Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Citi

Citi Vendor Cyber Rating & Cyber Score

citigroup.com

Citi's mission is to serve as a trusted partner to our clients by responsibly providing financial services that enable growth and economic progress. Our core activities are safeguarding assets, lending money, making payments and accessing the capital markets on behalf of our clients. We have over 200 years of experience helping our clients meet the world's toughest challenges and embrace its greatest opportunities. We are Citi, the global bank – an institution connecting millions of people across hundreds of countries and cities. For information on Citi’s commitment to privacy, visit on.citi/privacy.


Citi A.I CyberSecurity Scoring

Citi
Company Information
Website:http://www.citigroup.com
Employees number:200,467
Number of followers:5,098,515
NAICS:52
Industry Type:Financial Services
Homepage:citigroup.com
Citi Risk Score (AI oriented)
Between 750 and 799
logo
CitiFinancial Services
Updated:
20/05/2026
790/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Citi Global Score (TPRM)
xxxx
logo
CitiFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Citi
CitiFair
Current Score
790Baa (FAIR)
01000
4 incidents
-10 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
795Before Incident
MAY 2026
791Before Incident
APRIL 2026
792Before Incident
MARCH 2026
790Before Incident
FEBRUARY 2026
790Before Incident
JANUARY 2026
789Before Incident
DECEMBER 2025
797Before Incident
Cyber Attack
01 Dec 2025Citi
Navy Federal Credit Union, USAA, Citibank, Fidelity Investments and Wells Fargo: Operation DoppelBrand: Weaponizing Fortune 500 Brands

Operation DoppelBrand: Sophisticated Phishing Campaign Targets Fortune 500 Firms

787After Incident
CRITICAL-10
CITWELNAVUSAFID1771266975
Operation DoppelBrand: Sophisticated Phishing Campaign Targets Fortune 500 Firms An elusive cyberthreat group known as GS7 has been running Operation DoppelBrand, a large-scale phishing campaign targeting Fortune 500 companies, financial institutions, and high-value entities worldwide. First observed between December 2025 and January 2026, the operation leverages near-perfect replicas of corporate login portals to steal credentials and deploy remote management and monitoring (RMM) tools for further exploitation. ### Key Details of the Campaign - Targets: Primarily U.S.-based financial institutions including Wells Fargo, USAA, Navy Federal Credit Union, Fidelity Investments, and Citibank alongside technology, healthcare, and telecommunications firms in Europe and other regions. - Tactics: GS7 registers over 150 malicious domains via registrars like NameCheap and OwnRegistrar, routing traffic through Cloudflare to evade detection. Attackers exfiltrate stolen data usernames, passwords, IP addresses, geolocation, device fingerprints, and timestamps to Telegram bots controlled by the group. - Infrastructure: The group has operated since at least 2022, with claims of activity dating back nearly a decade. Researchers linked GS7 to Brazilian cybercrime forums, where stolen credentials and financial data are traded. - Impact: Beyond credential theft, GS7 installs RMM tools on victim systems, enabling remote access or malware deployment. The campaign’s sophistication including rotating infrastructure and meticulous branding mimicry has allowed it to evade detection until now. ### Researcher Findings Security firm SOCRadar uncovered the operation, identifying a Telegram group ("NfResultz by GS") tied to the threat actor. A self-proclaimed GS7 member provided screenshots of past campaigns, including a Fidelity Investments phishing demo that triggered RMM tool downloads upon login. SOCRadar released TTPs (tactics, techniques, and procedures) and IoCs (indicators of compromise) to help defenders track the group’s activities. With English-speaking markets as the primary focus, GS7’s DoppelBrand campaign remains active, underscoring the growing threat of highly organized, financially motivated phishing operations.
INCIDENT DETAILS -
TYPE
Phishing Campaign
MOTIVATION
Financial gain, data theft
IMPACT
Data Compromised: Usernames, passwords, IP addresses, geolocation, device fingerprints, timestampsSystems Affected: Corporate login portals, victim systems with RMM tools installedOperational Impact: Remote access or malware deployment on victim systemsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials, device fingerprints, geolocation, timestampsSensitivity Of Data: HighData Exfiltration: Yes, to Telegram botsPersonally Identifiable Information: Usernames, passwords, IP addresses, device fingerprints
NOVEMBER 2025
796Before Incident
OCTOBER 2025
796Before Incident
SEPTEMBER 2025
795Before Incident
AUGUST 2025
794Before Incident
JULY 2025
793Before Incident
JANUARY 2025
830Before Incident
Breach
01 Jan 2025Citi
JPMorgan Chase, Citigroup and Morgan Stanley: Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook

Cyber Threats in Finance: 2025’s Rising Risks and Evolving Attack Tactics

787After Incident
CRITICAL-43
CITJPM1776832106
Cyber Threats in Finance: 2025’s Rising Risks and Evolving Attack Tactics In 2025, financially motivated cyberattacks dominated the financial sector, driving 90% of breaches targeting banks, insurers, and payment processors. Data breaches accounted for 64% of incidents, with ransomware making up the remaining 36%. The average cost of a breach in finance reached $5.56 million per incident, the second-highest across all industries. Personal data was the most frequently compromised asset (54% of cases), followed by internal organizational data (35%) and credentials (22%). Attackers leveraged stolen information for fraud, credential resale, and persistent network access. Initial access methods remained consistent, with hacking (45%), malware (37%), and social engineering (25%) as the primary vectors. AI Accelerates Attack Timelines and Fraud AI integration reshaped cyber threats in 2025, compressing the window between vulnerability disclosure and exploitation. Machine learning-powered scanning tools enabled faster reconnaissance, while adaptive malware evaded signature-based detection by dynamically altering behavior in response to security controls. Generative AI amplified social engineering, producing contextually accurate phishing emails, deepfake impersonations, and fraudulent invoices that bypassed traditional filters. Fraud-as-a-service offerings on underground markets further lowered the barrier to entry for less skilled attackers. Unmanaged AI adoption within organizations termed shadow AI contributed to 20% of AI-related breaches. Among affected institutions, 97% lacked adequate access controls for AI systems. Third-Party Risks Escalate Supply chain compromises played a role in 30% of financial sector breaches, a significant increase from prior years. Vulnerable file transfer solutions, managed service platforms, and APIs served as common entry points. A breach at a shared third-party provider exposed customer data at major U.S. banks, including JPMorgan Chase, Citigroup, and Morgan Stanley, prompting regulatory scrutiny. Cryptocurrency exchange Bybit suffered a $1.5 billion theft after attackers exploited weaknesses in third-party wallet infrastructure. Ransomware Shifts to Data Exfiltration Ransomware impacted 12.8% of B2B financial organizations, with attackers prioritizing data exfiltration over encryption. Variants like Akira, Datacarry, and BlackLock targeted European institutions, while U.S. attacks increasingly focused on stealing sensitive data to trigger regulatory disclosures and investigations even when systems remained operational. Hacktivists and State Actors Intensify Pressure Hacktivist groups, including NoName057(16) and DarkStorm Team, launched DDoS campaigns against banks, particularly during elections and periods of geopolitical tension. State-aligned advanced persistent threat (APT) actors continued targeting financial institutions for intelligence gathering, exploiting zero-day vulnerabilities and maintaining long-term access. Geopolitical instability sustained elevated levels of disruptive activity throughout the year.
INCIDENT DETAILS -
TYPE
data_breachransomwareDDoSsupply_chain_compromise
MOTIVATION
financial_gainfraudintelligence_gatheringdisruptiongeopolitical
IMPACT
Financial Loss: $5.56 million (average per incident)personal_data (54%)internal_organizational_data (35%)credentials (22%)banksinsurerspayment_processorscryptocurrency_exchangesthird-party_providersfraudregulatory_disclosurespersistent_network_accessIdentity Theft Risk: highPayment Information Risk: high
DATA BREACH
personal_datainternal_organizational_datacredentialsSensitivity Of Data: highData Exfiltration: yesPersonally Identifiable Information: yes
FEBRUARY 2022
828Before Incident
Cyber Attack
01 Feb 2022Citi
Citi

Large-Scale Phishing Campaign Targeting Citibank Customers

818After Incident
CRITICAL-10
CIT0362322
The customers of Citibank are being targeted in a large-scale phishing campaign. The campaign features CitiBank logos and requestes the recipients to disclose sensitive personal details to lift alleged account holds. The customers are diverted to a website that looks exactly same as citybank portal and any credentials entered there would be compromised and can be misused.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Sensitive Personal Details, CredentialsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information, CredentialsSensitivity Of Data: HighPersonally Identifiable Information: Yes
MARCH 2013
832Before Incident
Breach
28 Mar 2013Citi
Citi

Citi Data Breach

799After Incident
LOW-33
CIT548072625
The California Office of the Attorney General reported a data breach involving Citi on March 28, 2013. The breach involved the accidental exposure of personally identifiable information due to an imperfect process used during a bankruptcy proceeding. The specific number of affected individuals and types of information compromised are unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personally Identifiable Information
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Citi ?
?
What was Citi's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Citi's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Citi's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Citi's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Citi's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Citi's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Citi's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Citi's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Citi's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Citi's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Citi's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Citi's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Citi ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Citi's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?