Find notable cyber news and cases, enriched with sources, timelines, and signals.

Farmers Insurance hit by cyberattack

Incident
First reported
Last updated
Happening score
H score 7
1 unique sources, 1 articles

Summary

Hide ▲

Farmers Insurance disclosed a security incident tied to a third-party vendor that affected more than 1 million customers and compromised some personal information. The vendor detected suspicious activity in its database environment and blocked the unauthorized actor. The breach was tied to activity on May 29, discovered the next day, and later confirmed in an investigation on July 24. Farmers is offering two years of complimentary identity monitoring services to affected individuals.

Timeline

  1. 26.08.2025 23:19 1 articles · 9mo ago

    Unauthorized access to Farmers Insurance vendor database

    Exploitation Observed

    An unauthorized actor accessed one of the third-party vendor's databases containing customer information, creating a security incident involving Farmers Insurance, Farmers Insurance Exchange, and affiliated companies and subsidiaries.

    Show sources
  2. 26.08.2025 23:19 1 articles · 9mo ago

    Vendor monitoring tools detect and block suspicious activity

    Detection Ioc Update

    The third-party vendor's monitoring tools detected suspicious activity in the database environment and the vendor took containment measures, including blocking the unauthorized actor, after the access was identified.

    Show sources
  3. 26.08.2025 23:19 1 articles · 9mo ago

    Investigation confirms customer personal information compromise

    Victim Impact Update

    On July 24, the investigation determined that some of the personal information of Farmers Insurance customers was compromised, while the filing did not specify which data elements were involved.

    Show sources
  4. 26.08.2025 23:19 1 articles · 9mo ago

    Farmers Insurance files breach notification after vendor incident

    Initial Disclosure

    Farmers Insurance, Farmers Insurance Exchange, and affiliated companies filed breach notification documents with the Office of the Maine Attorney General after the vendor-linked security incident, notified appropriate law enforcement authorities, and said it will provide affected individuals two years of complimentary identity monitoring services.

    Show sources