Company Details
marathon-petroleum-company
16,023
336,851
211
marathonpetroleum.com
41
MAR_2224870
Completed

Marathon Petroleum Corporation Company CyberSecurity Posture
marathonpetroleum.comMarathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.
Company Details
marathon-petroleum-company
16,023
336,851
211
marathonpetroleum.com
41
MAR_2224870
Completed
Between 800 and 849

MPC Global Score (TPRM)XXXX



No incidents recorded for Marathon Petroleum Corporation in 2025.
No incidents recorded for Marathon Petroleum Corporation in 2025.
No incidents recorded for Marathon Petroleum Corporation in 2025.
MPC cyber incidents detection timeline including parent company and subsidiaries

Marathon Petroleum Corporation (MPC) is a leading, integrated, downstream and midstream energy company headquartered in Findlay, Ohio. The company operates the nation's largest refining system. MPC's marketing system includes branded locations across the United States, including Marathon brand retail outlets. MPC also owns the general partner and majority limited partner interest in MPLX LP, a midstream company that owns and operates gathering, processing, and fractionation assets, as well as crude oil and light product transportation and logistics infrastructure. More information is available at www.marathonpetroleum.com.

At Enbridge, our goal is to be the first-choice energy delivery company in North America and beyond—for customers, communities, investors, regulators and policymakers, and employees. We also recognize the importance of a secure, reliable and affordable supply of energy, which we deliver every day th

The need for energy is universal. That's why ExxonMobil scientists and engineers are pioneering new research and pursuing new technologies to reduce emissions while creating more efficient fuels. We're committed to responsibly meeting the world's energy needs. We aim to achieve #netzero emissions
Oxy is an international energy company with assets primarily in the United States, the Middle East and North Africa. We are one of the largest oil producers in the U.S., including a leading producer in the Permian and DJ basins, and offshore Gulf of Mexico. Our midstream and marketing segment provid
Fortune Global 500 Company, Bharat Petroleum is the second largest Indian Oil Marketing Company and one of the premier integrated energy companies in India, engaged in refining of crude oil and marketing of petroleum products, with a significant presence in the upstream and downstream sectors of the
We are a global oil and gas company tasked with an important job—to safely find and deliver energy for the world. We’re experts in what we do—from the well site to the office. Across our operations and activities in 13 countries, we never forget our responsibility to be a great neighbor, and a gre

Cameron is a SLB company. For updates and information, please follow the main SLB company page on LinkedIn at: https://www.linkedin.com/company/slbglobal/ Cameron, a SLB company, is a leading provider of flow equipment products, systems and services to worldwide oil, gas and process industries. Lev

Nosso propósito é prover energia que assegure prosperidade de forma ética, justa, segura e competitiva. Queremos ser a melhor empresa diversificada e integrada de energia na geração de valor, construindo um mundo mais sustentável, conciliando o foco em óleo e gás com a diversificação em negócios de

CE Oltenia is the sole lignite producer in Romania and one of the major players in the energy services sector in Romania, set-up on 31 May 2012 following a decision of the Romanian Government for the reorganization of the energy sector through a merger between a national lignite company (Societate

NOV delivers technology-driven solutions to empower the global energy industry. For more than 150 years, NOV has pioneered innovations that enable its customers to safely produce abundant energy while minimizing environmental impact. The energy industry depends on NOV’s deep expertise and technology
.png)
Maryann T. Mannen, president and CEO, becomes chairman Jan. 1, 2026 as Michael J. Hennigan retires; John Surma continues as independent lead...
Marathon Petroleum (NYSE: MPC) will release Q3 2025 financial results on November 4, followed by an 11 AM EST conference call.
Mary Rose Martinez, CISO and VP at Marathon Petroleum, earned a HoustonCISO ORBIE Award for leading cybersecurity innovation,...
A California federal judge on Friday said he'd grant final approval to a $7.2 million deal by Marathon Petroleum and two related companies...
Marathon Petroleum Corp beat Wall Street estimates for second-quarter profit on Tuesday, benefiting from a rebound in refining margins as...
Marathon Petroleum (NYSE:MPC) has announced its latest quarterly dividend. The company's board of directors has declared a dividend of $0.91...
Role models for students, parents, educators, and the cybersecurity community Sponsored by Secureworks.
HOUSTON, April 24, 2025 (GLOBE NEWSWIRE) -- The 2025 HoustonCISO ORBIE Awards recognized the exceptional leadership and cyber resilience of...
Marathon Petroleum Corp, a leading integrated downstream energy company, has released its 2024 Form 10-K report, detailing its financial and...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Marathon Petroleum Corporation is http://www.marathonpetroleum.com/.
According to Rankiteo, Marathon Petroleum Corporation’s AI-generated cybersecurity score is 806, reflecting their Good security posture.
According to Rankiteo, Marathon Petroleum Corporation currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Marathon Petroleum Corporation is not certified under SOC 2 Type 1.
According to Rankiteo, Marathon Petroleum Corporation does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Marathon Petroleum Corporation is not listed as GDPR compliant.
According to Rankiteo, Marathon Petroleum Corporation does not currently maintain PCI DSS compliance.
According to Rankiteo, Marathon Petroleum Corporation is not compliant with HIPAA regulations.
According to Rankiteo,Marathon Petroleum Corporation is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Marathon Petroleum Corporation operates primarily in the Oil and Gas industry.
Marathon Petroleum Corporation employs approximately 16,023 people worldwide.
Marathon Petroleum Corporation presently has no subsidiaries across any sectors.
Marathon Petroleum Corporation’s official LinkedIn profile has approximately 336,851 followers.
Marathon Petroleum Corporation is classified under the NAICS code 211, which corresponds to Oil and Gas Extraction.
No, Marathon Petroleum Corporation does not have a profile on Crunchbase.
Yes, Marathon Petroleum Corporation maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/marathon-petroleum-company.
As of December 11, 2025, Rankiteo reports that Marathon Petroleum Corporation has not experienced any cybersecurity incidents.
Marathon Petroleum Corporation has an estimated 10,530 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, Marathon Petroleum Corporation has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.