Badge
11,371 badges added since 01 January 2025
ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Council for Relationships is a nonprofit organization whose mission is to help people from all walks of life improve their important relationships by providing exemplary therapy, educating and training clinicians in the family systems approach, and advancing the mental health field through research. More than 70 therapists and psychiatrists provide counseling to individuals, couples, and families in-person at 10 offices and community-based locations in the greater Philadelphia area and online across PA & NJ. Additionally, more than 60 clinical interns per year participating in CFR’s clinician education programs provide counseling on a sliding fee scale. We are committed to providing quality counseling services to all in need, regardless of ability to pay.

Council for Relationships A.I CyberSecurity Scoring

CR

Company Details

Linkedin ID:

council-for-relationships

Employees number:

128

Number of followers:

1,445

NAICS:

62133

Industry Type:

Mental Health Care

Homepage:

councilforrelationships.org

IP Addresses:

0

Company ID:

COU_1842612

Scan Status:

In-progress

AI scoreCR Risk Score (AI oriented)

Between 600 and 649

https://images.rankiteo.com/companyimages/council-for-relationships.jpeg
CR Mental Health Care
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreCR Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/council-for-relationships.jpeg
CR Mental Health Care
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

CR Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsSupply Chain SourceIncident DetailsView
Council for RelationshipsBreach6036/2024NA
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: On June 12, 2024, the Vermont Office of the Attorney General reported a data breach involving the Council for Relationships (CFR). The incident was due to unauthorized access to a server containing personal information of current and former staff, including names, addresses, social security numbers, payroll information, and bank account details, although it is uncertain if any information was actually taken.

Council for RelationshipsBreach8544/2024NA
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The Maine Office of the Attorney General reported a data breach involving Council for Relationships, Inc. on June 12, 2024. The breach occurred on April 1, 2024, due to an external system breach (hacking), affecting a total of 27,377 individuals, with 4 residents specifically impacted. The breach involved the unauthorized access to personal information, potentially compromising the data of a significant number of individuals.

Council for Relationships
Breach
Severity: 60
Impact: 3
Seen: 6/2024
Blog:
Supply Chain Source: NA
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: On June 12, 2024, the Vermont Office of the Attorney General reported a data breach involving the Council for Relationships (CFR). The incident was due to unauthorized access to a server containing personal information of current and former staff, including names, addresses, social security numbers, payroll information, and bank account details, although it is uncertain if any information was actually taken.

Council for Relationships, Inc.
Breach
Severity: 85
Impact: 4
Seen: 4/2024
Blog:
Supply Chain Source: NA
Rankiteo Explanation
Attack with significant impact with customers data leaks

Description: The Maine Office of the Attorney General reported a data breach involving Council for Relationships, Inc. on June 12, 2024. The breach occurred on April 1, 2024, due to an external system breach (hacking), affecting a total of 27,377 individuals, with 4 residents specifically impacted. The breach involved the unauthorized access to personal information, potentially compromising the data of a significant number of individuals.

Ailogo

CR Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for CR

Incidents vs Mental Health Care Industry Average (This Year)

No incidents recorded for Council for Relationships in 2026.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Council for Relationships in 2026.

Incident Types CR vs Mental Health Care Industry Avg (This Year)

No incidents recorded for Council for Relationships in 2026.

Incident History — CR (X = Date, Y = Severity)

CR cyber incidents detection timeline including parent company and subsidiaries

CR Company Subsidiaries

SubsidiaryImage

Council for Relationships is a nonprofit organization whose mission is to help people from all walks of life improve their important relationships by providing exemplary therapy, educating and training clinicians in the family systems approach, and advancing the mental health field through research. More than 70 therapists and psychiatrists provide counseling to individuals, couples, and families in-person at 10 offices and community-based locations in the greater Philadelphia area and online across PA & NJ. Additionally, more than 60 clinical interns per year participating in CFR’s clinician education programs provide counseling on a sliding fee scale. We are committed to providing quality counseling services to all in need, regardless of ability to pay.

Loading...
similarCompanies

CR Similar Companies

Paragon Behavioral Health Services, LLC

Paragon Behavioral Health Services, LLC is on a mission to forge a path that cultivates and enhances the lives of our communities through attentive and dedicative behavioral health care. We recognize the uniqueness of each participant and strive to promote feelings of dignity and a sense of self-wor

In Tune Counseling and Coaching

In Tune Counseling and Coaching emphasizes the client – therapist relationship. We offer a safe and comfortable setting that promotes respect, growth and development. Each individual is treated uniquely with regard to personal characteristics and interpersonal skills. Our therapists are invested in

Mindful Transitions, LLC

Mindful Transitions, LLC provides Clinical Social Work services to seniors on-site at Independent and Assisted Living residences. We assist the client and family in adjusting to the need for placement, mood changes, adjusting to new surroundings, coping with lifestyle changes, cognitive and physical

New Mexico Solutions (NMS)

New Mexico Solutions is a nonprofit organization offering comprehensive community-based services in the Albuquerque area. Since 1999, New Mexico Solutions has provided effective, ethical and responsive services to the community. New Mexico Solutions provides services under the philosophy that client

Integrate Brain Health

Integrate Brain Health (IBH) is a combination of two subsidiaries: Integrated Neuroscience Services and Integrated Neuropsychological Services. Integrated Neuroscience Services provides comprehensive consultation services to the neurofeedback clinician. Drs. Coben and Stevens utilize information t

COMMUNITY THERAPEUTIC SERVICES LIMITED

COMMUNITY THERAPEUTIC SERVICES LIMITED is a Registered Social Care Provider for People with Learning Disabilities, Autism and Mental Health Needs. The main office is located in 81 HIGH STREET WORLE, WESTON-SUPER-MARE, NORTH SOMERSET, United Kingdom. We provide a 'different level' of residential and

SHEN-PACO INDUSTRIES, INC.

Shen-Paco Industries, Inc. was founded in 1974 as a non-profit community based organization providing day support and employment services to adults with disabilities. Shen- Paco Industries started out small, serving less than 10 individuals in a small building located in New Market. Today the num

Apex Recovery

Apex Recovery offers all-inclusive assistance for anyone seeking to recover from drug addiction or alcohol abuse. We offer services specific to your individual needs as well as comprehensive guidance. We also offer aftercare services to ensure our clients get the care they need to have lasting recov

East Bay Relationship Center

Providing couples and marriage counseling, family therapy, teen counseling and individual therapy in the Tri-Valley and East Bay area through our offices in Pleasanton & Alameda. About Us We believe that at the core, much of our human distress is caused by relationship "malfunction". All of us

newsone

CR CyberSecurity News

November 10, 2025 08:00 AM
Poland’s policy on China: From partnership to skepticism

This is the eighth chapter of the report “Is Europe waking up to the China challenge? How geopolitics are reshaping EU and transatlantic...

October 23, 2025 07:00 AM
With Petro and Trump at odds, what’s next for the US-Colombia relationship?

Amid the current US-Colombia tensions, both countries should remind themselves of how important this relationship is for their shared goals.

May 20, 2025 07:00 AM
Unpacking Russia's cyber nesting doll

The latest report in the Atlantic Council's Russia Tomorrow series explores Russia's wartime cyber operations and broader cyber web.

February 19, 2025 08:00 AM
Why India and Armenia are now taking their relationship to new heights

The growing military and diplomatic cooperation between New Delhi and Yerevan benefits both beyond immediate defense concerns.

October 18, 2024 07:00 AM
Capture the (red) flag: An inside look into China’s hacking contest ecosystem

China has built the world's most comprehensive ecosystem for capture-the-flag (CTF) competitions—the predominant form of hacking competitions...

August 29, 2024 07:00 AM
Facing the North Korean Cyber Threat: United States-South Korea Coordination in Cyberspace

South Korea is sounding the alarm on North Korean cybersecurity threats. In line with his “Global Pivotal State” (GPS) agenda,...

May 31, 2024 07:00 AM
How Myanmar Became a Global Center for Cyber Scams

Organized crime groups in Southeast Asia have seized on Myanmar's instability amid civil war to establish a string of scam centers engaged in global online...

February 05, 2024 08:00 AM
Get Microsoft’s tips for partnering with your works councils

See how Microsoft collaborates with European works councils during product rollouts to ensure compliance and maintain healthy labor...

April 20, 2023 07:00 AM
The US-EU Trade and Technology Council: Assessing the record on data and technology issues

The role of the TTC is not to address direct regulatory controversies but to seek “success stories” and set the stage for future collaboration.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

CR CyberSecurity History Information

Official Website of Council for Relationships

The official website of Council for Relationships is http://www.councilforrelationships.org.

Council for Relationships’s AI-Generated Cybersecurity Score

According to Rankiteo, Council for Relationships’s AI-generated cybersecurity score is 648, reflecting their Poor security posture.

How many security badges does Council for Relationships’ have ?

According to Rankiteo, Council for Relationships currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Has Council for Relationships been affected by any supply chain cyber incidents ?

According to Rankiteo, Council for Relationships has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.

Does Council for Relationships have SOC 2 Type 1 certification ?

According to Rankiteo, Council for Relationships is not certified under SOC 2 Type 1.

Does Council for Relationships have SOC 2 Type 2 certification ?

According to Rankiteo, Council for Relationships does not hold a SOC 2 Type 2 certification.

Does Council for Relationships comply with GDPR ?

According to Rankiteo, Council for Relationships is not listed as GDPR compliant.

Does Council for Relationships have PCI DSS certification ?

According to Rankiteo, Council for Relationships does not currently maintain PCI DSS compliance.

Does Council for Relationships comply with HIPAA ?

According to Rankiteo, Council for Relationships is not compliant with HIPAA regulations.

Does Council for Relationships have ISO 27001 certification ?

According to Rankiteo,Council for Relationships is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Council for Relationships

Council for Relationships operates primarily in the Mental Health Care industry.

Number of Employees at Council for Relationships

Council for Relationships employs approximately 128 people worldwide.

Subsidiaries Owned by Council for Relationships

Council for Relationships presently has no subsidiaries across any sectors.

Council for Relationships’s LinkedIn Followers

Council for Relationships’s official LinkedIn profile has approximately 1,445 followers.

NAICS Classification of Council for Relationships

Council for Relationships is classified under the NAICS code 62133, which corresponds to Offices of Mental Health Practitioners (except Physicians).

Council for Relationships’s Presence on Crunchbase

No, Council for Relationships does not have a profile on Crunchbase.

Council for Relationships’s Presence on LinkedIn

Yes, Council for Relationships maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/council-for-relationships.

Cybersecurity Incidents Involving Council for Relationships

As of January 22, 2026, Rankiteo reports that Council for Relationships has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Council for Relationships has an estimated 5,278 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Council for Relationships ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

Incident Details

Can you provide details on each incident ?

Incident : Data Breach

Title: Data Breach at Council for Relationships, Inc.

Description: The Maine Office of the Attorney General reported a data breach involving Council for Relationships, Inc. on June 12, 2024. The breach occurred on April 1, 2024, due to an external system breach (hacking), affecting a total of 27,377 individuals, with 4 residents specifically impacted.

Date Detected: 2024-04-01

Date Publicly Disclosed: 2024-06-12

Type: Data Breach

Attack Vector: External System Breach (Hacking)

Incident : Data Breach

Title: Data Breach at Council for Relationships

Description: Unauthorized access to a server containing personal information of current and former staff, including names, addresses, social security numbers, payroll information, and bank account details.

Date Detected: 2024-06-12

Date Publicly Disclosed: 2024-06-12

Type: Data Breach

Attack Vector: Unauthorized Access

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Data Breach COU604072725

Data Compromised: Names, Addresses, Social security numbers, Payroll information, Bank account details

Systems Affected: server

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information, Financial Information and .

Which entities were affected by each incident ?

Incident : Data Breach COU528072725

Entity Name: Council for Relationships, Inc.

Entity Type: Organization

Customers Affected: 27377

Incident : Data Breach COU604072725

Entity Name: Council for Relationships

Entity Type: Non-profit Organization

Industry: Health and Social Services

Data Breach Information

What type of data was compromised in each breach ?

Incident : Data Breach COU528072725

Number of Records Exposed: 27377

Incident : Data Breach COU604072725

Type of Data Compromised: Personal information, Financial information

Sensitivity of Data: High

Personally Identifiable Information: namesaddressessocial security numbers

References

Where can I find more information about each incident ?

Incident : Data Breach COU528072725

Source: Maine Office of the Attorney General

Date Accessed: 2024-06-12

Incident : Data Breach COU604072725

Source: Vermont Office of the Attorney General

Date Accessed: 2024-06-12

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2024-06-12, and Source: Vermont Office of the Attorney GeneralDate Accessed: 2024-06-12.

Additional Questions

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2024-04-01.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-06-12.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were names, addresses, social security numbers, payroll information, bank account details and .

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was server.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were addresses, names, bank account details, social security numbers and payroll information.

What was the number of records exposed in the most significant breach ?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 350.0.

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Vermont Office of the Attorney General and Maine Office of the Attorney General.

cve

Latest Global CVEs (Not Company-Specific)

Description

Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlReader` component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. This allowed an attacker who controls a host listed in `backend.reading.allow` to redirect requests to internal or sensitive URLs that are not on the allowlist, bypassing the URL allowlist security control. This is a Server-Side Request Forgery (SSRF) vulnerability that could allow access to internal resources, but it does not allow attackers to include additional request headers. This vulnerability is fixed in `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, and 0.15.0. Users should upgrade to this version or later. Some workarounds are available. Restrict `backend.reading.allow` to only trusted hosts that you control and that do not issue redirects, ensure allowed hosts do not have open redirect vulnerabilities, and/or use network-level controls to block access from Backstage to sensitive internal endpoints.

Risk Information
cvss3
Base: 3.5
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Description

Backstage is an open framework for building developer portals, and @backstage/cli-common provides config loading functionality used by the backend and command line interface of Backstage. Prior to version 0.1.17, the `resolveSafeChildPath` utility function in `@backstage/backend-plugin-api`, which is used to prevent path traversal attacks, failed to properly validate symlink chains and dangling symlinks. An attacker could bypass the path validation via symlink chains (creating `link1 → link2 → /outside` where intermediate symlinks eventually resolve outside the allowed directory) and dangling symlinks (creating symlinks pointing to non-existent paths outside the base directory, which would later be created during file operations). This function is used by Scaffolder actions and other backend components to ensure file operations stay within designated directories. This vulnerability is fixed in `@backstage/backend-plugin-api` version 0.1.17. Users should upgrade to this version or later. Some workarounds are available. Run Backstage in a containerized environment with limited filesystem access and/or restrict template creation to trusted users.

Risk Information
cvss3
Base: 6.3
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Description

Backstage is an open framework for building developer portals. Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to read arbitrary files via the `debug:log` action by creating a symlink pointing to sensitive files (e.g., `/etc/passwd`, configuration files, secrets); delete arbitrary files via the `fs:delete` action by creating symlinks pointing outside the workspace, and write files outside the workspace via archive extraction (tar/zip) containing malicious symlinks. This affects any Backstage deployment where users can create or execute Scaffolder templates. This vulnerability is fixed in `@backstage/backend-defaults` versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0; `@backstage/plugin-scaffolder-backend` versions 2.2.2, 3.0.2, and 3.1.1; and `@backstage/plugin-scaffolder-node` versions 0.11.2 and 0.12.3. Users should upgrade to these versions or later. Some workarounds are available. Follow the recommendation in the Backstage Threat Model to limit access to creating and updating templates, restrict who can create and execute Scaffolder templates using the permissions framework, audit existing templates for symlink usage, and/or run Backstage in a containerized environment with limited filesystem access.

Risk Information
cvss3
Base: 7.1
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L
Description

FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-channel vulnerability in verify_key(). The method applied a random delay only on verification failures, allowing an attacker to statistically distinguish valid from invalid API keys by measuring response latencies. With enough repeated requests, an adversary could infer whether a key_id corresponds to a valid key, potentially accelerating brute-force or enumeration attacks. All users relying on verify_key() for API key authentication prior to the fix are affected. Users should upgrade to version 1.1.0 to receive a patch. The patch applies a uniform random delay (min_delay to max_delay) to all responses regardless of outcome, eliminating the timing correlation. Some workarounds are available. Add an application-level fixed delay or random jitter to all authentication responses (success and failure) before the fix is applied and/or use rate limiting to reduce the feasibility of statistical timing attacks.

Risk Information
cvss3
Base: 3.7
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description

The Flux Operator is a Kubernetes CRD controller that manages the lifecycle of CNCF Flux CD and the ControlPlane enterprise distribution. Starting in version 0.36.0 and prior to version 0.40.0, a privilege escalation vulnerability exists in the Flux Operator Web UI authentication code that allows an attacker to bypass Kubernetes RBAC impersonation and execute API requests with the operator's service account privileges. In order to be vulnerable, cluster admins must configure the Flux Operator with an OIDC provider that issues tokens lacking the expected claims (e.g., `email`, `groups`), or configure custom CEL expressions that can evaluate to empty values. After OIDC token claims are processed through CEL expressions, there is no validation that the resulting `username` and `groups` values are non-empty. When both values are empty, the Kubernetes client-go library does not add impersonation headers to API requests, causing them to be executed with the flux-operator service account's credentials instead of the authenticated user's limited permissions. This can result in privilege escalation, data exposure, and/or information disclosure. Version 0.40.0 patches the issue.

Risk Information
cvss3
Base: 5.3
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=council-for-relationships' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge