Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Acronis

Acronis Vendor Cyber Rating & Cyber Score

acronis.com

Acronis is a global cyber protection company delivering the only natively integrated cybersecurity, data protection, and infrastructure management platform for managed service providers and IT departments. Acronis solutions are designed to identify, protect, detect, respond, recover and govern IT deployments, ensuring data integrity and business continuity. A Swiss company founded in Singapore in 2003, Acronis has 15 offices worldwide and employees in 60+ countries. Acronis Cyber Platform is available in 26 languages in 150 countries and is used by over 21,000 service providers to protect over 750,000 businesses. Learn more at www.acronis.com. Community Rules: At Acronis, we value respectful, meaningful conversations. We welcome


Acronis A.I CyberSecurity Scoring

Acronis
Company Information
Website:https://www.acronis.com
Employees number:1,912
Number of followers:171,725
NAICS:5112
Industry Type:Software Development
Homepage:acronis.com
Acronis Risk Score (AI oriented)
Between 550 and 599
logo
AcronisSoftware Development
Updated:
16/09/2026
585/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Acronis Global Score (TPRM)
xxxx
logo
AcronisSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

AcronisVery Poor
Current Score
585Ca (VERY POOR)
01000
5 incidents
-47.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
587Before Incident
SEPTEMBER 2026
590Before Incident
Vulnerability
16 Sep 2026 • Acronis
Acronis, cPanel & WHM and Plesk: Acronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wild

Acronis Patches High-Severity Privilege Escalation Flaw in cPanel & Plesk Backup Tools

585After Incident
CRITICAL-5
PLEACRCPA1789547109
Acronis Patches High-Severity Privilege Escalation Flaw in cPanel & Plesk Backup Tools Acronis has released security updates to address a high-severity local privilege-escalation vulnerability (CVE-2026-87886) in its Backup plugin for cPanel & WHM and Backup extension for Plesk. The flaw, rated 7.8 on the CVSS scale, stems from insecure file permissions in Linux-based Acronis backup components, classified as CWE-276 (incorrect default permissions). Exploitation requires local access with low-level privileges but no user interaction. Successful attacks could allow threat actors to escalate privileges, compromising system confidentiality, integrity, and availability. Attackers with initial access via compromised accounts, weak credentials, or vulnerable web applications could leverage the flaw to access backup data, system files, or other customer accounts on shared hosting infrastructure. Acronis confirmed limited, targeted exploitation in the wild but warned that public disclosure and patch availability may increase attack risks. The vulnerability was patched in: - Acronis Backup plugin for cPanel & WHM (version 1.9.3 HF3) - Acronis Backup extension for Plesk (version 1.8.11) Managed service providers and hosting companies are urged to prioritize updates, as cPanel and Plesk servers often host multiple customer workloads. Security teams should monitor for unauthorized local access, unexpected privilege changes, and suspicious activity in Acronis-related files or directories. For organizations unable to patch immediately, Acronis recommends restricting local access, limiting shell permissions, and isolating backup infrastructure from standard hosting environments. The vendor’s advisory confirms the fix addresses one high-severity flaw, with exploitation already detected.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Backup data, system files, customer accounts on shared hosting infrastructureSystems Affected: Acronis Backup plugin for cPanel & WHM, Acronis Backup extension for PleskOperational Impact: Compromised system confidentiality, integrity, and availability
DATA BREACH
Type Of Data Compromised: Backup data, system files, customer account dataSensitivity Of Data: High (backup data, system files, customer accounts)
AUGUST 2026
584Before Incident
JULY 2026
582Before Incident
JUNE 2026
578Before Incident
MAY 2026
569Before Incident
APRIL 2026
566Before Incident
MARCH 2026
564Before Incident
FEBRUARY 2026
574Before Incident
Cyber Attack
06 Feb 2026 • Acronis
Acronis: Transparent Tribe Hacker Group Attacking India’s Startup Ecosystem

Transparent Tribe Shifts Cyber Espionage Focus to India’s Startup Ecosystem

555After Incident
LOW-19
ACR1770407517
Transparent Tribe Shifts Cyber Espionage Focus to India’s Startup Ecosystem A Pakistan-linked hacking group, Transparent Tribe (APT36), has redirected its cyber espionage efforts from traditional government targets to India’s startup sector, particularly companies in cybersecurity and intelligence. Active since 2013, the group now deploys Crimson RAT, a remote access trojan, to infiltrate systems via malicious emails disguised as legitimate documents. Researchers at Acronis uncovered the campaign after detecting suspicious files uploaded from India, containing startup-themed lures. Unlike past operations targeting defense and educational institutions, this wave zeroes in on startups providing security services to law enforcement. Attackers leveraged personal details of a real founder to craft convincing fake documents, increasing the likelihood of successful phishing. The infection chain begins with an ISO container file (e.g., MeetBisht.iso) attached to an email. Inside, a shortcut file masquerades as an Excel document, alongside a hidden folder containing: - A decoy document to distract victims, - A batch script to execute the payload, - The Crimson RAT disguised as an Excel executable. Once opened, the shortcut triggers the batch script, which: - Displays a fake Excel file while silently installing the malware, - Uses PowerShell to disable security warnings, - Creates a hard-linked executable in the user’s app data folder to evade detection. The Crimson RAT payload employs advanced evasion tactics, including: - Artificial file bloat (34MB, with only 80–150KB of malicious code) to bypass signature-based detection, - Randomized function names to hinder analysis, - Custom TCP protocols on non-standard ports (e.g., 18661, 20856) for command-and-control (C2) communications. The malware enables attackers to monitor screens, record audio, steal files, and remotely control infected systems all without the victim’s knowledge. The shift in targeting underscores a growing threat to India’s emerging tech and security sectors, where sensitive data and intellectual property are prime targets.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Cyber Espionage, Intellectual Property Theft
IMPACT
Data Compromised: Sensitive data, intellectual property, files, audio recordings, screen monitoring
DATA BREACH
Sensitive dataIntellectual propertyFilesAudio recordingsSensitivity Of Data: HighData Exfiltration: Yes
JANUARY 2026
573Before Incident
DECEMBER 2025
565Before Incident
NOVEMBER 2025
678Before Incident
Ransomware
01 Nov 2025 • Acronis
JanaWare: JanaWare Ransomware Hits Turkish Users via Tailored Adwind RAT

JanaWare Ransomware Campaign Targets Turkish Users with Stealthy Adwind RAT Variant

559After Incident
CRITICAL-119
ACR1776673520
JanaWare Ransomware Campaign Targets Turkish Users with Stealthy Adwind RAT Variant A newly uncovered ransomware campaign, dubbed JanaWare, is actively targeting users in Turkey using a customized version of the Adwind Remote Access Trojan (RAT). The operation employs geofencing, polymorphic malware, and layered obfuscation to evade detection while maintaining long-term persistence. First observed in 2020, with recent samples compiled as late as November 2025, JanaWare restricts infections to systems in Turkey by verifying language settings, locale configurations, and IP addresses. This localized approach has allowed the campaign to operate under the radar, avoiding broader security scrutiny. The attack begins with phishing emails that lure victims into clicking malicious links, often hosted on Google Drive. These links download a Java archive (JAR) file, which executes via javaw.exe to deploy the Adwind-based payload. The malware then disables security defenses including Microsoft Defender, Volume Shadow Copies, and third-party antivirus tools before downloading a Java-based ransomware module. JanaWare encrypts files using AES encryption and communicates with command-and-control (C2) servers over the Tor network. Ransom demands range between $200 and $400, targeting home users and small-to-medium-sized businesses (SMBs) with a high-volume, low-cost extortion strategy. Victims receive a Turkish-language ransom note directing them to contact attackers via qTox or Tor-based .onion sites. To evade detection, the malware employs polymorphic techniques, modifying its JAR file with random data to generate unique hashes per infection. It also uses obfuscation tools like Stringer and Allatori, along with custom class loaders, to hinder reverse engineering. Security researchers warn that JanaWare exemplifies a growing trend of regionally focused ransomware operations that exploit localized vulnerabilities while avoiding global attention. Indicators of compromise (IOCs) include the MD5 hashes 4f0444e11633a331eddb0deeec17fd69 (Adwind RAT) and b2d5bbf7746c2cb87d5505ced8d6c4c6 (ransomware module).
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: Files encrypted using AES encryptionSystems Affected: Systems in Turkey (home users and SMBs)Operational Impact: Disabling of security defenses (Microsoft Defender, Volume Shadow Copies, third-party antivirus tools)
DATA BREACH
Type Of Data Compromised: Files (encrypted)Data Encryption: AES encryption
MARCH 2023
663Before Incident
Breach
01 Mar 2023 • Acronis
Acronis

Acronis Security Breach

602After Incident
LOW-61
ACR175681023
Acronis minimizes the impact of the most recent security breach by saying that only one customer's account was affected. Several certificate files, command logs, system configurations, system information logs, filesystem archives, and python scripts for the company's maria.db database, backup configuration information, screenshots of backup operations, and more are all included in the Acronis breach. Their preliminary research indicates that the login information used by one particular customer to provide diagnostic data to Acronis support has been compromised. The business also stated that it is unaware of any vulnerabilities impacting its systems and that neither its products nor the security breach harmed them.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Certificate filesCommand logsSystem configurationsSystem information logsFilesystem archivesPython scripts for maria.db databaseBackup configuration informationScreenshots of backup operations
DATA BREACH
Certificate filesCommand logsSystem configurationsSystem information logsFilesystem archivesPython scripts for maria.db databaseBackup configuration informationScreenshots of backup operationsCertificate filesCommand logsSystem configurationsSystem information logsFilesystem archivesPython scriptsBackup configuration informationScreenshots
JANUARY 2020
764Before Incident
Ransomware
01 Jan 2020 • Acronis
JanaWare: New ‘JanaWare’ ransomware targeting Turkish citizens as cybercriminal ecosystem fragments

JanaWare Ransomware Targets Turkey in Low-Cost, High-Volume Campaign

551After Incident
CRITICAL-213
ACR1776198223
JanaWare Ransomware Targets Turkey in Low-Cost, High-Volume Campaign Cybersecurity firm Acronis has uncovered a localized ransomware campaign, JanaWare, specifically targeting users in Turkey since 2020. The operation employs a geofenced malware strain that restricts execution to systems with Turkish language settings and IP addresses within the country, ensuring it evades broader detection. JanaWare follows a low-value, high-volume model, demanding ransoms of $200–$400 far below typical ransomware demands. The campaign primarily affects home users and small-to-medium businesses, with infections spread via phishing emails containing malicious Java archives. Attack chains often begin with Adwind malware, a heavily obfuscated strain designed to bypass security analysis. Victims receive Turkish-language ransom notes embedded in the malware, instructing them to contact attackers via qTox, a decentralized chat platform. Acronis cited a confirmed case where a user’s files were encrypted after opening a Google Drive-linked email in Microsoft Outlook. The malware verifies the victim’s location before proceeding, reinforcing its Turkey-exclusive targeting. The regional focus has likely helped JanaWare operate undetected for years, demonstrating how localized ransomware campaigns can persist quietly in the threat landscape. Acronis noted that the geographic restrictions also hinder international researchers from analyzing the malware, suggesting a deliberate, non-opportunistic strategy. The report emerges amid broader shifts in the ransomware ecosystem. The FBI identified 63 new ransomware variants in 2025, linked to over $32 million in losses, while TRM Labs found a 94% increase in new strains (93 in 2025 vs. 48 in 2024). Despite a drop in blockchain-linked ransomware payments from $1.9 billion in 2024 to $1.3 billion in 2025 activity is expanding beyond traditional safe havens like Russia. Law enforcement now sees opportunities to disrupt gangs due to weaker operational security and traceable laundering infrastructure, though the long-term impact remains uncertain.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Financial Loss: $32 million (broader ransomware ecosystem, not specific to JanaWare)Data Compromised: Files encrypted
DATA BREACH
Type Of Data Compromised: FilesData Encryption: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Acronis ?
?
What was Acronis's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Acronis's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Acronis's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Acronis's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Acronis ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Acronis's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?