CRA A.I CyberSecurity Scoring
CRA
Company Information
Website:https://www.rockwellautomation.com/en-us/capabilities/industrial-cybersecurity.html
Employees number:None
Number of followers:4,121
NAICS:
Industry Type:Data Security Software Products
Homepage:rockwellautomation.com
CRA Risk Score (AI oriented)
Between 700 and 749
CRAData Security Software Products
Updated:
05/06/2026
05/06/2026
732/1000
Moderate
Ba
CRA Global Score (TPRM)
xxxx
CRAData Security Software Products
Score locked

CRAModerate
Current Score
732Ba (MODERATE)
01000
2 incidents
-13 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
733
JUNE 2026
732
MAY 2026
750
Cyber Attack
01 May 2026 • CRA
Rockwell Automation and U.S. gas stations: Over 900 US gas station tank gauge systems exposed to attacks
U.S. Government Warns of Widespread Attacks on Exposed Fuel and Chemical Tank Monitoring Systems
731
CRITICAL-19
U.SCYB1780676705
U.S. Government Warns of Widespread Attacks on Exposed Fuel and Chemical Tank Monitoring Systems
Over 900 automatic tank gauge (ATG) systems critical devices used to monitor fuel and chemical storage tanks in the U.S. have been found exposed online and are under active attack. ATGs automate inventory control, leak detection, and regulatory compliance across gas stations, industrial facilities, and other critical infrastructure sectors.
On Tuesday, the Cybersecurity and Infrastructure Security Agency (CISA), FBI, NSA, Department of Energy, and other federal agencies issued a joint advisory urging organizations to secure these internet-facing systems. Threat actors are exploiting vulnerabilities including hardcoded credentials, authentication bypasses, SQL injection, and command execution flaws to alter system settings, disable alerts, and risk leaks or equipment damage.
While the U.S. government has not attributed the attacks to a specific group, the advisory follows a May report by CNN linking Iranian hackers to breaches of ATG systems at multiple U.S. gas stations. In those incidents, attackers manipulated display readings without altering actual fuel levels, raising concerns about potential disruptions to safety functions like leak detection.
Security firm Shadowserver reported over 1,000 exposed ATG systems globally, with 909 located in the U.S. as of June 5. The agencies recommend restricting remote access, replacing default passwords, applying security updates, and implementing multi-factor authentication to mitigate risks.
The warning comes amid broader concerns over industrial control system (ICS) security, including a separate April advisory linking Iranian state-backed hackers to attacks on Rockwell Automation PLCs since March 2026, which caused financial and operational disruptions. Censys data revealed that 74.6% of exposed ICS hosts globally are in the U.S.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
APRIL 2026
750
MARCH 2026
757
Vulnerability
01 Mar 2026 • CRA
F5, Rockwell Automation, Fortinet and Cisco: March 2026 Cyber Threat Landscape Fueled by Ransomware, Breaches, and Access Markets
March 2026 Cyber Threat Landscape: Ransomware, Access Brokers, and Critical Vulnerabilities Drive Global Risks
750
CRITICAL-7
CRICYBF5LFOR1776854731
March 2026 Cyber Threat Landscape: Ransomware, Access Brokers, and Critical Vulnerabilities Drive Global Risks
The cybersecurity threat landscape in March 2026 saw heightened activity, with ransomware attacks, data breaches, and underground access markets shaping a volatile environment. According to Cyble Research & Intelligence Labs (CRIL), financially motivated cybercriminals intensified their operations, targeting industries reliant on uptime or handling sensitive data.
### Ransomware Surges, Dominated by Five Major Groups
Ransomware remained the leading attack vector, with 702 incidents recorded globally. Five threat groups Qilin, Akira, The Gentlemen, Dragonforce, and INC Ransom accounted for 56% of all activity, leveraging double-extortion tactics to maximize pressure on victims. The most affected sectors included:
- Construction
- Professional Services
- Manufacturing
- Healthcare
- Energy & Utilities
The U.S. was the primary target, influenced by geopolitical tensions, including those involving Iran.
### Compromised Access Market Expands
The sale of unauthorized network access surged, with 20 incidents tracked across cybercrime forums. Professional Services (25%) and Retail (20%) were the most targeted sectors. Three threat actors vexin, holyduxy, and algoyim dominated the market, facilitating ransomware, espionage, and financial fraud.
### Data Breaches Expose Massive Volumes of Sensitive Information
CRIL documented 54 significant data breaches, with notable incidents including:
- "nightly" claiming theft of 5TB of data from Hospitality Holdings, including biometric data and CCTV footage.
- XP95 advertising 3.8TB of South African government data for sale.
- A breach exposing 95,000 travel records, including passport and payment details.
### Critical Vulnerabilities Exploited at Scale
Attackers actively targeted flaws in CISA’s Known Exploited Vulnerabilities (KEV) catalog, including:
- CVE-2026-20131 (Cisco Secure Firewall Management Center)
- CVE-2025-53521 (F5 BIG-IP APM)
- CVE-2026-20963 (Microsoft SharePoint Server)
- CVE-2026-33017 (Langflow AI)
- CVE-2021-22681 (Rockwell Automation ICS)
Both zero-day exploits and unpatched legacy vulnerabilities were weaponized, highlighting persistent patch management gaps.
### Emerging Threats: AI, Supply Chain, and Geopolitical Risks
- AI-Driven Attacks: Threat actors used CyberStrikeAI, an open-source framework, to compromise 600+ Fortinet FortiGate devices across 55 countries.
- Supply Chain Risks: North Korean-linked actors distributed 26 malicious npm packages containing remote access trojans (RATs) via Pastebin and Vercel.
- Geopolitical Cyber Activity: Iran-linked operations are expected to escalate, with potential ransomware and hacktivist campaigns targeting Middle Eastern organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
757
JANUARY 2026
757
DECEMBER 2025
757
NOVEMBER 2025
757
OCTOBER 2025
757
SEPTEMBER 2025
757
AUGUST 2025
757
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CRA ??
What was CRA's A.I Rankiteo Cyber Score in June 2026 ??
What was CRA's A.I Rankiteo Cyber Score in May 2026 ??
What was CRA's A.I Rankiteo Cyber Score in April 2026 ??
What was CRA's A.I Rankiteo Cyber Score in March 2026 ??
What was CRA's A.I Rankiteo Cyber Score in February 2026 ??
What was CRA's A.I Rankiteo Cyber Score in January 2026 ??
What was CRA's A.I Rankiteo Cyber Score in December 2025 ??
What was CRA's A.I Rankiteo Cyber Score in November 2025 ??
What was CRA's A.I Rankiteo Cyber Score in October 2025 ??
What was CRA's A.I Rankiteo Cyber Score in September 2025 ??
What was CRA's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on CRA's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CRA ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CRA's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?