HackingSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedPIIIDENTITY_BASICLowContained
Farmers New World Life Insurance Company
bd_3acd56f74ef961fe · schema v1 · pii pii-v1
Full breach record for Farmers New World Life Insurance Company →Farmers New World Life Insurance Company (FNWL) notified customers of a security incident involving a third-party vendor. On May 29, 2025, an unauthorized actor accessed the vendor's database containing FNWL customer information. FNWL's parent company was alerted on May 30, 2025. The vendor detected the activity and blocked the actor. An investigation confirmed that certain personal information was acquired. FNWL is offering 24 months of free identity monitoring.
California clockDiscovered May 30, 2025 → Notified Aug 22, 202584d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_9a88b2c073098d14Washington State AGfiled 2025-08-22Candidate
- bd_c3cf131f3f18a186New Hampshire State AGfiled 2025-08-22Verified
- bd_d53fbb6afeb48dfbMaine State AGfiled 2025-08-22Verified
- bd_dc277ad86e04c000Indiana State AGfiled 2025-08-22Verified
Show 2 more filings ↓Show fewer ↑up to 4d gap
- bd_f135fbc406170657Montana State AGfiled 2025-08-22Verified
- bd_2df245b99dfbdde7Texas State AGfiled 2025-08-26(4d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-607540
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2025
- Raw hash
- a7fe3fd35f5af1c3173b4192a8f7fd899737bad4669a8e5f6b6267290d2f7874
Reporting entity
- Name
- Farmers New World Life Insurance Companynorm: farmers new world life insurance
Victim entity
- Name
- Farmers New World Life Insurance Companynorm: farmers new world life insurance
Incident
- Discovered
- May 30, 2025
- Materiality determined
- —
- Notification sent
- Aug 22, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified appropriate law enforcement authorities
- Third party
- via Third-party vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 30, 2025→ Notified: Aug 22, 202584d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.