Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Brown-Forman

Brown-Forman Vendor Cyber Rating & Cyber Score

brown-forman.com

Brown‑Forman Corporation is a global leader in the spirits industry, responsibly building exceptional beverage alcohol brands for more than 155 years. Headquartered in Louisville, Kentucky, we are guided by our founding promise, “Nothing Better in the Market.” Our premium portfolio includes the Jack Daniel’s Family of Brands, Woodford Reserve, Old Forester, New Mix, el Jimador, Herradura, The Glendronach, Glenglassaugh, Benriach, Diplomático Rum, Gin Mare, Fords Gin, Chambord, and Slane. With approximately 5,000 employees worldwide, we proudly share our passion for fine-quality spirits in more than 170 countries.


Brown-Forman A.I CyberSecurity Scoring

Brown-Forman
Company Information
Website:http://www.brown-forman.com
Employees number:4,733
Number of followers:323,706
NAICS:3121
Industry Type:Beverage Manufacturing
Homepage:brown-forman.com
Brown-Forman Risk Score (AI oriented)
Between 700 and 749
logo
Brown-FormanBeverage Manufacturing
Updated:
28/03/2026
718/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Brown-Forman Global Score (TPRM)
xxxx
logo
Brown-FormanBeverage Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Brown-Forman
Brown-FormanModerate
Current Score
718Ba (MODERATE)
01000
4 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
722Before Incident
MAY 2026
721Before Incident
APRIL 2026
720Before Incident
MARCH 2026
719Before Incident
FEBRUARY 2026
717Before Incident
JANUARY 2026
716Before Incident
DECEMBER 2025
743Before Incident
NOVEMBER 2025
741Before Incident
OCTOBER 2025
740Before Incident
SEPTEMBER 2025
739Before Incident
AUGUST 2025
740Before Incident
JULY 2025
737Before Incident
FEBRUARY 2021
728Before Incident
Ransomware
01 Feb 2021Brown-Forman
Brown-Forman

Brown-Forman Ransomware Breach

638After Incident
CRITICAL-90
BRO281322
Jack Daniel’s parent Brown-Forman was targeted by the REvil ransomware breach. The group stole 1TB of confidential information and data including employees, company agreements, contracts, financial statements, and internal correspondence. The gang is demanding a huge ransom by threatening to leak the data stolen in the attack.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
IMPACT
employeescompany agreementscontractsfinancial statementsinternal correspondence
DATA BREACH
employeescompany agreementscontractsfinancial statementsinternal correspondenceSensitivity Of Data: HighData Exfiltration: Yes
AUGUST 2020
718Before Incident
Ransomware
01 Aug 2020Brown-Forman
Brown-Forman: US liquor giant hit by ransomware – what the rest of us can do to help

Brown-Forman Hit by REvil Ransomware Attack: A Multi-Stage Extortion Scheme Unfolds

628After Incident
CRITICAL-90
BRO1772396670
Brown-Forman Hit by REvil Ransomware Attack: A Multi-Stage Extortion Scheme Unfolds Brown-Forman, the Kentucky-based liquor conglomerate behind global brands like Jack Daniel’s and Finlandia vodka, has fallen victim to a sophisticated ransomware attack orchestrated by the REvil (Sodinokibi) cybercriminal gang. According to reports from Bloomberg, which received an anonymous tip from the attackers, the incident follows REvil’s signature three-stage extortion playbook reconnaissance, data theft, and encryption with a modern twist: double-barrelled blackmail. ### The Attack: How It Unfolded 1. Reconnaissance & Network Infiltration The attackers first breached Brown-Forman’s network, escalating privileges to sysadmin-level access. They mapped the infrastructure, identified backup locations, and disabled security controls to maximize their reach. Trial malware deployments may have been used to test defenses before the full assault. 2. Data Exfiltration (1TB Stolen) Before encrypting files, the gang stole an alleged 1 terabyte of corporate data, spanning over a decade. Bloomberg was provided with links to a dark web portal where sample files were listed as "proof" of the breach. This tactic stealing data before encryption has become a hallmark of modern ransomware, enabling attackers to threaten public leaks if demands aren’t met. 3. Encryption (Prevented in This Case) Typically, REvil would then deploy ransomware to encrypt files across the network. However, Brown-Forman appears to have halted this stage, avoiding the operational disruption seen in other high-profile attacks (e.g., Garmin’s days-long outage). The company has reportedly refused to pay the ransom, a stance that disrupts the extortion cycle but leaves the stolen data at risk of exposure. ### The Evolution of Ransomware: From CryptoLocker to Double Extortion The attack reflects broader shifts in ransomware tactics: - Early Ransomware (2013–2016): Groups like CryptoLocker targeted individual users, demanding $300 per infected device. Later, gangs like SamSam pivoted to network-wide attacks, offering "bulk decryption" for tens of thousands of dollars. - Modern Extortion (2019–Present): REvil and others now steal data first, then encrypt, creating a dual threat: pay for decryption and to prevent a data leak. Recent victims, including Garmin and CWT, have paid millions Garmin reportedly negotiated a $10M demand down to an undisclosed sum, while CWT paid $4.5M for 30,000 encrypted devices. ### Regulatory and Ethical Implications Under most data protection laws, all ransomware attacks are breaches even if files are only encrypted. However, the pre-encryption data theft amplifies the stakes. Companies face: - Regulatory scrutiny for failing to protect data. - Reputational damage if stolen data is leaked (e.g., internal documents, customer records). - No guarantee that paying will prevent leaks attackers may sell or re-extort the data. Brown-Forman’s refusal to pay aligns with the approach of other victims, like law firm Grubman Shire Meiselas & Sacks, which rejected REvil’s threats to auction celebrity data. While the stolen data remains unpublicized, the incident underscores the growing audacity of ransomware gangs and the challenges of deterring them. ### Key Takeaways - Target: Brown-Forman (Jack Daniel’s, Finlandia vodka). - Attackers: REvil (Sodinokibi) gang. - Method: Three-stage extortion (reconnaissance, data theft, encryption). - Data Stolen: 1TB, including files dating back over 10 years. - Outcome: Encryption stage blocked; company refused ransom demands. - Broader Trend: Ransomware gangs increasingly use data theft as leverage, with demands now reaching millions per attack. The incident highlights the escalating financial and operational risks of ransomware, as well as the difficult choices victims face in responding to extortion.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (extortion), data theft for leverage
IMPACT
Data Compromised: 1TB of corporate dataOperational Impact: Prevented encryption stage, avoiding operational disruptionBrand Reputation Impact: Potential reputational damage if stolen data is leakedLegal Liabilities: Regulatory scrutiny under data protection laws
DATA BREACH
Type Of Data Compromised: Corporate data (internal documents, potentially customer records)Sensitivity Of Data: High (spanning over a decade)Data Exfiltration: 1TB stolen before encryptionData Encryption: Attempted but prevented
JULY 2020
773Before Incident
Breach
28 Jul 2020Brown-Forman
Brown-Forman Corporation

Brown-Forman Corporation Data Breach (2020)

720After Incident
CRITICAL-53
BRO1000091725
The Maine Office of the Attorney General disclosed on May 10, 2021, that Brown-Forman Corporation suffered a data breach due to unauthorized access to its internal network, initially detected on July 28, 2020, and confirmed on August 4, 2020. The incident impacted 72 individuals, with compromised data potentially including Social Security numbers (SSNs) and credit card information linked to expired cards. The breach exposed sensitive personal and financial details, raising concerns over identity theft, fraud, and reputational harm. While the compromised credit card data pertained to expired cards—reducing immediate financial risk—the exposure of SSNs poses long-term threats, as such information is permanent and highly valuable to cybercriminals. The company likely faced regulatory scrutiny, customer distrust, and potential legal liabilities due to the failure to safeguard personally identifiable information (PII). The attack underscores vulnerabilities in corporate network security, particularly in protecting high-value employee and customer data from unauthorized intrusions. Though the scale was limited to 72 individuals, the nature of the exposed data elevates the severity of the incident.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numberscredit card information (expired cards)internal networkIdentity Theft Risk: Potential (due to SSN exposure)Payment Information Risk: Potential (expired credit card data)
DATA BREACH
Social Security numberscredit card information (expired)Sensitivity Of Data: High (SSNs, payment data)
APRIL 2020
806Before Incident
Cyber Attack
14 Apr 2020Brown-Forman
Brown-Forman Corporation

Data Breach at Brown-Forman Corporation

771After Incident
HIGH-35
BRO740080425
The California Office of the Attorney General reported a data breach involving Brown-Forman Corporation on August 25, 2020. The breach occurred on July 28, 2020, and involved a cyber attack that compromised personal information about current and former employees, as well as certain beneficiaries. Approximately, the data included names, Social Security Numbers, email addresses, home addresses, job titles, and salary information, although the number of affected individuals was not specified.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namesSocial Security Numbersemail addresseshome addressesjob titlessalary information
DATA BREACH
namesSocial Security Numbersemail addresseshome addressesjob titlessalary informationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Brown-Forman ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Brown-Forman's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Brown-Forman's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Brown-Forman ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Brown-Forman's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Brown-Forman Cyber Scoring History | Rankiteo