Company Details
marathon-petroleum-company
16,023
336,851
211
marathonpetroleum.com
41
MAR_2224870
Completed

Marathon Petroleum Corporation Company CyberSecurity Posture
marathonpetroleum.comMarathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.
Company Details
marathon-petroleum-company
16,023
336,851
211
marathonpetroleum.com
41
MAR_2224870
Completed
Between 800 and 849

MPC Global Score (TPRM)XXXX



No incidents recorded for Marathon Petroleum Corporation in 2025.
No incidents recorded for Marathon Petroleum Corporation in 2025.
No incidents recorded for Marathon Petroleum Corporation in 2025.
MPC cyber incidents detection timeline including parent company and subsidiaries

Marathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.


TechnipFMC is a leading technology provider to the traditional and new energies industry, delivering fully integrated projects, products, and services. With our proprietary technologies and comprehensive solutions, we are transforming our clients’ project economics, helping them unlock new possibi

Koch Engineered Solutions (KES) provides uniquely engineered solutions in construction; mass and heat transfer; combustion and emissions controls; filtration; separation; materials applications; automation and actuation. KES is located in Wichita, Kansas, and is a subsidiary of Koch Industries, one

We’re a leading producer of the energy and chemicals that drive global commerce and enhance the daily lives of people around the globe by continuing delivering an uninterrupted supply of energy to the world. Our resilience and agility has built one of the world’s largest integrated energy and chemi
We’re a leading producer of the energy and chemicals that drive global commerce and enhance the daily lives of people around the globe by continuing delivering an uninterrupted supply of energy to the world. Our resilience and agility has built one of the world’s largest integrated energy and chemi

Petróleos de Venezuela S.A. is a Venezuelan state company, began operations on January 1st, 1976 and whose activities are the oil exploration, production, refining, marketing and transportation of Venezuelan oil as well as the orimulsion, chemical, petrochemical businesses and coal. We have the lar
Fortune Global 500 Company, Bharat Petroleum is the second largest Indian Oil Marketing Company and one of the premier integrated energy companies in India, engaged in refining of crude oil and marketing of petroleum products, with a significant presence in the upstream and downstream sectors of the
Shell is a global group of energy and petrochemical companies, employing 103,000 people and with operations in more than 70 countries. We serve more than 1 million commercial and industrial customers, and around 33 million customers daily at more than 47,000 Shell-branded retail service stations. O

ОАО Oil and Gas Company «RussNeft» came into existence in September 2002 . The structure of OAO NK “RussNeft” counts 24 upstream enterprises, 2 refineries, its own distribution net of gas filling stations. Geographic reach of “RussNeft” covers 12 regions of Russia and CIS: Khanty-Mansi Autonomous

Cameron is a SLB company. For updates and information, please follow the main SLB company page on LinkedIn at: https://www.linkedin.com/company/slbglobal/ Cameron, a SLB company, is a leading provider of flow equipment products, systems and services to worldwide oil, gas and process industries. Lev
.png)
Maryann T. Mannen, president and CEO, becomes chairman Jan. 1, 2026 as Michael J. Hennigan retires; John Surma continues as independent lead...
Marathon Petroleum (NYSE: MPC) will release Q3 2025 financial results on November 4, followed by an 11 AM EST conference call.
Mary Rose Martinez, CISO and VP at Marathon Petroleum, earned a HoustonCISO ORBIE Award for leading cybersecurity innovation,...
A California federal judge on Friday said he'd grant final approval to a $7.2 million deal by Marathon Petroleum and two related companies...
Marathon Petroleum Corp beat Wall Street estimates for second-quarter profit on Tuesday, benefiting from a rebound in refining margins as...
Marathon Petroleum (NYSE:MPC) has announced its latest quarterly dividend. The company's board of directors has declared a dividend of $0.91...
Role models for students, parents, educators, and the cybersecurity community Sponsored by Secureworks.
HOUSTON, April 24, 2025 (GLOBE NEWSWIRE) -- The 2025 HoustonCISO ORBIE Awards recognized the exceptional leadership and cyber resilience of...
Marathon Petroleum Corp, a leading integrated downstream energy company, has released its 2024 Form 10-K report, detailing its financial and...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Marathon Petroleum Corporation is http://www.marathonpetroleum.com/.
According to Rankiteo, Marathon Petroleum Corporation’s AI-generated cybersecurity score is 807, reflecting their Good security posture.
According to Rankiteo, Marathon Petroleum Corporation currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Marathon Petroleum Corporation is not certified under SOC 2 Type 1.
According to Rankiteo, Marathon Petroleum Corporation does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Marathon Petroleum Corporation is not listed as GDPR compliant.
According to Rankiteo, Marathon Petroleum Corporation does not currently maintain PCI DSS compliance.
According to Rankiteo, Marathon Petroleum Corporation is not compliant with HIPAA regulations.
According to Rankiteo,Marathon Petroleum Corporation is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Marathon Petroleum Corporation operates primarily in the Oil and Gas industry.
Marathon Petroleum Corporation employs approximately 16,023 people worldwide.
Marathon Petroleum Corporation presently has no subsidiaries across any sectors.
Marathon Petroleum Corporation’s official LinkedIn profile has approximately 336,851 followers.
Marathon Petroleum Corporation is classified under the NAICS code 211, which corresponds to Oil and Gas Extraction.
No, Marathon Petroleum Corporation does not have a profile on Crunchbase.
Yes, Marathon Petroleum Corporation maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/marathon-petroleum-company.
As of December 06, 2025, Rankiteo reports that Marathon Petroleum Corporation has not experienced any cybersecurity incidents.
Marathon Petroleum Corporation has an estimated 10,499 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, Marathon Petroleum Corporation has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social login providers such as Google, GitHub, GitLab, Facebook or Dropbox lack CSRF protection, since they don't send a state parameter and verify the response using this parameter. This vulnerability is fixed in 1.10.4.
Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.
A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.aencode of the file /src/models/embed.py. Performing manipulation of the argument health_url results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The patch is named 0ff771dc1933d5a6b78f804115e78a7d8625c3f3. To fix this issue, it is recommended to deploy a patch. The vendor responded with a vulnerability confirmation and a list of security measures they have established already (e.g. disabled URL parsing, disabled URL upload mode, removed URL-to-markdown conversion).
A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarlab.rar. Such manipulation leads to path traversal. It is possible to launch the attack remotely. Attacks of this nature are highly complex. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 7.20 build 128 is able to mitigate this issue. You should upgrade the affected component. The vendor responded very professional: "This is the real vulnerability affecting RAR for Android only. WinRAR and Unix RAR versions are not affected. We already fixed it in RAR for Android 7.20 build 128 and we publicly mentioned it in that version changelog. (...) To avoid confusion among users, it would be useful if such disclosure emphasizes that it is RAR for Android only issue and WinRAR isn't affected."
A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument safe_dir causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.