Farmer Brothers Company
ent_e41f9ae558bd8be6
Disclosures
16
State AG · 12 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
14,470
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Farmer Brothers Company
- Normalized
- farmer brothers— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493006PMLETBTVJ3262
- SEC EDGAR CIK
- 0000034563
- Domain
- farmerbros.com
Disclosure history (16)newest first
- Washington State AGas victim2025-09-10
Farmer Brothers Company reported a ransomware incident affecting 1,573 Washington residents. Unauthorized access occurred between March 6 and March 14, 2025. Compromised data included names, SSNs, driver's licenses, passport numbers, health insurance policy numbers, treatment information, and dates of birth. The company notified federal law enforcement, secured systems, and offered 12 months of credit monitoring via TransUnion.
- Texas State AGas victim2025-09-10
Farmer Brothers Company based in Fort Worth, Texas, a business – retail or merchant entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-08-19 and reported on 2025-09-10. 3,453 Texas residents were affected. 14,460 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Medical Information;Health Insurance Information. Consumers were notified via U.S. Mail.
- Vermont State AGas victim2025-09-09
Farmer Brothers Company notified consumers of a data breach where an unknown actor accessed archived files between March 6 and 14, 2025. The incident involved personal information including names and government IDs. The company reported the incident to federal law enforcement and is offering 12 months of credit monitoring.
- Oregon State AGas victim2025-09-09
Farmer Brothers Company reported a data breach to the Oregon Attorney General. The breach was reported on 2025-09-09. The breach occurred during 3/6/2025 - 3/14/2025. The breach was discovered on 8/19/2025. 14,470 individuals were affected. Notice was sent on 9/9/2025.
- California State AGas victim2025-09-09
Farmer Brothers Company notified California residents of unauthorized access to archived files between March 6 and March 14, 2025. The company identified indications of potential unauthorized access on March 14, 2025. Personal information involved includes basic identity data. The company secured systems, reported to law enforcement, and is offering 12 months of credit monitoring.
- Nebraska State AGas victim2025-09-09
Farmer Brothers Company notified Nebraska AG of unauthorized access to archived systems between March 6-14, 2025. The incident affected 81 Nebraska residents, exposing names, SSNs, and driver's license numbers. The company secured systems, notified federal law enforcement, and provided 12 months of credit monitoring via TransUnion to affected individuals.
- Maine State AGas victim2025-09-09
Farmer Brothers Company reported an external system breach (hacking) occurring between March 6 and March 14, 2025. The incident affected 14,460 individuals nationwide, including 9 Maine residents. Compromised data included names, Social Security numbers, and driver's license numbers. Notices were sent on September 9, 2025, offering 12 months of credit monitoring.
- Montana State AGas victim2025-09-09
Farmer Brothers Company notified Montana residents of a data breach where an unknown actor accessed archived files between March 6-14, 2025. The company reported the incident to federal law enforcement and is offering 12 months of credit monitoring. Personal information was involved, though no identity theft was confirmed.
- Massachusetts State AGas victim2025-09-09
Farmer Brothers Company reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-09-09. 53 Massachusetts residents were affected.
- Indiana State AGas victim2025-09-09
Farmer Brothers Company reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-06 and was reported on 2025-09-09. 128 Indiana residents were affected. 14,460 individuals affected in total.
- New Hampshire State AGas victim2025-09-09
Farmer Brothers Company notified the New Hampshire Attorney General of a data event affecting 14 NH residents. Unauthorized access to archived files occurred between March 6 and March 14, 2025. The actor accessed names, SSNs, and driver's license numbers. Farmer Brothers reported to federal law enforcement, implemented safeguards, and provided 12 months of credit monitoring via TransUnion to affected individuals.
- Illinois State AGas victim2025-09-01
FARMER BROTHERS COMPANY filed a data-breach notice with the Illinois Attorney General in September 2025 (case 25-09-432). The register records the breach as discovered on August 19, 2025. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- California State AGas reporting2018-12-11
Farmer Bros. Co. reported that on September 18, 2018, it became aware that multiple company email accounts were accessed by an unauthorized third party. The breach date listed by the CA AG is May 1, 2018. The investigation concluded in November 2018. Affected data may include names, addresses, SSNs, driver's license numbers, payment card numbers, CVVs, bank account numbers, and routing numbers. The company engaged a cyber incident response team and enhanced email security protections. Identity theft protection services were offered to affected individuals.
- Massachusetts State AGas reporting2018-12-11
Farmer Bros. Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-12-11. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas reporting2018-12-11
Farmer Bros. Co. notified Montana residents of a September 2018 cyber incident where unauthorized third parties accessed company email accounts. The investigation revealed that some accounts contained PII and financial data, including SSNs, driver's licenses, and payment card details. While it was undetermined if data was copied, the company offered 12 months of credit monitoring and identity theft protection services.
- New Hampshire State AGas reporting2018-12-07
Farmer Bros. Co. notified the NH AG of unauthorized access to multiple email accounts on Sept 18, 2018. Investigation confirmed PII (SSN, DL, name) of 3 NH residents was stored in affected systems. Notifications mailed Dec 11, 2018. Remediation included password resets and enhanced email security.