HomeCyber SecurityFarmers Insurance coverage knowledge breach impacts 1.1M individuals after Salesforce assault

Farmers Insurance coverage knowledge breach impacts 1.1M individuals after Salesforce assault


Farmers Insurance coverage knowledge breach impacts 1.1M individuals after Salesforce assault

U.S. insurance coverage big Farmers Insurance coverage has disclosed an information breach impacting 1.1 million clients, with BleepingComputer studying that the information was stolen within the widespread Salesforce assaults.

Farmers Insurance coverage is a U.S.-based insurer that gives auto, residence, life, and enterprise insurance coverage merchandise. It operates by a community of brokers and subsidiaries, serving greater than 10 million households nationwide.

The corporate disclosed the information breach in an advisory on its web site, saying that its database at a third-party vendor was breached on Could 29, 2025.

“On Could 30, 2025, certainly one of Farmers’ third-party distributors alerted Farmers to suspicious exercise involving an unauthorized actor accessing one of many vendor’s databases containing Farmers buyer info (the “Incident”),” reads the knowledge breach notification on its web site.

“The third-party vendor had monitoring instruments in place, which allowed the seller to rapidly detect the exercise and take applicable containment measures, together with blocking the unauthorized actor. After studying of the exercise, Farmers instantly launched a complete investigation to find out the character and scope of the Incident and notified applicable regulation enforcement authorities.”

The corporate says that its investigation decided that clients’ names, addresses, dates of delivery, driver’s license numbers, and/or final 4 digits of Social Safety numbers have been stolen throughout the breach.

Farmers started sending knowledge breach notifications to impacted people on August 22, with a pattern notification [1, 2] shared with the Maine Legal professional Common’s Workplace, stating {that a} mixed whole of 1,111,386 clients have been impacted.

Whereas Farmers didn’t disclose the title of the third-party vendor, BleepingComputer has discovered that the information was stolen within the widespread Salesforce knowledge theft assaults which have impacted quite a few organizations this 12 months.

BleepingComputer contacted Farmers with extra questions in regards to the breach and can replace the story if we obtain a response.

The Salesforce knowledge theft assaults

Because the starting of the 12 months, risk actors categorized as ‘UNC6040’ or ‘UNC6240’ have been conducting social engineering assaults on Salesforce clients.

Throughout these assaults, risk actors conduct voice phishing (vishing) to trick workers into linking a malicious OAuth app with their firm’s Salesforce cases.

As soon as linked, the risk actors used the connection to obtain and steal the databases, which have been then used to extort the corporate by electronic mail.

The extortion calls for come from the ShinyHunters cybercrime group, who informed BleepingComputer that the assaults contain a number of overlapping risk teams, with every group dealing with particular duties to breach Salesforce cases and steal knowledge.

“Like we’ve stated repeatedly already, ShinyHunters and Scattered Spider are one and the identical,” ShinyHunters informed BleepingComputer.

“They supply us with preliminary entry and we conduct the dump and exfiltration of the Salesforce CRM cases. Identical to we did with Snowflake.”

Different firms impacted in these assaults embrace Google, Cisco, WorkdayAdidasQantasAllianz Life, and the LVMH subsidiaries Louis VuittonDior, and Tiffany & Co.

 

46% of environments had passwords cracked, practically doubling from 25% final 12 months.

Get the Picus Blue Report 2025 now for a complete have a look at extra findings on prevention, detection, and knowledge exfiltration developments.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments