Company Details
liberty-mutual-insurance
37,367
509,258
524
libertymutualgroup.com
0
LIB_1659307
In-progress


Liberty Mutual Insurance Company CyberSecurity Posture
libertymutualgroup.comAt Liberty Mutual, we believe progress happens when people feel secure. For more than 110 years we have helped people and businesses embrace today and confidently pursue tomorrow by providing protection for the unexpected and delivering it with care. A Fortune 100 company with more than 40,000 employees in 28 countries and economies, we are the ninth largest global property and casualty insurer and generate more than $50 billion in annual consolidated revenue. We operate through three strategic business units: US Retail Markets, providing auto, home, renters and other personal and small commercial lines property and casualty insurance to individuals and small businesses countrywide; Global Risk Solutions, delivering a full range of comprehensive commercial and specialty insurance, reinsurance and surety solutions to mid-size and large businesses worldwide; and Liberty Mutual Investments, deploying more than $100 billion of long-term capital globally across its integrated platform to drive economic growth, power innovation and secure Liberty Mutual’s promises. For more information, visit www.libertymutualinsurance.com.
Company Details
liberty-mutual-insurance
37,367
509,258
524
libertymutualgroup.com
0
LIB_1659307
In-progress
Between 750 and 799

LMI Global Score (TPRM)XXXX

Description: The California Office of the Attorney General reported a data breach involving Liberty Mutual Group, Inc. on March 30, 2021. The breach occurred between November 21, 2020, and March 12, 2021, during which an unauthorized third party may have accessed individuals' driver’s license numbers and personal information via fraudulent auto insurance applications. The exact number of individuals affected remains unknown.
Description: An IT systems breach had hit it. It had suffered unauthorized access to its IT infrastructure. Hackers demanded millions from Liberty Life and threaten to start releasing sensitive data. The hackers have obtained “sensitive data” about “top clients”.


No incidents recorded for Liberty Mutual Insurance in 2026.
No incidents recorded for Liberty Mutual Insurance in 2026.
No incidents recorded for Liberty Mutual Insurance in 2026.
LMI cyber incidents detection timeline including parent company and subsidiaries

At Liberty Mutual, we believe progress happens when people feel secure. For more than 110 years we have helped people and businesses embrace today and confidently pursue tomorrow by providing protection for the unexpected and delivering it with care. A Fortune 100 company with more than 40,000 employees in 28 countries and economies, we are the ninth largest global property and casualty insurer and generate more than $50 billion in annual consolidated revenue. We operate through three strategic business units: US Retail Markets, providing auto, home, renters and other personal and small commercial lines property and casualty insurance to individuals and small businesses countrywide; Global Risk Solutions, delivering a full range of comprehensive commercial and specialty insurance, reinsurance and surety solutions to mid-size and large businesses worldwide; and Liberty Mutual Investments, deploying more than $100 billion of long-term capital globally across its integrated platform to drive economic growth, power innovation and secure Liberty Mutual’s promises. For more information, visit www.libertymutualinsurance.com.


💛 We're a leading Insurance, Wealth & Retirement business. 📣 Follow for #LifeAtAviva. Aviva is nothing without our people. Living up to our purpose to be with you today for a better tomorrow applies to those we work with just as much as it does to our customers. We want Aviva to be a pla
Assurant is a leading global business services company that supports, protects, and connects major consumer purchases. A Fortune 500 company with a presence in 21 countries, Assurant supports the advancement of the connected world by partnering with the world’s leading brands to develop innovative s

QBE is an international insurer and reinsurer listed on the Australian Securities Exchange and headquartered in Sydney. We employ over 13,000 people in 26 countries. Leveraging our deep expertise and insights, QBE offers commercial, personal and specialty products and risk management solutions to h

Munich Re is one of the world’s leading providers of reinsurance, primary insurance and insurance-related risk solutions. The group consists of the reinsurance and ERGO business segments, as well as the capital investment company MEAG. We are globally active and operate in all lines of the insurance

American International Group, Inc. (NYSE: AIG) is a leading global insurance organization. AIG provides insurance solutions that help businesses and individuals in approximately 190 countries and jurisdictions protect their assets and manage risks through AIG operations and network partners. Additi

Tokio Marine Group is a global insurance group that provides safety and security to customers worldwide. The Group consists of Tokio Marine Holdings and over 250 subsidiaries and 26 affiliates located in more than 480 cities in 46 countries and regions worldwide, operating extensively in the non-li

Helvetia Baloise is the largest multi-line insurer in Switzerland and one of the leading insurance groups in Europe. Every day, more than 22,000 employees are committed to supporting around 13 million customers with insurance, pension and financial solutions – from private individuals and SMEs to in

At Anthem Blue Cross and Blue Shield we understand our health connects us to each other. What we all do impacts those around us. So Anthem is dedicated to delivering better care to our members, providing greater value to our customers and helping improve the health of our communities. Independent l

Founded in October 1949, The People’s Insurance Company (Group) of China is the first nation-wide insurance company in the People’s Republic of China and has developed into a leading large-scale integrated insurance financial group in the PRC, ranking 208th on the Global 500 (2014) published by the
.png)
Insurers writing standalone cyber insurance products reported $1.11 bn in direct written premiums spread among 46 groups of insurers (140...
Best Stand-Alone Cyber Security Insurance Companies in the U.S. rankings highlight key players in the cybersecurity insurance market based...
More than 150 people attended the 11th annual conference, organized jointly by faculty members in the Departments of Computer Science and...
The Trump Administration raised alarm for some and relief for others with its February 2025 announcement of a “pause” of anti-corruption...
New York State is securing more than $19 million in penalties from eight auto insurance providers for violations of the state's...
The cyber risk landscape has become increasingly unpredictable, with threats evolving faster than many organizations can adapt.
New York State Department of Financial Services (DFS) Superintendent Adrienne A. Harris has collected more than $19 million in penalties for...
Eight auto insurers failed to meet the requirements of New York's cybersecurity regulations during widespread online attacks in 2021 and...
New York DFS fined eight auto insurers and agencies $19 mn for weak cybersecurity controls that exposed personal data through online quoting...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Liberty Mutual Insurance is http://www.libertymutualgroup.com.
According to Rankiteo, Liberty Mutual Insurance’s AI-generated cybersecurity score is 778, reflecting their Fair security posture.
According to Rankiteo, Liberty Mutual Insurance currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Liberty Mutual Insurance has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Liberty Mutual Insurance is not certified under SOC 2 Type 1.
According to Rankiteo, Liberty Mutual Insurance does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Liberty Mutual Insurance is not listed as GDPR compliant.
According to Rankiteo, Liberty Mutual Insurance does not currently maintain PCI DSS compliance.
According to Rankiteo, Liberty Mutual Insurance is not compliant with HIPAA regulations.
According to Rankiteo,Liberty Mutual Insurance is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Liberty Mutual Insurance operates primarily in the Insurance industry.
Liberty Mutual Insurance employs approximately 37,367 people worldwide.
Liberty Mutual Insurance presently has no subsidiaries across any sectors.
Liberty Mutual Insurance’s official LinkedIn profile has approximately 509,258 followers.
Liberty Mutual Insurance is classified under the NAICS code 524, which corresponds to Insurance Carriers and Related Activities.
No, Liberty Mutual Insurance does not have a profile on Crunchbase.
Yes, Liberty Mutual Insurance maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/liberty-mutual-insurance.
As of January 22, 2026, Rankiteo reports that Liberty Mutual Insurance has experienced 2 cybersecurity incidents.
Liberty Mutual Insurance has an estimated 15,156 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach and Cyber Attack.
Title: Liberty Life IT Systems Breach
Description: An unauthorized access to Liberty Life's IT infrastructure resulted in hackers demanding millions and threatening to release sensitive data about top clients.
Type: Data Breach
Threat Actor: Hackers
Motivation: Financial Gain
Title: Liberty Mutual Group Data Breach
Description: The California Office of the Attorney General reported a data breach involving Liberty Mutual Group, Inc. on March 30, 2021. The breach dates are between November 21, 2020, and March 12, 2021, during which an unauthorized third party may have accessed individuals' driver’s license numbers and personal information via fraudulent auto insurance applications. The exact number of individuals affected remains unknown.
Date Detected: 2021-03-30
Date Publicly Disclosed: 2021-03-30
Type: Data Breach
Attack Vector: Fraudulent auto insurance applications
Threat Actor: Unauthorized third party
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Sensitive data about top clients

Data Compromised: Driver’s license numbers, Personal information
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Sensitive data, Driver’S License Numbers, Personal Information and .

Entity Name: Liberty Life
Entity Type: Insurance Company
Industry: Insurance

Entity Name: Liberty Mutual Group, Inc.
Entity Type: Insurance Company
Industry: Insurance

Type of Data Compromised: Sensitive data
Sensitivity of Data: High

Type of Data Compromised: Driver’s license numbers, Personal information

Ransom Demanded: Millions

Source: California Office of the Attorney General
Date Accessed: 2021-03-30
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2021-03-30.

High Value Targets: Top clients
Data Sold on Dark Web: Top clients
Last Ransom Demanded: The amount of the last ransom demanded was Millions.
Last Attacking Group: The attacking group in the last incident were an Hackers and Unauthorized third party.
Most Recent Incident Detected: The most recent incident detected was on 2021-03-30.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2021-03-30.
Most Significant Data Compromised: The most significant data compromised in an incident were Sensitive data about top clients, Driver’s license numbers, Personal information and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Driver’s license numbers, Personal information and Sensitive data about top clients.
Highest Ransom Demanded: The highest ransom demanded in a ransomware incident was Millions.
Most Recent Source: The most recent source of information about an incident is California Office of the Attorney General.
.png)
SummaryA command injection vulnerability (CWE-78) has been found to exist in the `wrangler pages deploy` command. The issue occurs because the `--commit-hash` parameter is passed directly to a shell command without proper validation or sanitization, allowing an attacker with control of `--commit-hash` to execute arbitrary commands on the system running Wrangler. Root causeThe commitHash variable, derived from user input via the --commit-hash CLI argument, is interpolated directly into a shell command using template literals (e.g., execSync(`git show -s --format=%B ${commitHash}`)). Shell metacharacters are interpreted by the shell, enabling command execution. ImpactThis vulnerability is generally hard to exploit, as it requires --commit-hash to be attacker controlled. The vulnerability primarily affects CI/CD environments where `wrangler pages deploy` is used in automated pipelines and the --commit-hash parameter is populated from external, potentially untrusted sources. An attacker could exploit this to: * Run any shell command. * Exfiltrate environment variables. * Compromise the CI runner to install backdoors or modify build artifacts. Credits Disclosed responsibly by kny4hacker. Mitigation * Wrangler v4 users are requested to upgrade to Wrangler v4.59.1 or higher. * Wrangler v3 users are requested to upgrade to Wrangler v3.114.17 or higher. * Users on Wrangler v2 (EOL) should upgrade to a supported major version.
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.