Group

As of January 24, 2026, Rankiteo reports that Farmers Insurance Group has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Farmers Insurance Group has an estimated 6,261 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Farmers Insurance Group ?

Incident Types: The types of cybersecurity incidents that have occurred include Vulnerability.

How does Farmers Insurance Group detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes, and law enforcement notified with yes, and containment measures with investigation launched, unauthorized access contained, and communication strategy with public disclosure on company website, regulator notifications..

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Farmers Insurance Data Breach

Description: Farmers Insurance, a U.S.-based insurance provider, was the victim of a significant data breach affecting 1.1 million customers. An unauthorized actor gained access to a third-party database containing sensitive customer information, including names, addresses, birth dates, driver’s license information, and fragments of Social Security numbers. The breach was attributed to the cybercrime groups ShinyHunters and Scattered Spider, who exploited a rogue OAuth app via social engineering to infiltrate Salesforce CRM systems.

Date Detected: May 2024

Date Publicly Disclosed: August 22, 2024

Type: Data Breach

Attack Vector: Social Engineering (Rogue OAuth App)

Vulnerability Exploited: Third-party Salesforce CRM integration

Threat Actor: ShinyHuntersScattered Spider

Motivation: Data Exfiltration and Extortion

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Vulnerability.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Rogue OAuth app via social engineering.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach SALFAR1767922939

Data Compromised: 1,111,386 records

Systems Affected: Third-party Salesforce CRM database

Brand Reputation Impact: High

Identity Theft Risk: High

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Names, Addresses, Birth Dates, Driver’S License Information, Fragments Of Social Security Numbers and .

Which entities were affected by each incident ?

Incident : Data Breach SALFAR1767922939

Entity Name: Farmers Insurance

Entity Type: Insurance Provider

Industry: Insurance

Location: United States

Customers Affected: 1,111,386

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Data Breach SALFAR1767922939

Incident Response Plan Activated: Yes

Law Enforcement Notified: Yes

Containment Measures: Investigation launched, unauthorized access contained

Communication Strategy: Public disclosure on company website, regulator notifications

What is the company's incident response plan?

Incident Response Plan: The company's incident response plan is described as Yes.

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach SALFAR1767922939

Type of Data Compromised: Names, Addresses, Birth dates, Driver’s license information, Fragments of social security numbers

Number of Records Exposed: 1,111,386

Sensitivity of Data: High

Data Exfiltration: Yes

Personally Identifiable Information: Yes

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by investigation launched and unauthorized access contained.

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : Data Breach SALFAR1767922939

Data Exfiltration: Yes

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Data Breach SALFAR1767922939

Regulatory Notifications: Yes

Lessons Learned and Recommendations

What lessons were learned from each incident ?

Incident : Data Breach SALFAR1767922939

Lessons Learned: The breach highlights the risks of third-party vendor vulnerabilities, particularly in CRM systems like Salesforce. Social engineering remains a primary attack vector, emphasizing the need for robust vendor risk management, zero-trust security models, and ongoing security awareness training. Organizations must also ensure isolation, token rotation, and IP allowlists for third-party integrations.

What recommendations were made to prevent future incidents ?

Incident : Data Breach SALFAR1767922939

Recommendations: Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.Implement robust vendor risk management with ongoing scrutiny of third-party connections., Adopt zero-trust security models as a standard practice., Enhance incident response readiness with rapid detection and transparent communication., Monitor for fraud on affected datasets and prepare regulatory notifications., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Treat security awareness as an ongoing discipline to mitigate social engineering risks.

What are the key lessons learned from past incidents ?

Key Lessons Learned: The key lessons learned from past incidents are The breach highlights the risks of third-party vendor vulnerabilities, particularly in CRM systems like Salesforce. Social engineering remains a primary attack vector, emphasizing the need for robust vendor risk management, zero-trust security models, and ongoing security awareness training. Organizations must also ensure isolation, token rotation, and IP allowlists for third-party integrations.

References

Where can I find more information about each incident ?

Incident : Data Breach SALFAR1767922939

Source: Farmers Insurance Website

Incident : Data Breach SALFAR1767922939

Source: Bleeping Computer

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Farmers Insurance Website, and Source: Bleeping Computer.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Data Breach SALFAR1767922939

Investigation Status: Ongoing

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public disclosure on company website and regulator notifications.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Data Breach SALFAR1767922939

Stakeholder Advisories: Monitor for fraud on affected datasets; prepare communications and FAQs for regulators and customers.

Customer Advisories: Affected customers were notified on August 22, 2024, regarding the exposure of their personal information.

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Monitor for fraud on affected datasets; prepare communications and FAQs for regulators and customers., Affected customers were notified on August 22, 2024 and regarding the exposure of their personal information..

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Data Breach SALFAR1767922939

Entry Point: Rogue OAuth app via social engineering

High Value Targets: Salesforce CRM instances

Data Sold on Dark Web: Salesforce CRM instances

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Data Breach SALFAR1767922939

Root Causes: Exploitation of third-party Salesforce CRM integration via social engineering (rogue OAuth app). Lack of sufficient vendor risk management and security controls for third-party access.

Corrective Actions: Enhance vendor risk management, implement zero-trust security models, improve incident response readiness, and conduct ongoing security awareness training.

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Enhance vendor risk management, implement zero-trust security models, improve incident response readiness, and conduct ongoing security awareness training..

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an ShinyHuntersScattered Spider.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on May 2024.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on August 22, 2024.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were 1,111 and386 records.

Response to the Incidents

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident were Investigation launched and unauthorized access contained.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were 1,111 and386 records.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 1.1M.

Lessons Learned and Recommendations

What was the most significant lesson learned from past incidents ?

Most Significant Lesson Learned: The most significant lesson learned from past incidents was The breach highlights the risks of third-party vendor vulnerabilities, particularly in CRM systems like Salesforce. Social engineering remains a primary attack vector, emphasizing the need for robust vendor risk management, zero-trust security models, and ongoing security awareness training. Organizations must also ensure isolation, token rotation, and IP allowlists for third-party integrations.

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Adopt zero-trust security models as a standard practice., Treat security awareness as an ongoing discipline to mitigate social engineering risks., Request confirmation of isolation, token rotation, and IP allowlists for shared CRM integrations., Monitor for fraud on affected datasets and prepare regulatory notifications., Implement robust vendor risk management with ongoing scrutiny of third-party connections. and Enhance incident response readiness with rapid detection and transparent communication..

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Farmers Insurance Website and Bleeping Computer.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.

Stakeholder and Customer Advisories

What was the most recent stakeholder advisory issued ?

Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Monitor for fraud on affected datasets; prepare communications and FAQs for regulators and customers., .

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued were an Affected customers were notified on August 22, 2024 and regarding the exposure of their personal information.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an Rogue OAuth app via social engineering.

cve

Latest Global CVEs (Not Company-Specific)

Description

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Description

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.

Description

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.

Description

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

Risk Information
cvss3
Base: 6.0
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
cvss4
Base: 6.0
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=farmersinsurance-group' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge