Farmers Insurance disclosed a data breach affecting 1.1 million customers in August 2026 after an unauthorized actor accessed a third-party vendor's database on May 29, 2025 — an incident linked to the widespread Salesforce social engineering campaign. Exposed data includes names, addresses, dates of birth, driver's license numbers, and the last four digits of Social Security numbers for some customers. If you have a Farmers policy, freeze your credit at all three bureaus, request an IRS Identity Protection PIN, enroll in the free Cyberscout monitoring Farmers is offering, and remove your data from broker sites before criminals cross-reference the leak.
What Happened in the Farmers Insurance Breach?
The timeline:
- May 29, 2025: An unauthorized actor accessed a third-party vendor's database containing Farmers customer data.
- May 30, 2025: The vendor notified Farmers of suspicious activity. Farmers launched an immediate investigation and alerted law enforcement.
- July 24, 2025: Farmers' review completed, confirming exposure of personal information for more than 1.1 million customers.
- August 22, 2026: Farmers began mailing customer notifications and posted a public notice on its website.
The incident has been publicly linked to the broader Salesforce social engineering campaign of 2025-2026 — the same vishing-driven playbook that hit dozens of enterprises during that window. Farmers Insurance Exchange and its subsidiaries are all in scope.
What Data Was Exposed?
Confirmed by Farmers' disclosure:
- Full names
- Home addresses
- Dates of birth
- Driver's license numbers
- Last four digits of Social Security numbers (for some customers)
Driver's license numbers matter more than most people realize
DL numbers plus DOB and address are the exact ingredients for auto-insurance fraud, fake driver's license production, and identity verification bypass at car dealerships, cell carriers, and utility companies. Even the last four of your SSN, combined with the rest of this data, lowers the bar for account takeover at many services that use partial SSN as identity verification.
Are You Affected?
Assume affected if:
- You receive a physical letter from Farmers Insurance dated August or September 2026
- You are or were a Farmers Insurance auto, home, life, or renters policyholder
- You had a policy with one of Farmers' subsidiaries or exchanges (Farmers, 21st Century, Foremost, Bristol West, MetLife Auto & Home post-acquisition)
- You submitted personal information to Farmers for a quote, claim, or agent application
Farmers is offering free identity monitoring — call 1-833-426-6809 to check your eligibility and enroll if you have not received a letter yet.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Immediate Steps to Take
Step 1: Freeze Your Credit at All Three Bureaus
A credit freeze prevents anyone — including you — from opening new credit lines in your name until you lift it. Free, reversible, and the single most effective action after DOB + partial SSN + DL exposure. Freeze at:
Also freeze Innovis (fourth bureau) and ChexSystems (protects against fraudulent new bank accounts).
Step 2: Enroll in Farmers' Free Monitoring — Then Layer On Top
Farmers is providing free Cyberscout Single Bureau Credit Monitoring, Credit Report, and Credit Score for 24 months to impacted customers. Enroll — there is no downside — but understand its limits: single-bureau monitoring misses fraud that lands at the other two bureaus, and monitoring alerts you after fraud, not before. Combine with a freeze at all three bureaus for full coverage.
Step 3: Request a Replacement Driver's License
In many states you can request a new driver's license number if yours has been exposed in a data breach. Contact your state DMV (bring the Farmers notification letter as proof). If your state won't reissue the number, add a fraud alert to your driving record and request a copy of your MVR periodically.
Step 4: Get an IRS Identity Protection PIN
Partial SSN + DOB is enough to attempt tax-refund fraud in many cases. Request an IRS Identity Protection PIN at irs.gov/ippin. A criminal cannot file a fraudulent return in your name without the PIN, and you'll get a fresh one every year.
Step 5: Rotate Passwords on Insurance and Auto-Related Accounts
If you used the same password for your Farmers account and other services (bank, DMV portal, other insurers), rotate all of them now with unique passwords stored in a password manager. Enable phishing-resistant 2FA — an authenticator app or hardware key, not SMS — because SMS 2FA is defeated by SIM swaps.
Step 6: Watch for Insurance-Specific Phishing
Expect emails, texts, and calls impersonating Farmers, other insurers, or state insurance departments, referencing your real policy details, address, and "claim update," "refund," or "class action settlement" language. Any inbound request to verify banking, log in, or make a payment should be answered by calling the number on the back of your Farmers insurance card — never a number in the message.
Cut the Trail: Remove Your Data From Broker Sites
The Farmers leak on its own is dangerous. It becomes far more dangerous when attackers pair it with data-broker records — relatives, past addresses, phone numbers, employer, court records — which they can buy for pennies on Spokeo, BeenVerified, Whitepages, and 100+ similar sites. Removing your data from those brokers breaks the chain: when an attacker looks you up after the Farmers leak and finds nothing on the public web, most give up and move to easier targets.
PrivacyOn shrinks your public footprint fast
PrivacyOn removes your personal information from 100+ major data broker sites, adds 24/7 dark web monitoring, and covers up to 5 family members from $8.33/month. Start with a free scan to see exactly which brokers are exposing your address and phone — the same data attackers will try to cross-reference against the Farmers dump.
Longer-Term Protection
- Set fraud alerts at all three credit bureaus (separate from the freeze; alerts warn lenders to verify identity)
- Add dark-web monitoring for your SSN, DL number, and email so you know when they appear in new dumps
- Use email aliases for future insurance quotes (iCloud Hide My Email, Firefox Relay, DuckDuckGo Email Protection) so one leak doesn't burn your primary inbox
- Review bank, brokerage, and insurance statements weekly for the next 12 months
- Preserve the Farmers notification letter — you may need it for a class action or to request a new driver's license number
- Report suspected identity theft at IdentityTheft.gov to generate a formal FTC recovery plan
Frequently Asked Questions
Is the Farmers Insurance 2026 breach confirmed?
Yes. Farmers Insurance disclosed the breach in August 2026 after an unauthorized actor accessed a third-party vendor database on May 29, 2025. More than 1.1 million customers were confirmed impacted; notifications began in writing on approximately August 22, 2026, and Farmers posted a public notice on its website. The incident is linked to the broader Salesforce social engineering campaign.
How many people were affected by the Farmers breach?
More than 1.1 million customers were confirmed impacted per Farmers' review completed July 24, 2025. Affected policyholders span Farmers Insurance Exchange and its subsidiaries.
Was my full Social Security number leaked in the Farmers breach?
Full SSNs were not exposed in the current disclosure. However, the last four digits of SSNs were exposed for some customers, combined with names, addresses, DOBs, and driver's license numbers — a combination that is still dangerous for identity verification bypass, tax fraud attempts, and account takeover.
Should I accept Farmers' free credit monitoring?
Yes — call 1-833-426-6809 to enroll in the 24 months of free Cyberscout monitoring Farmers is offering. But do not stop there. Free breach-response monitoring only covers one credit bureau and only alerts you after fraud happens. Pair it with a freeze at all three bureaus, an IRS IP PIN, and data-broker removal.
Can I request a new driver's license number after the Farmers breach?
Many states allow you to request a new driver's license number if yours has been exposed in a data breach — contact your state DMV and bring the Farmers notification letter as proof. If your state won't reissue, add a fraud alert to your driving record and pull your MVR periodically.
Is there a better identity protection service after a breach like this?
Yes — PrivacyOn is our top pick. It removes your personal information from 100+ data broker sites so attackers cannot cross-reference the Farmers leak with your current address and relatives, adds 24/7 dark web monitoring for your SSN and email, and covers up to 5 family members from $8.33/month. The free monitoring from Farmers' Cyberscout vendor only alerts you after fraud has already happened; PrivacyOn shrinks the exposed surface first, which is what stops most opportunistic attackers.
Can I sue Farmers over the 2026 breach?
Yes — a class action lawsuit was filed against Farmers Insurance Exchange following the disclosure, and several plaintiffs' firms have announced investigations. If you are affected, save your notification letter and any related correspondence; you may qualify to join a class action later. This is not legal advice — consult an attorney for your situation.
How long will Farmers-breach data be dangerous?
DOB, address, DL number, and even partial SSN don't expire. Once this data enters criminal circulation it remains useful for the rest of your life — and it will be repeatedly cross-referenced against future leaks. That's why long-term measures (permanent credit freezes, annual IP PIN, ongoing broker removal, dark-web monitoring) matter far more than any one-time cleanup.