HackingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
FARMERS INSURANCE EXCHANGE
bd_844e3a4ba41f21e3 · schema v1 · pii pii-v1
Full breach record for FARMERS INSURANCE EXCHANGE →Farmers Insurance Exchange disclosed a security incident involving a third-party vendor's database containing customer information. An unauthorized actor accessed the database on May 29, 2025, and acquired certain data. Farmers was alerted on May 30, 2025. The incident involved personal information including names, addresses, and potentially financial account data. Farmers engaged forensic experts, notified law enforcement, and is offering 24 months of identity monitoring to affected individuals.
California clockDiscovered May 30, 2025 → Notified Aug 22, 202584d ✗ CA 60-day late27 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_3d574addd193bf62Texas State AGfiled 2025-12-09(6d gap)Verified
- bd_32fc259e6a6fb47cOregon State AGfiled 2025-08-25(100d gap)Verified
- bd_640b89a4c48862f3Iowa State AGfiled 2025-08-22(103d gap)Candidate
- bd_641a3c5356a7d18cMontana State AGfiled 2025-08-22(103d gap)Verified
Show 3 more filings ↓Show fewer ↑up to 103d gap
- bd_79b4e01b1bc2dd08Maine State AGfiled 2025-08-22(103d gap)Verified
- bd_9afb6aacb234e39eNew Hampshire State AGfiled 2025-08-22(103d gap)Verified
- bd_cdbdcdd70760a334California State AGfiled 2025-08-22(103d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-615004
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 3, 2025
- Raw hash
- 683555a1ee5a5e02139cc405940b775ef255c48e5d20102852e7e068ad5b2171
Reporting entity
- Name
- FARMERS INSURANCE EXCHANGEnorm: farmers insurance exchange
Victim entity
- Name
- FARMERS INSURANCE EXCHANGEnorm: farmers insurance exchange
Incident
- Discovered
- May 30, 2025
- Materiality determined
- —
- Notification sent
- Aug 22, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified appropriate law enforcement authorities
- Third party
- via Third-party vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 27 weeks(187 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 30, 2025→ Notified: Aug 22, 202584d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.