Company Details
asmglobal
2,610
62,773
None
legendsglobal.com
0
ASM_2262845
In-progress

ASM Global Company CyberSecurity Posture
legendsglobal.comASM Global is the world’s leading venue management company and producer of live event experiences. Acquired by Legends in 2024, with over 400 premier venues worldwide, ASM Global operates and invests in the world's most important stadiums, arenas, convention centers, and theaters, including entertainment districts and mixed-use developments. We produce over 20,000 live events annually, welcoming more than 164 million guests each year. As the global leader in content programming and revenue optimization, our best-in-class management leverages the latest data-driven marketing strategies to deliver maximum value and profitability for venue owners. Beyond the walls of our venues, ASM Global is actively working to invest in people, strengthen our communities, and protect the environment. Our corporate social responsibility platform, ASM Global Acts, embodies a refreshing, modern commitment to social equity and global sustainability. A robust and growing DE&I initiative, commitment to local purchasing, and prioritizing green innovations (with an industry-leading 50+ certified green venues) are just a couple of examples of ASM Global’s impactful, environmentally friendly outlook. As the global industry leader, we understand the importance of setting an exceptional example while having a great time doing it.
Company Details
asmglobal
2,610
62,773
None
legendsglobal.com
0
ASM_2262845
In-progress
Between 750 and 799

ASM Global Global Score (TPRM)XXXX

Description: ASM Global Parent Inc. experienced a **cyberattack** detected on **October 12, 2023**, exposing sensitive personal and health data of customers. The compromised information included **names, Social Security numbers, driver’s license/state ID numbers, passport numbers, credit/debit card details, and medical records** (diagnoses and treatment details). The breach led to a **$1.4 million class-action settlement**, with affected individuals eligible for reimbursement of up to **$10,000** for documented losses (e.g., identity theft, fraud) and pro rata cash payments. The lawsuit alleged **negligence in data protection**, though ASM denied wrongdoing. The incident highlights severe risks to **financial, reputational, and personal privacy**, with potential long-term consequences for victims, including fraud and medical identity theft. The settlement fund covers legal fees, administrative costs, and compensation for claimants, with payouts contingent on validation of losses.


No incidents recorded for ASM Global in 2025.
No incidents recorded for ASM Global in 2025.
No incidents recorded for ASM Global in 2025.
ASM Global cyber incidents detection timeline including parent company and subsidiaries

ASM Global is the world’s leading venue management company and producer of live event experiences. Acquired by Legends in 2024, with over 400 premier venues worldwide, ASM Global operates and invests in the world's most important stadiums, arenas, convention centers, and theaters, including entertainment districts and mixed-use developments. We produce over 20,000 live events annually, welcoming more than 164 million guests each year. As the global leader in content programming and revenue optimization, our best-in-class management leverages the latest data-driven marketing strategies to deliver maximum value and profitability for venue owners. Beyond the walls of our venues, ASM Global is actively working to invest in people, strengthen our communities, and protect the environment. Our corporate social responsibility platform, ASM Global Acts, embodies a refreshing, modern commitment to social equity and global sustainability. A robust and growing DE&I initiative, commitment to local purchasing, and prioritizing green innovations (with an industry-leading 50+ certified green venues) are just a couple of examples of ASM Global’s impactful, environmentally friendly outlook. As the global industry leader, we understand the importance of setting an exceptional example while having a great time doing it.


Leading global entertainment company born in Latin America, with over 6,000 screens, 3rd largest in the world. Cinépolis has operations in Mexico, Central and South America, Asia, Spain, India and United States of America. With more than 40k cinepolites delivering the "Cinepolis" experience based i

At DIRECTV, we believe TV is meant to be enjoyed. Everything we do is focused on delivering an entertainment experience above and beyond expectations and industry standards and advocating for excellence on behalf of our customers. A shared passion for the joy of television defines our mission to

Descubrimos que el entretenimiento se vive de manera diferente, así que unimos conocimientos, desarrollamos lazos y encontramos una familia con un único objetivo "Crear momentos inolvidables” Integramos las experiencias de Cinemex Tradicional, Market, Platino, los video juegos y la realidad vi
.png)
ASM International (ENXTAM:ASM) turned in a net profit margin of 23.9%, up from 20% last year, with annual earnings growth hitting an...
ASM International posted orders below analysts' forecasts for the third quarter as bookings from China fell substantially and demand for...
Computer chip equipment maker ASM International reported third-quarter bookings below market expectations on Tuesday, hit by a...
Tax file numbers, bank account details, superannuation IDs and other sensitive personal information was stolen in a cyber attack on the...
Criminal IP at Booth J30 | Sands Expo Singapore | October 21 – 23, 2025TORRANCE, Calif., Oct. 14, 2025 (GLOBE NEWSWIRE) -- Criminal IP,...
ASM International (ENXTAM:ASM) is catching extra attention as European chip equipment stocks respond to a wave of optimism.
Orders have declined from producers of integrated circuits that power smartphones and other electronic devices.
ASM International lowers revenue forecast for second half of year due to lower customer demand. Share price falls nearly 6 percent.
Venue and entertainment behemoths Legends and ASM Global have officially united under the new banner of Legends Global.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of ASM Global is http://www.asmglobal.com.
According to Rankiteo, ASM Global’s AI-generated cybersecurity score is 756, reflecting their Fair security posture.
According to Rankiteo, ASM Global currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, ASM Global is not certified under SOC 2 Type 1.
According to Rankiteo, ASM Global does not hold a SOC 2 Type 2 certification.
According to Rankiteo, ASM Global is not listed as GDPR compliant.
According to Rankiteo, ASM Global does not currently maintain PCI DSS compliance.
According to Rankiteo, ASM Global is not compliant with HIPAA regulations.
According to Rankiteo,ASM Global is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
ASM Global operates primarily in the Entertainment industry.
ASM Global employs approximately 2,610 people worldwide.
ASM Global presently has no subsidiaries across any sectors.
ASM Global’s official LinkedIn profile has approximately 62,773 followers.
ASM Global is classified under the NAICS code None, which corresponds to Others.
No, ASM Global does not have a profile on Crunchbase.
Yes, ASM Global maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/asmglobal.
As of December 04, 2025, Rankiteo reports that ASM Global has experienced 1 cybersecurity incidents.
ASM Global has an estimated 2,141 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Total Financial Loss: The total financial loss from these incidents is estimated to be $0.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notification letters sent to affected individuals; settlement claims process established (online/mail)...
Title: ASM Global Parent $1.4M Data Breach Class Action Settlement
Description: ASM Global Parent Inc. agreed to pay $1.4 million to resolve a class action lawsuit alleging it failed to adequately protect sensitive personal and health information, which threat actors accessed during a cyberattack. The exposed information included names, Social Security numbers, driver’s license or state identification numbers, passport numbers, credit or debit card details, and, in some cases, medical diagnosis and treatment details.
Date Detected: 2023-10-12
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Data Compromised: Names, Social security numbers, Driver’s license or state identification numbers, Passport numbers, Credit or debit card details, Medical diagnosis and treatment details (in some cases)
Brand Reputation Impact: Class action lawsuit and settlement
Legal Liabilities: $1.4M settlement fund (including attorneys' fees, administration costs, and class member payments)
Identity Theft Risk: High (due to exposure of SSNs, driver’s license numbers, and financial data)
Payment Information Risk: High (credit/debit card details exposed)
Average Financial Loss: The average financial loss per incident is $0.00.
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Protected Health Information (Phi), Payment Card Information (Pci) and .

Entity Name: ASM Global Parent Inc.
Entity Type: Corporation
Location: United States
Customers Affected: Residents of the United States whose personal information was compromised in the incident detected on Oct. 12, 2023

Communication Strategy: Notification letters sent to affected individuals; settlement claims process established (online/mail).

Type of Data Compromised: Personally identifiable information (pii), Protected health information (phi), Payment card information (pci)
Sensitivity of Data: High (includes SSNs, medical data, and financial information)
Data Exfiltration: Yes
Personally Identifiable Information: NamesSocial Security numbersDriver’s license/state ID numbersPassport numbersCredit/debit card detailsMedical diagnosis/treatment details

Legal Actions: Class action lawsuit settled for $1.4M
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through Class action lawsuit settled for $1.4M.

Source: Class Action Settlement Notice (ASM Global Parent Inc. Data Security Incident Litigation)

Source: Settlement Administrator Contact: 844-496-1268

Source: Mailing Address for Claims: ASM Global Parent Inc. Data Security Incident Litigation, c/o Settlement Administrator, P.O. Box 25226, Santa Ana, CA 92799
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Class Action Settlement Notice (ASM Global Parent Inc. Data Security Incident Litigation), and Source: Settlement Administrator Contact: 844-496-1268, and Source: Mailing Address for Claims: ASM Global Parent Inc. Data Security Incident Litigation, c/o Settlement Administrator, P.O. Box 25226, Santa Ana, CA 92799.

Investigation Status: Settled (class action lawsuit resolved with $1.4M fund)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notification letters sent to affected individuals; settlement claims process established (online/mail)..

Stakeholder Advisories: Notification letters sent to affected U.S. residents; claim submission instructions provided (online/mail).
Customer Advisories: Eligible class members can submit claims for out-of-pocket expenses (up to $10,000) or pro rata cash payments. Deadline: Jan. 2, 2026.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Notification letters sent to affected U.S. residents; claim submission instructions provided (online/mail)., Eligible class members can submit claims for out-of-pocket expenses (up to $10,000) or pro rata cash payments. Deadline: Jan. 2 and 2026..

Root Causes: Alleged failure to adequately protect personal and health information (specific technical root causes not disclosed).
Most Recent Incident Detected: The most recent incident detected was on 2023-10-12.
Highest Financial Loss: The highest financial loss from an incident was {'settlement_fund': '$1.4M', 'out_of_pocket_expense_reimbursement': 'Up to $10,000 per claimant', 'pro_rata_cash_payment': 'Remainder of fund after expenses (California residents receive 2 shares)'}.
Most Significant Data Compromised: The most significant data compromised in an incident were Names, Social Security numbers, Driver’s license or state identification numbers, Passport numbers, Credit or debit card details, Medical diagnosis and treatment details (in some cases) and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Social Security numbers, Driver’s license or state identification numbers, Credit or debit card details, Names, Passport numbers and Medical diagnosis and treatment details (in some cases).
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was Class action lawsuit settled for $1.4M.
Most Recent Source: The most recent source of information about an incident are Class Action Settlement Notice (ASM Global Parent Inc. Data Security Incident Litigation), Mailing Address for Claims: ASM Global Parent Inc. Data Security Incident Litigation, c/o Settlement Administrator, P.O. Box 25226, Santa Ana, CA 92799 and Settlement Administrator Contact: 844-496-1268.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Settled (class action lawsuit resolved with $1.4M fund).
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Notification letters sent to affected U.S. residents; claim submission instructions provided (online/mail)., .
Most Recent Customer Advisory: The most recent customer advisory issued were an Eligible class members can submit claims for out-of-pocket expenses (up to $10,000) or pro rata cash payments. Deadline: Jan. 2 and 2026.
.png)
MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands in both array and string formats. When a string format is provided, it is passed directly to shell interpretation (sh -c) without input validation, allowing shell metacharacters to be interpreted. This vulnerability can be exploited through direct command injection or indirect prompt injection attacks, where AI agents may execute commands without explicit user intent. This vulnerability is fixed in 2.9.8.
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.
An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.
Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.
Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.