Company Details
deutscher-fussball-bund
1,403
48,962
7112
dfb.de
0
DFB_2678665
In-progress

DFB Company CyberSecurity Posture
dfb.deIn 1981 the DFB GmbH was founded as an independent and 100% subsidiary of the German Football Association for marketing of products and licenses. With the integration of DFB-Medien GmbH & Co. KG in 2017, all IT topics were also bundled in the DFB GmbH. The company's current range of services includes marketing & sales, IT & digital services and the event management of major events. The Managing Directors are Dr. Frank Biendara and Denni Strich.
Company Details
deutscher-fussball-bund
1,403
48,962
7112
dfb.de
0
DFB_2678665
In-progress
Between 700 and 749

DFB Global Score (TPRM)XXXX

Description: Members of the French Football Federation, the country's football governing body catering to over 2.2 million individuals, had their information exposed following the breach of administrative management software used by football clubs, according to The Register Unauthorized system account associated with a breached account allowed the theft of individuals' names, gender, birthdates, birthplaces, nationalities, phone numbers, email addresses, postal addresses, and license numbers, but not their national identity numbers or banking details, said the FFF. More details on the number of impacted members were not provided but the FFF emphasized that immediate action was taken to deactivate the compromised account and implement password resets for all users. Additional software security measures have also been implemented in the wake of the intrusion, noted the FFF, which has already notified ANSSI and CNIL, the country's cybersecurity agency and data protection watchdog, respectively. Affected members have also been warned about suspicious messages claiming to be from the FFF after the attack.


DFB has 16.28% more incidents than the average of same-industry companies with at least one recorded incident.
DFB has 56.25% more incidents than the average of all companies with at least one recorded incident.
DFB reported 1 incidents this year: 0 cyber attacks, 0 ransomware, 0 vulnerabilities, 1 data breaches, compared to industry peers with at least 1 incident.
DFB cyber incidents detection timeline including parent company and subsidiaries

In 1981 the DFB GmbH was founded as an independent and 100% subsidiary of the German Football Association for marketing of products and licenses. With the integration of DFB-Medien GmbH & Co. KG in 2017, all IT topics were also bundled in the DFB GmbH. The company's current range of services includes marketing & sales, IT & digital services and the event management of major events. The Managing Directors are Dr. Frank Biendara and Denni Strich.


The National Basketball Association (NBA) is a global sports and media organization with the mission to inspire and connect people everywhere through the power of basketball. Built around five professional sports leagues: the NBA, WNBA, NBA G League, NBA 2K League and Basketball Africa League, the

Major League Baseball (MLB) is the most historic professional sports league in the United States and consists of 30 member clubs in the U.S. and Canada, representing the highest level of professional baseball. Led by Commissioner Robert D. Manfred, Jr., MLB remains committed to making an impact in
.png)
Arminia Bielefeld's fairytale run in the DFB Pokal is over. On Saturday, Bielefeld lost 4-2 to Bundesliga side VfB Stuttgart.
Live stream Arminia Bielefeld vs. VfB Stuttgart in the DFB-Pokal final for free on ServusTV. Access this free streaming platform from anywhere in the world...
Arminia Bielefeld players and staff celebrate after knocking out Bayer Leverkusen to reach the DFB Pokal final in Berlin.
LEIPZIG, Germany: A second-half Benjamin Sesko penalty steered RB Leipzig to a 1-0 win at home to Wolfsburg and a place in the German Cup...
This year, the DFB Pokal once again has a wonderful underdog story in the form of Arminia Bielefeld.
We are delighted to announce our partnership with RB Leipzig, two-time DFB Cup winner and one of Germany's most thrilling and innovative...
Four-time German champions, two DFB Pokals, countless European nights, and the spine of the 1954 World Cup-winning side—all that and more is 1.
The supermassive leak contains data from numerous previous breaches, comprising an astounding 12 terabytes of information, spanning over a mind-boggling 26...
On Saturday, RB Leipzig defended their DFB Pokal title tanks to a 2-0 victory over Eintracht Frankfurt in front of 74,332 fans at a sold-out...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of DFB is https://www.dfb.de.
According to Rankiteo, DFB’s AI-generated cybersecurity score is 703, reflecting their Moderate security posture.
According to Rankiteo, DFB currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, DFB is not certified under SOC 2 Type 1.
According to Rankiteo, DFB does not hold a SOC 2 Type 2 certification.
According to Rankiteo, DFB is not listed as GDPR compliant.
According to Rankiteo, DFB does not currently maintain PCI DSS compliance.
According to Rankiteo, DFB is not compliant with HIPAA regulations.
According to Rankiteo,DFB is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
DFB operates primarily in the Spectator Sports industry.
DFB employs approximately 1,403 people worldwide.
DFB presently has no subsidiaries across any sectors.
DFB’s official LinkedIn profile has approximately 48,962 followers.
DFB is classified under the NAICS code 7112, which corresponds to Spectator Sports.
No, DFB does not have a profile on Crunchbase.
Yes, DFB maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/deutscher-fussball-bund.
As of December 03, 2025, Rankiteo reports that DFB has experienced 1 cybersecurity incidents.
DFB has an estimated 6,542 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with get_class_from_dynamic_module(...) and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the auto_map string. Crucially, this happens even when the caller explicitly sets trust_remote_code=False in vllm.transformers_utils.config.get_config. In practice, an attacker can publish a benign-looking frontend repo whose config.json points via auto_map to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host. This vulnerability is fixed in 0.11.1.
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.