On March 14, 2025, Farmer Brothers Company discovered signs of unauthorized access to its systems, prompting an immediate and thorough investigation. The company determined that an unknown actor had gained access to certain archived files and folders between March 6 and March 14. As a result, sensitive personal information was potentially exposed, including names, Social Security numbers and driver’s license numbers.
The breach affected a total of 14,460 individuals in the United States, with nine residents in Maine impacted, according to the Maine Attorney General’s data breach notification.
Further disclosures were filed on September 10, 2025. According to the notice to the Washington Attorney General, 1,573 people have been affected in the state. 186 people in Montana have bene affected according to the Montana Attorney General notice.
Farmer Brothers completed a detailed review of the compromised files to identify affected individuals and to gather missing address information. The company notified consumers in writing on Sept. 9, 2025.
In response to the breach, Farmer Brothers acted quickly to secure its systems and launched an extensive investigation with the support of federal law enforcement. The company reviewed its existing policies and implemented additional administrative safeguards to strengthen information security.
For those affected, Farmer Brothers is offering twelve months of complimentary credit monitoring and identity restoration services through TransUnion. Impacted individuals are encouraged to enroll in these services, as they are not automatically enrolled. The company has also provided detailed guidance on protecting against identity theft and fraud, including instructions for placing fraud alerts or credit freezes and obtaining free credit reports.
Affected individuals should remain vigilant by monitoring account statements and credit reports for suspicious activity. Farmer Brothers has provided a dedicated call center, managed by CyberScout, to assist with questions and enrollment in credit monitoring services.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.