ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Marathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.

Marathon Petroleum Corporation A.I CyberSecurity Scoring

MPC

Company Details

Linkedin ID:

marathon-petroleum-company

Employees number:

16,023

Number of followers:

336,851

NAICS:

211

Industry Type:

Oil and Gas

Homepage:

marathonpetroleum.com

IP Addresses:

41

Company ID:

MAR_2224870

Scan Status:

Completed

AI scoreMPC Risk Score (AI oriented)

Between 800 and 849

https://images.rankiteo.com/companyimages/marathon-petroleum-company.jpeg
MPC Oil and Gas
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreMPC Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/marathon-petroleum-company.jpeg
MPC Oil and Gas
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

MPC Company CyberSecurity News & History

Past Incidents
0
Attack Types
0
No data available
Ailogo

MPC Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for MPC

Incidents vs Oil and Gas Industry Average (This Year)

No incidents recorded for Marathon Petroleum Corporation in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Marathon Petroleum Corporation in 2025.

Incident Types MPC vs Oil and Gas Industry Avg (This Year)

No incidents recorded for Marathon Petroleum Corporation in 2025.

Incident History — MPC (X = Date, Y = Severity)

MPC cyber incidents detection timeline including parent company and subsidiaries

MPC Company Subsidiaries

SubsidiaryImage

Marathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.

Loading...
similarCompanies

MPC Similar Companies

Enbridge

At Enbridge, our goal is to be the first-choice energy delivery company in North America and beyond—for customers, communities, investors, regulators and policymakers, and employees. We also recognize the importance of a secure, reliable and affordable supply of energy, which we deliver every day th

ExxonMobil

The need for energy is universal. That's why ExxonMobil scientists and engineers are pioneering new research and pursuing new technologies to reduce emissions while creating more efficient fuels. We're committed to responsibly meeting the world's energy needs. We aim to achieve #netzero emissions

Oxy is an international energy company with assets primarily in the United States, the Middle East and North Africa. We are one of the largest oil producers in the U.S., including a leading producer in the Permian and DJ basins, and offshore Gulf of Mexico. Our midstream and marketing segment provid

Bharat Petroleum Corporation Limited

Fortune Global 500 Company, Bharat Petroleum is the second largest Indian Oil Marketing Company and one of the premier integrated energy companies in India, engaged in refining of crude oil and marketing of petroleum products, with a significant presence in the upstream and downstream sectors of the

ConocoPhillips

We are a global oil and gas company tasked with an important job—to safely find and deliver energy for the world. We’re experts in what we do—from the well site to the office. Across our operations and activities in 13 countries, we never forget our responsibility to be a great neighbor, and a gre

Cameron, a Schlumberger company

Cameron is a SLB company. For updates and information, please follow the main SLB company page on LinkedIn at: https://www.linkedin.com/company/slbglobal/ Cameron, a SLB company, is a leading provider of flow equipment products, systems and services to worldwide oil, gas and process industries. Lev

Nosso propósito é prover energia que assegure prosperidade de forma ética, justa, segura e competitiva. Queremos ser a melhor empresa diversificada e integrada de energia na geração de valor, construindo um mundo mais sustentável, conciliando o foco em óleo e gás com a diversificação em negócios de

Complexul Energetic Oltenia

CE Oltenia is the sole lignite producer in Romania and one of the major players in the energy services sector in Romania, set-up on 31 May 2012 following a decision of the Romanian Government for the reorganization of the energy sector through a merger between a national lignite company (Societate

NOV delivers technology-driven solutions to empower the global energy industry. For more than 150 years, NOV has pioneered innovations that enable its customers to safely produce abundant energy while minimizing environmental impact. The energy industry depends on NOV’s deep expertise and technology

newsone

MPC CyberSecurity News

November 04, 2025 08:00 AM
Marathon Petroleum (NYSE: MPC) elects CEO Maryann T. Mannen as chairman Jan. 1, 2026

Maryann T. Mannen, president and CEO, becomes chairman Jan. 1, 2026 as Michael J. Hennigan retires; John Surma continues as independent lead...

September 09, 2025 07:00 AM
Major Oil Refiner Marathon Petroleum Sets Q3 2025 Earnings Release Date - What to Expect

Marathon Petroleum (NYSE: MPC) will release Q3 2025 financial results on November 4, followed by an 11 AM EST conference call.

September 04, 2025 07:00 AM
MPC’s Martinez honored with HoustonCISO ORBIE Award

Mary Rose Martinez, CISO and VP at Marathon Petroleum, earned a HoustonCISO ORBIE Award for leading cybersecurity innovation,...

August 22, 2025 07:00 AM
Marathon Petroleum Cos. Near Final OK On $7M Wage Deal

A California federal judge on Friday said he'd grant final approval to a $7.2 million deal by Marathon Petroleum and two related companies...

August 05, 2025 07:00 AM
Top US refiner Marathon Petroleum beats quarterly profit on higher refining margins

Marathon Petroleum Corp beat Wall Street estimates for second-quarter profit on Tuesday, benefiting from a rebound in refining margins as...

July 30, 2025 07:00 AM
Marathon Petroleum Sets $0.91 Dividend Payout: Key Dates for Investors Revealed

Marathon Petroleum (NYSE:MPC) has announced its latest quarterly dividend. The company's board of directors has declared a dividend of $0.91...

May 20, 2025 07:00 AM
Women Know Cyber: 150 Fascinating Females Fighting Cybercrime

Role models for students, parents, educators, and the cybersecurity community Sponsored by Secureworks.

April 24, 2025 07:00 AM
Top Security Executives Recognized at the 2025 HoustonCISO ORBIE Awards

HOUSTON, April 24, 2025 (GLOBE NEWSWIRE) -- The 2025 HoustonCISO ORBIE Awards recognized the exceptional leadership and cyber resilience of...

February 27, 2025 08:00 AM
Marathon Petroleum Corp SEC 10-K Report

Marathon Petroleum Corp, a leading integrated downstream energy company, has released its 2024 Form 10-K report, detailing its financial and...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

MPC CyberSecurity History Information

Official Website of Marathon Petroleum Corporation

The official website of Marathon Petroleum Corporation is http://www.marathonpetroleum.com/.

Marathon Petroleum Corporation’s AI-Generated Cybersecurity Score

According to Rankiteo, Marathon Petroleum Corporation’s AI-generated cybersecurity score is 806, reflecting their Good security posture.

How many security badges does Marathon Petroleum Corporation’ have ?

According to Rankiteo, Marathon Petroleum Corporation currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Marathon Petroleum Corporation have SOC 2 Type 1 certification ?

According to Rankiteo, Marathon Petroleum Corporation is not certified under SOC 2 Type 1.

Does Marathon Petroleum Corporation have SOC 2 Type 2 certification ?

According to Rankiteo, Marathon Petroleum Corporation does not hold a SOC 2 Type 2 certification.

Does Marathon Petroleum Corporation comply with GDPR ?

According to Rankiteo, Marathon Petroleum Corporation is not listed as GDPR compliant.

Does Marathon Petroleum Corporation have PCI DSS certification ?

According to Rankiteo, Marathon Petroleum Corporation does not currently maintain PCI DSS compliance.

Does Marathon Petroleum Corporation comply with HIPAA ?

According to Rankiteo, Marathon Petroleum Corporation is not compliant with HIPAA regulations.

Does Marathon Petroleum Corporation have ISO 27001 certification ?

According to Rankiteo,Marathon Petroleum Corporation is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Marathon Petroleum Corporation

Marathon Petroleum Corporation operates primarily in the Oil and Gas industry.

Number of Employees at Marathon Petroleum Corporation

Marathon Petroleum Corporation employs approximately 16,023 people worldwide.

Subsidiaries Owned by Marathon Petroleum Corporation

Marathon Petroleum Corporation presently has no subsidiaries across any sectors.

Marathon Petroleum Corporation’s LinkedIn Followers

Marathon Petroleum Corporation’s official LinkedIn profile has approximately 336,851 followers.

NAICS Classification of Marathon Petroleum Corporation

Marathon Petroleum Corporation is classified under the NAICS code 211, which corresponds to Oil and Gas Extraction.

Marathon Petroleum Corporation’s Presence on Crunchbase

No, Marathon Petroleum Corporation does not have a profile on Crunchbase.

Marathon Petroleum Corporation’s Presence on LinkedIn

Yes, Marathon Petroleum Corporation maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/marathon-petroleum-company.

Cybersecurity Incidents Involving Marathon Petroleum Corporation

As of December 11, 2025, Rankiteo reports that Marathon Petroleum Corporation has not experienced any cybersecurity incidents.

Number of Peer and Competitor Companies

Marathon Petroleum Corporation has an estimated 10,530 peer or competitor companies worldwide.

Marathon Petroleum Corporation CyberSecurity History Information

How many cyber incidents has Marathon Petroleum Corporation faced ?

Total Incidents: According to Rankiteo, Marathon Petroleum Corporation has faced 0 incidents in the past.

What types of cybersecurity incidents have occurred at Marathon Petroleum Corporation ?

Incident Types: The types of cybersecurity incidents that have occurred include .

Incident Details

What are the most common types of attacks the company has faced ?

Additional Questions

cve

Latest Global CVEs (Not Company-Specific)

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.

Risk Information
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Description

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.

Risk Information
cvss3
Base: 8.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Description

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Risk Information
cvss3
Base: 5.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=marathon-petroleum-company' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge