Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Shamir Medical Center (Assaf Harofeh)

Shamir Medical Center (Assaf Harofeh) Vendor Cyber Rating & Cyber Score

shamir.org

Shamir Medical Center (Assaf Harofeh): A Growing Hospital in a Challenging Era. As the fourth-largest government hospital in Israel, Shamir Medical Center provides over 1 million residents in Israel's central region with state-of-the-art medical care and services. Serving an economically and socially diverse community, we are proud to be the medical 'home base' for the cultural mosaic that is Israel, administrating care to Jews, Muslims and Christians, religious and secular communities, low and middle-income families and veterans as well as immigrants from Ethiopia and the former Soviet Union. At the heart of our approach is the personalized care we deliver to all of our patients and their families and an unwavering commitment to the


SMC A.I CyberSecurity Scoring

SMC
Company Information
Website:https://www.shamir.org/he/
Employees number:447
Number of followers:908
NAICS:71394
Industry Type:Wellness and Fitness Services
Homepage:shamir.org
SMC Risk Score (AI oriented)
Between 600 and 649
logo
SMCWellness and Fitness Services
Updated:
03/04/2026
606/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SMC Global Score (TPRM)
xxxx
logo
SMCWellness and Fitness Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SMC
SMCPoor
Current Score
606Caa (POOR)
01000
3 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
618Before Incident
JUNE 2026
615Before Incident
MAY 2026
610Before Incident
APRIL 2026
609Before Incident
MARCH 2026
606Before Incident
FEBRUARY 2026
603Before Incident
JANUARY 2026
600Before Incident
DECEMBER 2025
594Before Incident
NOVEMBER 2025
592Before Incident
OCTOBER 2025
607Before Incident
Cyber Attack
22 Oct 2025SMC
Shamir Medical Center (Assaf Harofeh Hospital)

Cyberattack on Shamir Medical Center (Assaf Harofeh Hospital) by Iranian Actors

588After Incident
CRITICAL-19
ASS4232942102225
Shamir Medical Center, a major Israeli hospital, was targeted in a cyberattack on Yom Kippur by Iranian actors, initially misattributed to an Eastern European ransomware group. The attack involved a data breach where medical information was leaked, though no medical services were disrupted. Authorities emphasized that the incident crossed a critical red line, as it risked endangering human life by targeting a healthcare facility. The attackers exploited stolen credentials to infiltrate systems, part of a broader campaign against Israeli infrastructure. While the breach was contained early, the leak of sensitive patient data posed severe reputational and operational risks. Israeli cybersecurity agencies, including the National Cyber Directorate and Shin Bet, collaborated to mitigate the damage, preventing more severe consequences like service outages or direct harm to patients. The attack underscored vulnerabilities in supply chain-linked digital service providers, with over ten private firms affected in recent weeks.
INCIDENT DETAILS -
TYPE
CyberattackData BreachDisruption AttemptRansomware (false flag)
MOTIVATION
GeopoliticalDisruption of Critical InfrastructureData Theft
IMPACT
Hospital IT SystemsOperational Impact: Attempted disruption (no actual harm to medical services)Brand Reputation Impact: Moderate (public disclosure of data leak and Iranian attribution)Identity Theft Risk: Potential (medical data leaked)
DATA BREACH
Medical InformationSensitivity Of Data: High (medical records)
SEPTEMBER 2025
605Before Incident
AUGUST 2025
602Before Incident
JUNE 2025
740Before Incident
Ransomware
16 Jun 2025SMC
Shamir Medical Center (Israel)

Qilin Ransomware Gang's 700th Attack in 2025: Global Surge in Cyber Extortion

594After Incident
CRITICAL-146
ASS0992409102325
Shamir Medical Center, a major healthcare provider in Israel, fell victim to a Qilin ransomware attack in 2025, resulting in the theft of 8 TB of sensitive data, including patient records and operational information. The cybercriminals demanded $700,000 in exchange for deleting the stolen data, though it remains unclear whether the ransom was paid. The breach exposed over 300,000 individuals' personal and medical data, posing severe risks to patient privacy, trust, and the hospital’s operational continuity. The attack disrupted critical healthcare services, potentially delaying treatments and administrative processes. Given the scale of data exfiltration—one of Qilin’s largest confirmed breaches in the healthcare sector—the incident underscores the group’s focus on high-value targets where system downtime and data loss can have life-threatening consequences. The financial and reputational damage extends beyond immediate recovery costs, with long-term implications for cybersecurity investments and regulatory compliance in Israel’s healthcare infrastructure.
INCIDENT DETAILS -
TYPE
ransomwaredata breachsystem disruption
MOTIVATION
financial gaindisruptiondata theft for extortion
IMPACT
Total Data Stolen: 47 TB (confirmed attacks)Total Data Stolen All Attacks: 116 TBmanufacturing (e.g., Asahi Group, Alu Perpignan)healthcare (e.g., Shamir Medical Center, Utsunomiya Central Clinic)government (e.g., Region Hauts-de-France, Orleans Parish Sheriff’s Office)education (e.g., Uvalde Consolidated ISD, Mecklenburg County Public Schools)finance (e.g., 30 South Korean asset management firms)retail (e.g., Crossroads Trading Co.)transportation (e.g., Kuala Lumpur International Airport)legal (e.g., Cleveland Municipal Court)Uvalde Consolidated Independent School District3 days (September 15–18, 2025)Mecklenburg County Public Schools1 weekAlu Perpignan3 weeks (system shutdown)Asahi Group Holdingsongoing (as of report date)Cleveland Municipal CourtweeksKuala Lumpur International Airportschool closures (education sector)POS/credit card terminal failures (retail)loss of 3 months’ business (Alu Perpignan)disruption to 80% of high schools (Region Hauts-de-France)airport system disruptions (Malaysia Airports Holdings)Alu Perpignan3 months’ worth of businessHamilton County Sheriff’s Office$48,000 (recovery costs)Synnovis (2024 attack)£33 million ($44 million)high (due to public disclosures and media coverage)high (788,377 records exposed)moderate (e.g., Crossroads Trading Co. POS/credit card terminal issues)
DATA BREACH
personally identifiable information (PII)health records (e.g., Shamir Medical Center: 8 TB)design/proprietary data (e.g., Nissan Creative Box: 4 TB)financial data (e.g., asset management firms)government/legal documents (e.g., Cleveland Municipal Court)high (healthcare, PII, proprietary business data)databasesdesign files (e.g., Nissan Creative Box)health recordsgovernment documentsfinancial records
MAY 2025
769Before Incident
Cyber Attack
01 May 2025SMC
Shamir Medical Center

Suspected Cyberattack on Shamir Medical Center

739After Incident
CRITICAL-30
ASS3002130100325
Shamir Medical Center, a healthcare institution, recently faced a suspected cyberattack that raised concerns over potential unauthorized access to sensitive patient data. While the hospital’s day-to-day operations remained unaffected, cybersecurity experts are actively investigating whether confidential medical records, personal details, or other critical information were compromised. The incident underscores the growing threat to healthcare systems, where breaches can expose highly sensitive data, including patient histories, treatment records, and financial information. The attack’s scope is still under assessment, but the mere suspicion of data leakage poses significant reputational risks and could erode patient trust. If confirmed, the breach may also trigger regulatory scrutiny, financial penalties, and legal liabilities. Healthcare institutions are prime targets for cybercriminals due to the high value of medical data on the black market, making robust cybersecurity measures essential to prevent exploitation and ensure patient safety.
INCIDENT DETAILS -
TYPE
Cyberattack (Suspected)
IMPACT
Data Compromised: Potential sensitive patient dataDowntime: None (operations continued as normal)Brand Reputation Impact: Potential (due to suspected data leak)Identity Theft Risk: Potential (if patient data was compromised)
DATA BREACH
Type Of Data Compromised: Potential sensitive patient dataSensitivity Of Data: High (patient data)Data Exfiltration: Suspected (under examination)Personally Identifiable Information: Potential (patient data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SMC ?
?
What was SMC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was SMC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SMC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SMC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SMC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SMC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SMC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SMC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SMC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SMC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was SMC's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on SMC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SMC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SMC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?