CA A.I CyberSecurity Scoring
CA
Company Information
Website:https://ehxr.fa.us2.oraclecloud.com/hcmUI/CandidateExperience/en/sites/City-of-Atlanta-Careers/requisitions?mode=location
Employees number:5,156
Number of followers:65,886
NAICS:92
Industry Type:Government Administration
Homepage:oraclecloud.com
CA Risk Score (AI oriented)
Between 700 and 749
CAGovernment Administration
Updated:
31/03/2026
31/03/2026
724/1000
Moderate
Ba
CA Global Score (TPRM)
xxxx
CAGovernment Administration
Score locked

CAModerate
Current Score
724Ba (MODERATE)
01000
4 incidents
-133 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
556
Breach
11 Aug 2026 • CA
Wesco: Wesco Cloud CRM Data Breach: ExfilSquad Data Theft and Supply Chain Risks Analyzed
Wesco Investigates Data Breach After ExfilSquad Claims Theft of 2.6 Million Records
463
CRITICAL-93
WES1786569977
Wesco Investigates Data Breach After ExfilSquad Claims Theft of 2.6 Million Records
On August 11, 2026, global supply chain and distribution company Wesco confirmed it is investigating a cybersecurity incident following claims by the data extortion group ExfilSquad that it stole and leaked 2.6 million records from the company’s cloud CRM environment. Wesco stated that no business disruption occurred, no ransomware or malware was detected on internal systems, and sensitive customer or employee data including payment card or financial account information was not believed to be at risk. However, ExfilSquad’s leak allegedly includes personally identifiable information (PII), account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access-related details, raising concerns about downstream phishing, business email compromise (BEC), and fraud risks for Wesco’s partners and customers.
The attack appears to have targeted Wesco’s cloud CRM system, likely based on Microsoft Dynamics 365, with potential exploitation of misconfigured Microsoft Power Pages data tables. ExfilSquad, known for extortion-only operations, typically gains initial access via compromised credentials or exposed cloud applications, then uses legitimate tools like 7z, rclone, and PowerShell to stage and exfiltrate data to attacker-controlled cloud storage (e.g., MEGA, pCloud). The group’s tactics align with the MITRE ATT&CK framework, including valid account abuse (T1078), cloud service discovery (T1526), and exfiltration over web services (T1567.002). No malware was detected, and all activities leveraged dual-use administrative tools, complicating detection.
ExfilSquad has a history of targeting supply chain, education, and public sector organizations, with prior breaches at Analog Devices, the UK’s Police National Legal Database, and Newcastle University. The stolen data reportedly containing customer lists, shipment details, and project pricing poses significant third-party risk, as it can be weaponized for spear phishing and invoice fraud across Wesco’s ecosystem.
Key Timeline:
- August 7, 2026: ExfilSquad begins distributing stolen data via torrents.
- August 11, 2026: Wesco confirms the incident after ExfilSquad publishes the leaked data following failed ransom negotiations.
As of the report date, no technical indicators of compromise (IOCs) beyond a single domain (mallory[.]ai) have been publicly disclosed, and no regulatory filings or law enforcement advisories have been referenced. The incident underscores the growing threat of data theft extortion targeting cloud environments, particularly in sectors handling sensitive partner data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
727
Ransomware
30 Jul 2026 • CA
Allstate Corporation: Allstate Data Breach: Edelson Lechtzin LLP Launches Investigation Into Exposure of Personal Information
Allstate Data Breach Under Investigation After ExfilSquad Ransomware Attack
554
CRITICAL-173
ALL1785522998
Allstate Data Breach Under Investigation After ExfilSquad Ransomware Attack
On July 26, 2026, Allstate Corporation confirmed a data breach after the ransomware group ExfilSquad claimed responsibility for a cyberattack, alleging the theft of over 657,000 records and 15.1 GB of sensitive data. The incident was detected following reports from cybersecurity platforms, prompting an investigation by the national class action law firm Edelson Lechtzin LLP.
The breach may have exposed personal information, putting affected individuals at heightened risk of identity theft and fraud. Allstate, a major U.S. provider of auto, home, and life insurance, has begun notifying impacted customers.
Edelson Lechtzin LLP is evaluating potential legal action on behalf of those whose data was compromised, offering free case assessments to determine eligibility for claims. The firm specializes in data breach litigation, among other class action matters.
The full scope of the breach and its long-term impact remain under review.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
726
MAY 2026
725
APRIL 2026
725
MARCH 2026
724
FEBRUARY 2026
723
JANUARY 2026
722
DECEMBER 2025
721
NOVEMBER 2025
720
OCTOBER 2025
719
SEPTEMBER 2025
718
APRIL 2018
655
Ransomware
01 Apr 2018 • CA
City of Atlanta
Ransomware Attack on the City of Atlanta
414
CRITICAL-241
CIT152817522
A ransomware attack destabilized municipal operations of the city of Atlanta after which the city had to spend more than $2.6 million on emergency efforts.
The attackers targeted five of the city's 13 local government departments and disrupted many day-to-day functions, including the Police Department records system, infrastructure maintenance requests, and the judicial system, and also hindered revenue collection and water bill payments.
The attackers apparently demanded a ransom of roughly $50,000 worth of bitcoin to restore its systems.
However, it is not clear whether the city decided to pay the ransom or not.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
MARCH 2018
773
Ransomware
01 Mar 2018 • CA
City of Atlanta
Ransomware Attack on City of Atlanta
653
HIGH-120
CIT1129622
The city of Atlanta's government has apparently become the victim of a ransomware attack.
Its official Twitter account announced that the city government "is currently experiencing outages on various customer-facing applications, including some that customers may use to pay bills or access court-related information."
A city employee sent the station a screenshot of a ransomware message demanding a payment of $6,800 to unlock each computer or $51,000 to provide all the keys for affected systems.
An internal email shared with WXIA said that the internal systems affected include the city's payroll application.
Based on the screenshot, one security expert WXIA showed it to said that it resembled the message from a variant of Samsam, a family of ransomware that struck a number of hospitals two years ago.
Those malware attacks exploited a Java de-serialization vulnerability in Java-based application servers.
But it's not clear that the Atlanta outbreak started in the same way.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CA ??
What was CA's A.I Rankiteo Cyber Score in July 2026 ??
What was CA's A.I Rankiteo Cyber Score in June 2026 ??
What was CA's A.I Rankiteo Cyber Score in May 2026 ??
What was CA's A.I Rankiteo Cyber Score in April 2026 ??
What was CA's A.I Rankiteo Cyber Score in March 2026 ??
What was CA's A.I Rankiteo Cyber Score in February 2026 ??
What was CA's A.I Rankiteo Cyber Score in January 2026 ??
What was CA's A.I Rankiteo Cyber Score in December 2025 ??
What was CA's A.I Rankiteo Cyber Score in November 2025 ??
What was CA's A.I Rankiteo Cyber Score in October 2025 ??
What was CA's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on CA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?