HackingSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
FARMERS INSURANCE EXCHANGE
bd_cdbdcdd70760a334 · schema v1 · pii pii-v1
Full breach record for FARMERS INSURANCE EXCHANGE →Farmers Insurance Exchange disclosed a security incident involving a third-party vendor. On May 29, 2025, an unauthorized actor accessed the vendor's database containing customer information. Farmers was alerted on May 30, 2025. The investigation confirmed that personal information, including names, addresses, and potentially financial account data, was acquired. Farmers engaged forensic experts, notified law enforcement, and is offering 24 months of identity monitoring to affected individuals.
California clockDiscovered May 30, 2025 → Notified Aug 22, 202584d ✗ CA 60-day late12 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_640b89a4c48862f3Iowa State AGfiled 2025-08-22Candidate
- bd_641a3c5356a7d18cMontana State AGfiled 2025-08-22Verified
- bd_79b4e01b1bc2dd08Maine State AGfiled 2025-08-22Verified
- bd_9afb6aacb234e39eNew Hampshire State AGfiled 2025-08-22Verified
Show 3 more filings ↓Show fewer ↑up to 109d gap
- bd_32fc259e6a6fb47cOregon State AGfiled 2025-08-25(3d gap)Verified
- bd_844e3a4ba41f21e3California State AGfiled 2025-12-03(103d gap)Verified
- bd_3d574addd193bf62Texas State AGfiled 2025-12-09(109d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-607524
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2025
- Raw hash
- f09c2309cbca5f3e7fc962a77ea0170c9371e0f4bcddfd7a5505a9a388ee4b2f
Reporting entity
- Name
- FARMERS INSURANCE EXCHANGEnorm: farmers insurance exchange
Victim entity
- Name
- FARMERS INSURANCE EXCHANGEnorm: farmers insurance exchange
Incident
- Discovered
- May 30, 2025
- Materiality determined
- —
- Notification sent
- Aug 22, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified appropriate law enforcement authorities
- Third party
- via Third-party vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 12 weeks(84 days from discovery to filing)
- Compliance flags
- CA 60-day late · 84d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 30, 2025→ Notified: Aug 22, 202584d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.