ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Marathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.

Marathon Petroleum Corporation A.I CyberSecurity Scoring

MPC

Company Details

Linkedin ID:

marathon-petroleum-company

Employees number:

16,023

Number of followers:

336,851

NAICS:

211

Industry Type:

Oil and Gas

Homepage:

marathonpetroleum.com

IP Addresses:

41

Company ID:

MAR_2224870

Scan Status:

Completed

AI scoreMPC Risk Score (AI oriented)

Between 800 and 849

https://images.rankiteo.com/companyimages/marathon-petroleum-company.jpeg
MPC Oil and Gas
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreMPC Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/marathon-petroleum-company.jpeg
MPC Oil and Gas
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

MPC Company CyberSecurity News & History

Past Incidents
0
Attack Types
0
No data available
Ailogo

MPC Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for MPC

Incidents vs Oil and Gas Industry Average (This Year)

No incidents recorded for Marathon Petroleum Corporation in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Marathon Petroleum Corporation in 2025.

Incident Types MPC vs Oil and Gas Industry Avg (This Year)

No incidents recorded for Marathon Petroleum Corporation in 2025.

Incident History — MPC (X = Date, Y = Severity)

MPC cyber incidents detection timeline including parent company and subsidiaries

MPC Company Subsidiaries

SubsidiaryImage

Marathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.

Loading...
similarCompanies

MPC Similar Companies

TechnipFMC

TechnipFMC is a leading technology provider to the traditional and new energies industry, delivering fully integrated projects, products, and services. With our proprietary technologies and comprehensive solutions, we are transforming our clients’ project economics, helping them unlock new possibi

Koch Engineered Solutions

Koch Engineered Solutions (KES) provides uniquely engineered solutions in construction; mass and heat transfer; combustion and emissions controls; filtration; separation; materials applications; automation and actuation. KES is located in Wichita, Kansas, and is a subsidiary of Koch Industries, one

We’re a leading producer of the energy and chemicals that drive global commerce and enhance the daily lives of people around the globe by continuing delivering an uninterrupted supply of energy to the world. Our resilience and agility has built one of the world’s largest integrated energy and chemi

aramco

We’re a leading producer of the energy and chemicals that drive global commerce and enhance the daily lives of people around the globe by continuing delivering an uninterrupted supply of energy to the world. Our resilience and agility has built one of the world’s largest integrated energy and chemi

PDVSA Petróleos de Venezuela S.A.

Petróleos de Venezuela S.A. is a Venezuelan state company, began operations on January 1st, 1976 and whose activities are the oil exploration, production, refining, marketing and transportation of Venezuelan oil as well as the orimulsion, chemical, petrochemical businesses and coal. We have the lar

Bharat Petroleum Corporation Limited

Fortune Global 500 Company, Bharat Petroleum is the second largest Indian Oil Marketing Company and one of the premier integrated energy companies in India, engaged in refining of crude oil and marketing of petroleum products, with a significant presence in the upstream and downstream sectors of the

Shell

Shell is a global group of energy and petrochemical companies, employing 103,000 people and with operations in more than 70 countries. We serve more than 1 million commercial and industrial customers, and around 33 million customers daily at more than 47,000 Shell-branded retail service stations. O

RussNeft

ОАО Oil and Gas Company «RussNeft» came into existence in September 2002 . The structure of OAO NK “RussNeft” counts 24 upstream enterprises, 2 refineries, its own distribution net of gas filling stations. Geographic reach of “RussNeft” covers 12 regions of Russia and CIS: Khanty-Mansi Autonomous

Cameron, a Schlumberger company

Cameron is a SLB company. For updates and information, please follow the main SLB company page on LinkedIn at: https://www.linkedin.com/company/slbglobal/ Cameron, a SLB company, is a leading provider of flow equipment products, systems and services to worldwide oil, gas and process industries. Lev

newsone

MPC CyberSecurity News

November 04, 2025 08:00 AM
Marathon Petroleum (NYSE: MPC) elects CEO Maryann T. Mannen as chairman Jan. 1, 2026

Maryann T. Mannen, president and CEO, becomes chairman Jan. 1, 2026 as Michael J. Hennigan retires; John Surma continues as independent lead...

September 09, 2025 07:00 AM
Major Oil Refiner Marathon Petroleum Sets Q3 2025 Earnings Release Date - What to Expect

Marathon Petroleum (NYSE: MPC) will release Q3 2025 financial results on November 4, followed by an 11 AM EST conference call.

September 04, 2025 07:00 AM
MPC’s Martinez honored with HoustonCISO ORBIE Award

Mary Rose Martinez, CISO and VP at Marathon Petroleum, earned a HoustonCISO ORBIE Award for leading cybersecurity innovation,...

August 22, 2025 07:00 AM
Marathon Petroleum Cos. Near Final OK On $7M Wage Deal

A California federal judge on Friday said he'd grant final approval to a $7.2 million deal by Marathon Petroleum and two related companies...

August 05, 2025 07:00 AM
Top US refiner Marathon Petroleum beats quarterly profit on higher refining margins

Marathon Petroleum Corp beat Wall Street estimates for second-quarter profit on Tuesday, benefiting from a rebound in refining margins as...

July 30, 2025 07:00 AM
Marathon Petroleum Sets $0.91 Dividend Payout: Key Dates for Investors Revealed

Marathon Petroleum (NYSE:MPC) has announced its latest quarterly dividend. The company's board of directors has declared a dividend of $0.91...

May 20, 2025 07:00 AM
Women Know Cyber: 150 Fascinating Females Fighting Cybercrime

Role models for students, parents, educators, and the cybersecurity community Sponsored by Secureworks.

April 24, 2025 07:00 AM
Top Security Executives Recognized at the 2025 HoustonCISO ORBIE Awards

HOUSTON, April 24, 2025 (GLOBE NEWSWIRE) -- The 2025 HoustonCISO ORBIE Awards recognized the exceptional leadership and cyber resilience of...

February 27, 2025 08:00 AM
Marathon Petroleum Corp SEC 10-K Report

Marathon Petroleum Corp, a leading integrated downstream energy company, has released its 2024 Form 10-K report, detailing its financial and...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

MPC CyberSecurity History Information

Official Website of Marathon Petroleum Corporation

The official website of Marathon Petroleum Corporation is http://www.marathonpetroleum.com/.

Marathon Petroleum Corporation’s AI-Generated Cybersecurity Score

According to Rankiteo, Marathon Petroleum Corporation’s AI-generated cybersecurity score is 807, reflecting their Good security posture.

How many security badges does Marathon Petroleum Corporation’ have ?

According to Rankiteo, Marathon Petroleum Corporation currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Marathon Petroleum Corporation have SOC 2 Type 1 certification ?

According to Rankiteo, Marathon Petroleum Corporation is not certified under SOC 2 Type 1.

Does Marathon Petroleum Corporation have SOC 2 Type 2 certification ?

According to Rankiteo, Marathon Petroleum Corporation does not hold a SOC 2 Type 2 certification.

Does Marathon Petroleum Corporation comply with GDPR ?

According to Rankiteo, Marathon Petroleum Corporation is not listed as GDPR compliant.

Does Marathon Petroleum Corporation have PCI DSS certification ?

According to Rankiteo, Marathon Petroleum Corporation does not currently maintain PCI DSS compliance.

Does Marathon Petroleum Corporation comply with HIPAA ?

According to Rankiteo, Marathon Petroleum Corporation is not compliant with HIPAA regulations.

Does Marathon Petroleum Corporation have ISO 27001 certification ?

According to Rankiteo,Marathon Petroleum Corporation is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Marathon Petroleum Corporation

Marathon Petroleum Corporation operates primarily in the Oil and Gas industry.

Number of Employees at Marathon Petroleum Corporation

Marathon Petroleum Corporation employs approximately 16,023 people worldwide.

Subsidiaries Owned by Marathon Petroleum Corporation

Marathon Petroleum Corporation presently has no subsidiaries across any sectors.

Marathon Petroleum Corporation’s LinkedIn Followers

Marathon Petroleum Corporation’s official LinkedIn profile has approximately 336,851 followers.

NAICS Classification of Marathon Petroleum Corporation

Marathon Petroleum Corporation is classified under the NAICS code 211, which corresponds to Oil and Gas Extraction.

Marathon Petroleum Corporation’s Presence on Crunchbase

No, Marathon Petroleum Corporation does not have a profile on Crunchbase.

Marathon Petroleum Corporation’s Presence on LinkedIn

Yes, Marathon Petroleum Corporation maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/marathon-petroleum-company.

Cybersecurity Incidents Involving Marathon Petroleum Corporation

As of December 06, 2025, Rankiteo reports that Marathon Petroleum Corporation has not experienced any cybersecurity incidents.

Number of Peer and Competitor Companies

Marathon Petroleum Corporation has an estimated 10,499 peer or competitor companies worldwide.

Marathon Petroleum Corporation CyberSecurity History Information

How many cyber incidents has Marathon Petroleum Corporation faced ?

Total Incidents: According to Rankiteo, Marathon Petroleum Corporation has faced 0 incidents in the past.

What types of cybersecurity incidents have occurred at Marathon Petroleum Corporation ?

Incident Types: The types of cybersecurity incidents that have occurred include .

Incident Details

What are the most common types of attacks the company has faced ?

Additional Questions

cve

Latest Global CVEs (Not Company-Specific)

Description

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social login providers such as Google, GitHub, GitLab, Facebook or Dropbox lack CSRF protection, since they don't send a state parameter and verify the response using this parameter. This vulnerability is fixed in 1.10.4.

Risk Information
cvss3
Base: 3.7
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Description

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

Risk Information
cvss4
Base: 9.4
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.aencode of the file /src/models/embed.py. Performing manipulation of the argument health_url results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The patch is named 0ff771dc1933d5a6b78f804115e78a7d8625c3f3. To fix this issue, it is recommended to deploy a patch. The vendor responded with a vulnerability confirmation and a list of security measures they have established already (e.g. disabled URL parsing, disabled URL upload mode, removed URL-to-markdown conversion).

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarlab.rar. Such manipulation leads to path traversal. It is possible to launch the attack remotely. Attacks of this nature are highly complex. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 7.20 build 128 is able to mitigate this issue. You should upgrade the affected component. The vendor responded very professional: "This is the real vulnerability affecting RAR for Android only. WinRAR and Unix RAR versions are not affected. We already fixed it in RAR for Android 7.20 build 128 and we publicly mentioned it in that version changelog. (...) To avoid confusion among users, it would be useful if such disclosure emphasizes that it is RAR for Android only issue and WinRAR isn't affected."

Risk Information
cvss2
Base: 5.1
Severity: HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
cvss3
Base: 5.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
cvss4
Base: 2.3
Severity: HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument safe_dir causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 9.0
Severity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 7.4
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=marathon-petroleum-company' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge