CybelAngel A.I CyberSecurity Scoring
CybelAngel
Company Information
Website:https://www.cybelangel.com
Employees number:153
Number of followers:51,427
NAICS:541514
Industry Type:Computer and Network Security
Homepage:cybelangel.com
CybelAngel Risk Score (AI oriented)
Between 650 and 699
CybelAngelComputer and Network Security
Updated:
21/04/2026
21/04/2026
661/1000
Weak
B
CybelAngel Global Score (TPRM)
xxxx
CybelAngelComputer and Network Security
Score locked

CybelAngelWeak
Current Score
661B (WEAK)
01000
2 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
671
SEPTEMBER 2026
670
AUGUST 2026
668
JULY 2026
667
JUNE 2026
665
MAY 2026
662
APRIL 2026
681
Cyber Attack
16 Apr 2026 • CybelAngel
LiteLLM: Vect formalizes BreachForums and TeamPCP alliance to push model for industrialized ransomware, scale RaaS operations
Vect Ransomware Group Forges Unprecedented Cybercrime Alliance to Scale Attacks
660
CRITICAL-21
CYB1776775372
Vect Ransomware Group Forges Unprecedented Cybercrime Alliance to Scale Attacks
A new report from Dataminr reveals that the ransomware group Vect has formalized a partnership with BreachForums and the hacking collective TeamPCP, creating an industrialized model for ransomware-as-a-service (RaaS) operations. This collaboration lowers the barrier to entry for cybercriminals, incentivizes affiliate-driven attacks, and leverages compromised supply chain credentials to maximize impact.
Since emerging in December 2025, Vect has rapidly evolved, establishing a multi-tier affiliate program, deploying TOR-based infrastructure, and refining double-extortion tactics stealing data before encryption to pressure victims into paying. The group’s operational maturity is evident in its use of purpose-built C++ ransomware (unlike many RaaS variants derived from leaked code), Monero payments, and TOX-based communications, suggesting ties to experienced Russian-speaking operators.
The partnership with BreachForums a cybercrime marketplace with 300,000 registered users marks a shift in ransomware distribution. Unlike traditional selective recruitment, Vect is publicly mobilizing the entire forum as a distribution network, enabling mass affiliate enrollment. Meanwhile, TeamPCP provides high-value access by compromising open-source security tools (including LiteLLM, Trivy, and Telnyx SDK) embedded in enterprise CI/CD pipelines, granting attackers deep system access.
Confirmed victims include Guesty (700 GB of exfiltrated data), Indian manufacturer USHA International Limited (employee records and SAP databases exposed), and S&P Global (unconfirmed listing). Vect’s ransomware targets Windows, Linux, and VMware ESXi, using ChaCha20-Poly1305 encryption, intermittent file scrambling, and defense evasion techniques such as manipulating Windows Safe Mode and terminating security processes to evade detection.
The alliance represents an unprecedented scale in ransomware industrialization, combining supply chain-sourced access, mass affiliate mobilization, and forum-integrated infrastructure in a single model. Organizations that incorporated affected tools in March 2026 are advised to rotate credentials immediately, audit CI/CD pipelines, and enforce SMB signing, WinRM restrictions, and TOR blocking to mitigate risks. Vect’s leak site remains active, with early detection of exposure providing a critical window for response.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
679
FEBRUARY 2026
679
JANUARY 2026
677
DECEMBER 2025
676
NOVEMBER 2025
674
JUNE 2024
752
Ransomware
16 Jun 2024 • CybelAngel
Qilin, CL0P, Salesforce, Sinobi and Play: Ransomware and Supply Chain Attacks Set Records in 2025
Ransomware and Supply Chain Attacks Surge in 2025
642
CRITICAL-110
QILCYBSALHALPLA1768955694
Ransomware and Supply Chain Attacks Hit Record Highs in 2025, Signaling Escalating Threats
2025 marked a sharp escalation in cyber threats, with ransomware and supply chain attacks reaching unprecedented levels, according to a new report from threat intelligence firm Cyble. The year saw 6,604 ransomware attacks a 52% increase over 2024 with December alone recording 731 incidents, the second-highest monthly total of the year. Meanwhile, supply chain attacks surged by 93%, rising from 154 in 2024 to 297 in 2025, as threat actors increasingly exploited third-party vulnerabilities to maximize impact.
### Ransomware Groups Adapt and Expand
Ransomware operations remained decentralized and resilient, with affiliates quickly regrouping under new leaders following law enforcement disruptions. Qilin emerged as the dominant group in 2025, claiming 17% of all ransomware victims after RansomHub’s decline likely due to sabotage by rival group Dragonforce. Other top players included Akira, CL0P, Play, and the newcomer Sinobi, with only Akira and Play maintaining their positions from 2024.
Cyble documented 57 new ransomware groups, 27 extortion groups, and over 350 new ransomware strains in 2025, many derived from MedusaLocker, Chaos, and Makop families. Among the most aggressive new groups, Devman, Sinobi, Warlock, and Gunra disproportionately targeted critical infrastructure, particularly in government, law enforcement, energy, and utilities.
### Supply Chain Attacks Evolve in Sophistication
Supply chain attacks not only doubled but also grew in complexity, moving beyond traditional software package poisoning to exploit cloud integrations, SaaS trust relationships, and vendor distribution pipelines. Attackers increasingly abused upstream services such as identity providers and package registries to compromise downstream environments at scale.
A notable example involved attacks on Salesforce via third-party integrations, where threat actors weaponized OAuth-based trust relationships after compromising third-party tokens. Every industry tracked by Cyble was affected, but IT and technology sectors bore the brunt, given their potential to amplify attacks across customer networks.
### Geographic and Industry Targeting
The U.S. remained the most targeted nation, accounting for 55% of all ransomware attacks, followed by Canada, Germany, the UK, Italy, and France. By industry, construction, professional services, and manufacturing were the hardest hit, with healthcare and IT also facing significant threats.
As 2026 begins, the trends suggest no immediate slowdown, with ransomware and supply chain attacks continuing to evolve in both scale and sophistication.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CybelAngel ??
What was CybelAngel's A.I Rankiteo Cyber Score in September 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in August 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in July 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in June 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in May 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in April 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in March 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in February 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in January 2026 ??
What was CybelAngel's A.I Rankiteo Cyber Score in December 2025 ??
What was CybelAngel's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on CybelAngel's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CybelAngel ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CybelAngel's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?