Company Details
consumers-union
114
1,295
511
consumerreports.org
0
CON_2853070
In-progress

Consumers Union Company CyberSecurity Posture
consumerreports.orgConsumers Union (CU) is an expert, independent, nonprofit organization whose mission is to work for a fair, just, and safe marketplace for all consumers and to empower consumers to protect themselves. To maintain its independence and impartiality, CU accepts no outside advertising and no free samples and employs several hundred mystery shoppers and technical experts to buy and test the products it evaluates. CU publishes Consumer Reports, one of the top-ten-circulation magazines in the country, and ConsumerReports.org, which has the most subscribers of any Web site of its kind, in addition to two newsletters, Consumer Reports on Health and Consumer Reports Money Adviser.
Company Details
consumers-union
114
1,295
511
consumerreports.org
0
CON_2853070
In-progress
Between 750 and 799

Consumers Union Global Score (TPRM)XXXX

Description: The Maine Office of the Attorney General reported a data breach involving Consumer Reports on September 28, 2023, which occurred on May 29, 2023. The incident involved unauthorized access to Pension Benefit Information, LLC’s MOVEit Transfer software, affecting 560 individuals, including social security numbers that were compromised. Notification letters to affected individuals were expected to be provided starting August 18, 2023.


No incidents recorded for Consumers Union in 2025.
No incidents recorded for Consumers Union in 2025.
No incidents recorded for Consumers Union in 2025.
Consumers Union cyber incidents detection timeline including parent company and subsidiaries

Consumers Union (CU) is an expert, independent, nonprofit organization whose mission is to work for a fair, just, and safe marketplace for all consumers and to empower consumers to protect themselves. To maintain its independence and impartiality, CU accepts no outside advertising and no free samples and employs several hundred mystery shoppers and technical experts to buy and test the products it evaluates. CU publishes Consumer Reports, one of the top-ten-circulation magazines in the country, and ConsumerReports.org, which has the most subscribers of any Web site of its kind, in addition to two newsletters, Consumer Reports on Health and Consumer Reports Money Adviser.

Thousands of employees, one goal: empower people today to build a better future for the next generation. How do we do that? By disrupting industries. By treating our employees as our most important resource. By improving the quality of life in our communities and by protecting our planet. We crea

A globo é feita de gente que quer fazer diferente, fazer junto, fazer o futuro. Gente espalhada por todo o país (e mundo!) trabalhando com conteúdo, notícias, negócios, tecnologia e brasilidade de sobra. Canais na TV aberta e por assinatura, produtos digitais como globoplay, Cartola, g1, ge, gsho
.png)
Minister of Public Security General Luong Tam Quang met with Jens Rubbert, Chairman of the EU–ASEAN Business Council (EU–ABC),...
Guardio raises $80m to scale its consumer cybersecurity platform. Discover the latest FinTech funding news today.
The White & Case Tech Newsflash provides updates on the latest issues and trends in technology and the law. We deliver fresh perspectives across all of our...
In 2019, the US data privacy framework changed significantly with the emergence of the California Consumer Privacy Act which created a...
To help credit unions of all sizes, we developed a number of resource centers that provide critical regulatory and supervisory information...
Cybersecurity researcher Jeremiah Fowler has once again highlighted the fragility of data security, uncovering an unprotected 378 GB...
California finalizes CCPA/CPRA rules on ADMT, risk assessments, and cybersecurity audits—compliance starts Jan 2027.
Unlock the potential of open banking solutions with Mastercard Open Finance, paving the way for seamless financial innovation.
NCUA resources that can be referenced when evaluating or performing due diligence on third-party vendors that provide artificial...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Consumers Union is http://www.consumerreports.org.
According to Rankiteo, Consumers Union’s AI-generated cybersecurity score is 753, reflecting their Fair security posture.
According to Rankiteo, Consumers Union currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Consumers Union is not certified under SOC 2 Type 1.
According to Rankiteo, Consumers Union does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Consumers Union is not listed as GDPR compliant.
According to Rankiteo, Consumers Union does not currently maintain PCI DSS compliance.
According to Rankiteo, Consumers Union is not compliant with HIPAA regulations.
According to Rankiteo,Consumers Union is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Consumers Union operates primarily in the Book and Periodical Publishing industry.
Consumers Union employs approximately 114 people worldwide.
Consumers Union presently has no subsidiaries across any sectors.
Consumers Union’s official LinkedIn profile has approximately 1,295 followers.
Consumers Union is classified under the NAICS code 511, which corresponds to Publishing Industries (except Internet).
No, Consumers Union does not have a profile on Crunchbase.
Yes, Consumers Union maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/consumers-union.
As of November 28, 2025, Rankiteo reports that Consumers Union has experienced 1 cybersecurity incidents.
Consumers Union has an estimated 4,881 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notification letters to affected individuals expected to be provided starting august 18, 2023..
Title: Data Breach at Consumer Reports
Description: Unauthorized access to Pension Benefit Information, LLC’s MOVEit Transfer software, compromising social security numbers of 560 individuals.
Date Detected: 2023-09-28
Date Publicly Disclosed: 2023-09-28
Type: Data Breach
Attack Vector: Unauthorized Access
Vulnerability Exploited: MOVEit Transfer software
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Social security numbers
Systems Affected: MOVEit Transfer software
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Social Security Numbers.

Entity Name: Consumer Reports
Entity Type: Organization
Industry: Consumer Services
Customers Affected: 560

Communication Strategy: Notification letters to affected individuals expected to be provided starting August 18, 2023

Type of Data Compromised: Social Security Numbers
Number of Records Exposed: 560
Sensitivity of Data: High
Personally Identifiable Information: Social Security Numbers

Source: Maine Office of the Attorney General
Date Accessed: 2023-09-28
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2023-09-28.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notification letters to affected individuals expected to be provided starting August 18 and 2023.
Most Recent Incident Detected: The most recent incident detected was on 2023-09-28.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2023-09-28.
Most Significant Data Compromised: The most significant data compromised in an incident were Social Security Numbers and .
Most Significant System Affected: The most significant system affected in an incident was MOVEit Transfer software.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was Social Security Numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 560.0.
Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.