Farmers Insurance data breach (2025): what was exposed and what to do

Updated Corrections

September 28, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

Farmers Insurance data breach (2025): what was exposed and what to do

By Delist Editorial Team · Updated September 28, 2026 · Corrections

September 28, 2026

What happened

Farmers Insurance (Farmers Insurance Exchange / Farmers Group and related entities, including brands such as Foremost and Bristol West named in consumer letters) notified customers of a cybersecurity incident after a third-party vendor alerted the company on May 30, 2025 that an unauthorized actor had accessed a vendor database containing Farmers customer information. Company notices—including Iowa and Massachusetts Attorney General materials and sample consumer letters—state the unauthorized access and acquisition occurred on May 29, 2025 (Iowa’s letter describes roughly one hour of access that day). Farmers stated the incident was contained and did not impact Farmers’ own systems.

Farmers’ investigation, with a data-review expert, determined by July 24, 2025 that personal information for a select population of customers was involved. Written notices began mailing on or around August 22, 2025. A filing / sample notice shared with Maine’s Attorney General’s Office, as reported by BleepingComputer, listed 1,111,386 customers impacted. That is the AG-linked figure as reported in the press—not a Delist count. BankInfoSecurity / CUInfoSecurity and SecurityWeek described separate Maine filings: about 1.07 million for Farmers Insurance Exchange / Farmers Group affiliates and 40,214 for Farmers New World Life (SecurityWeek rounded the life unit as ~40,000)—together corroborating a ~1.11 million scale. Prefer the combined 1,111,386 Maine-linked total as reported by BleepingComputer when a single nationwide figure is needed, and treat the split as filing detail. Iowa’s AG letter listed 4,750 Iowa residents.

Farmers did not publicly name the vendor in its advisory. BleepingComputer reported learning that the theft was part of the widespread 2025 Salesforce data-theft attacks. Treat the Salesforce link as press reporting unless your official notice names the vendor. A stable farmers.com advisory URL was still not reliably fetchable on this pass; use the Massachusetts AG sample notice and the hosted online substitute notice instead.

Sources

What data was exposed

Per Farmers’ Iowa AG letter, Massachusetts AG sample consumer notice, and online substitute notice language (also summarized by SecurityWeek, BleepingComputer, and CUInfoSecurity), the vendor database contained:

  • Name
  • Address
  • Date of birth
  • Driver’s license number
  • And/or last four digits of Social Security number

Farmers stated there was no evidence that additional personal information was accessed, and Iowa’s letter says the notification letter identifies the specific data elements for each individual. Not every person received every field—rely on your letter.

Breach details

Detail Value
Breach name Farmers Insurance (third-party vendor database; Salesforce-linked per press)
Date Unauthorized access May 29, 2025; vendor alert May 30, 2025; file review determination July 24, 2025
Disclosed Consumer mail from ~August 22, 2025; Iowa / Mass AG letters Aug 22, 2025; press coverage late August 2025
Accounts affected 1,111,386 (Maine AG sample/filing, as reported by BleepingComputer). Split filings: Exchange/Group ~1.07M + Farmers New World Life 40,214 (CUInfoSecurity). Iowa AG: 4,750 Iowa residents.
Domain farmers.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your information is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Farmers Insurance; it reflects a publicly reported security incident.

For whether your information was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you) — not this page alone.

What to do now

Because driver’s license numbers (and, for some people, last-four SSN) were named:

  • Place a free credit freeze at Equifax, Experian, and TransUnion if your notice lists a license number or SSN digits. See how to freeze your credit.
  • Enroll in any complimentary identity monitoring Farmers offered (24 months via Cyberscout / myTrueIdentity in Iowa and Massachusetts sample letters; enrollment deadline printed on those letters was November 25, 2025) only through channels on your letter—not cold emails.
  • Treat unexpected calls that cite your policy number, claim, or license as possible social engineering; contact Farmers or your agent through a number you look up yourself (sample letters listed 1-833-426-6809 for questions).
  • Review insurance mail, credit reports, and financial statements for unfamiliar activity.
  • Keep the letter—it documents which fields applied to you.

Short checklist: first 48 hours after a data breach. If the letter is confusing: a company emailed me about a breach.

How this shows up on the open web

Names, addresses, and dates of birth sit next to the same building blocks people-search sites already publish. After a driver’s license–heavy insurance incident, impersonation and phishing can sound more plausible when someone can also look up your current address or phone online. Run a free open-web scan to see which people-search and broker sites expose your personal data. Delist does not claim to have scanned Farmers’ or its vendor’s systems, and it does not remove records from a breach dump.

Related reading on license rails: when a store scans your driver’s license, AssuranceAmerica (2026), IDScan.net (2026), and Florida DMV / DAVID (2026).

My driver’s license was in the Farmers vendor breach—what should I do first?

Freeze credit if your notice lists a license number or SSN digits. Treat calls that cite your policy or license as possible social engineering. Enroll in letter-printed monitoring only.

Frequently asked questions

How many Farmers customers were affected?

BleepingComputer’s coverage of the Maine Attorney General sample/filing cites 1,111,386 customers. CUInfoSecurity described Maine filings of about 1.07 million (Farmers Exchange/Group) plus 40,214 (Farmers New World Life); SecurityWeek rounded the life unit as ~40,000. Those are regulatory figures as reported publicly—not Delist counts. Iowa’s AG letter listed 4,750 Iowa residents.

Were full Social Security numbers exposed?

Farmers’ Iowa AG letter and Massachusetts / online sample notices list driver’s license number and/or the last four digits of Social Security number among the fields—not necessarily full SSNs for everyone. Check your letter.

Was this a Salesforce breach?

Farmers described a third-party vendor database and did not publicly name the vendor in its advisory. BleepingComputer reported the theft was part of the 2025 Salesforce attack wave. Treat that link as press reporting unless your official notice names the system.

Can Delist remove my driver’s license from the Farmers vendor files?

No. Delist does not scrub insurer or vendor systems or breach dumps. A free scan checks open-web people-search and broker listings only.

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.