Farmers Insurance suffered a cyberattack on 29 May 2025 compromising information belonging to more than 1.1 million customers. The incident was later added to the list of organisations affected by the SaaS-platform campaign recorded at 25-0923.
Campaigns Are Recognised Backwards
On 29 May this was one company’s incident. It became part of a campaign months later, when enough comparable incidents had accumulated for researchers to connect them.
That is how every campaign in this database was assembled, and it has a consequence the corpus should state plainly: an organisation compromised early in a campaign has no way to know it. There is no peer warning at 25-0512 to act on, because no peer has been publicly compromised yet.
The sector-rotation warning this desk offered as unusually actionable only helps organisations that are not first.
Which Makes Early Victims The Least Culpable And The Least Defensible
After the campaign is public, an organisation that has not hardened its service desk or reviewed connected applications is making an identifiable choice.
Before it is public, the same organisation is doing what every peer is doing. This desk records that distinction because the corpus is read backwards, and hindsight makes May look like August.
Insurance Is The Sector This Campaign Kept Returning To
Farmers in May, Allianz Life in July at 25-0717. The corpus filed at 25-0512 that a group works one industry at a time because the vendors, outsourcers and support scripts repeat within a sector.
Insurers share a further characteristic: a large intermediary population — agents, brokers, financial professionals — with legitimate platform access and no direct employment relationship to the insurer. That is a wide and thinly governed identity boundary.
Compiled from public reporting, listed below. The attribution to the wider campaign is as reported and was made after the fact. Corrections: corrections@forensicpost.com.