Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
DigitalOcean

DigitalOcean Vendor Cyber Rating & Cyber Score

digitalocean.com

DigitalOcean simplifies cloud computing so businesses can spend more time creating software that changes the world. With its mission-critical infrastructure and fully managed offerings, DigitalOcean helps developers at startups and growing digital businesses rapidly build, deploy and scale, whether creating a digital presence or building digital products. DigitalOcean combines the power of simplicity, security, community and customer support so customers can spend less time managing their infrastructure and more time building innovative applications that drive business growth.


DigitalOcean A.I CyberSecurity Scoring

DigitalOcean
Company Information
Website:https://www.digitalocean.com
Employees number:2,363
Number of followers:158,363
NAICS:5112
Industry Type:Software Development
Homepage:digitalocean.com
DigitalOcean Risk Score (AI oriented)
Between 700 and 749
logo
DigitalOceanSoftware Development
Updated:
10/07/2026
703/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
DigitalOcean Global Score (TPRM)
xxxx
logo
DigitalOceanSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

DigitalOcean
DigitalOceanModerate
Current Score
703Ba (MODERATE)
01000
4 incidents
-32.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
706Before Incident
JULY 2026
703Before Incident
JUNE 2026
707Before Incident
Vulnerability
11 Jun 2026DigitalOcean
ThemeREX, Joomla, Simple File List, WP File Manager, Oracle and DigitalOcean: Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

WP-SHELLSTORM Cybercrime Group's Exposed Server Reveals Mass Webshell Operation Targeting 1.4 Million Sites

701After Incident
CRITICAL-6
ORAJOOMANWPMDIGTHE1783693992
Cybercrime Crew’s Exposed Server Reveals Mass Webshell Operation Targeting 1.4 Million Sites A cybercrime group, tracked as WP-SHELLSTORM, inadvertently exposed its operations for three weeks after leaving an unsecured server online. The incident, discovered by researchers at SOCRadar and Ctrl-Alt-Intel, provided an unprecedented look into a webshell access brokerage a scheme where attackers compromise websites en masse, install backdoors, and sell access to other criminals. ### The Exposure On June 11, 2026, SOCRadar identified an unprotected server (IP: 137.175.93[.]126) hosting 800MB of data, including: - Hacking tools (exploit scripts, webshells) - Activity logs (command histories, scan results) - Target lists naming 1.4 million websites (WordPress, Joomla, and others) - Command-and-control (C2) configurations The server, rented in the U.S., was left open due to a Python web server left running for 22 days a simple but costly oversight. Ctrl-Alt-Intel independently analyzed the same directory, publishing findings on June 22, before SOCRadar’s July 9 report. ### The Attack Method The group exploited 27 known vulnerabilities, primarily in WordPress plugins, to deploy webshells small scripts granting remote control over compromised servers. Key flaws included: - Breeze caching plugin (CVE-2026-3844) – Exploited against 45,000+ sites, successfully backdooring 17,000+ (only effective with a non-default setting enabled). - Joomla JCE editor (CVE-2026-48907) – Targeted 560,000+ sites but only breached 77. - Other WordPress plugins (e.g., ThemeREX Addons, Simple File List, WP File Manager). The attackers used FOFA, a Chinese search engine for internet-connected systems, to build target lists. Their toolkit included: - down.php – A heavily obfuscated webshell derived from BestShell (open-source Chinese malware). - VShell – A stealthy backdoor disguised as a kernel process ([kworker/0:2]) to evade detection. ### Compromise Scale While the 1.4 million figure represents targets, not breaches, researchers confirmed: - Ctrl-Alt-Intel: 25,195 sites with evidence of compromise. - SOCRadar: 5,700+ active webshells. ### Earlier Corporate Espionage Campaign Before the WordPress spree, the same group ran a quieter operation in May 2026, targeting Java-based corporate systems via a Nacos configuration server flaw (CVE-2021-29441). They extracted: - 613 configuration files from 11 systems across nine companies (fintech, e-commerce, logistics, gaming, electronics). - Cloud credentials (AWS, Alibaba, Oracle, Tencent, DigitalOcean). - Database passwords and Alipay RSA private keys. SOCRadar suggests this was a "funding round" before scaling up the higher-volume webshell operation. ### Attribution & Sloppy Tradecraft Researchers assess with medium-to-high confidence that the group is Chinese or Chinese-speaking, citing: - Simplified Chinese in code and command logs. - Use of FOFA (requiring a Chinese phone number for registration). - Tools like Godzilla and VShell, common in Chinese-speaking cybercrime forums. Despite a sophisticated toolchain, the group made basic errors: - Left the server unprotected for weeks. - Exposed a FOFA config file, traceable via law enforcement. - Failed to sanitize command histories, revealing the full operation. When alerted, the group deleted log entries between July 2–4, but the damage was already done. ### Broader Implications WP-SHELLSTORM stands out not for its technical sophistication, but for its scale and opportunism. Using publicly known vulnerabilities and automated scanning, the group compromised thousands of sites without needing zero-days. The incident mirrors a March 2026 exposure of Russia’s APT28 (Fancy Bear), where an open directory revealed phishing tools and logs. In both cases, human error not advanced hacking led to the unraveling of major cybercrime operations.
INCIDENT DETAILS -
TYPE
Webshell AttackData BreachCybercrime Brokerage
MOTIVATION
Financial gainCybercrime brokerageCorporate espionage
IMPACT
Configuration filesCloud credentials (AWS, Alibaba, Oracle, Tencent, DigitalOcean)Database passwordsAlipay RSA private keysWebsite backdoor accessWordPress sites (45,000+ targeted, 17,000+ compromised)Joomla sites (560,000+ targeted, 77 compromised)Java-based corporate systems (11 systems across 9 companies)Operational Impact: Mass compromise of websites for resale of access; potential data exfiltration and further attacks by buyersBrand Reputation Impact: Potential reputational damage to affected entities due to compromise and data exposureIdentity Theft Risk: High (due to exposure of PII and credentials)Payment Information Risk: High (Alipay RSA private keys exposed)
DATA BREACH
Configuration filesCloud credentialsDatabase passwordsAlipay RSA private keysWebshell access logsNumber Of Records Exposed: 613 configuration files from 11 systems; 1.4 million websites targetedSensitivity Of Data: High (credentials, private keys, PII)Data Exfiltration: Yes (data sold on dark web implied)Configuration filesLogsWebshell scriptsPersonally Identifiable Information: Likely (credentials and private keys)
MAY 2026
709Before Incident
APRIL 2026
684Before Incident
MARCH 2026
711Before Incident
Cyber Attack
15 Mar 2026DigitalOcean
DigitalOcean: Notorious online data leak market BreachForums taken down by whitehat heroes

BreachForums Shut Down After CCITIC Abuse Reports

687After Incident
LOW-24
DIG1773779139
BreachForums Shut Down After CCITIC Abuse Reports, Admin Seeks New Leadership BreachForums, a prominent underground marketplace for malware and stolen data, was taken offline over the weekend following targeted action by the Cyber Counter-Intelligence Threat Investigation Consortium (CCITIC). The nonprofit organization, which supports law enforcement in cybercrime takedowns, identified the forum’s upstream servers hosted on DigitalOcean’s Frankfurt datacenter (ASN 14061) and filed abuse reports that led to their shutdown. Both the clearnet and Tor versions of the site displayed a 502 Bad Gateway error. The forum’s admin later announced plans to step down, posting a message seeking a successor to take over leadership. While BreachForums has previously been seized by law enforcement first in June 2023 and again in May 2024 it has repeatedly resurfaced under new management. However, CCITIC suggests this shutdown may be permanent, citing a January 2026 data breach that exposed the forum’s user database of approximately 324,000 accounts. The incident has reportedly eroded trust among threat actors, fracturing the underground ecosystem. The takedown highlights how persistent investigative efforts, including OSINT (open-source intelligence) and coordinated abuse reports, can disrupt cybercriminal operations without direct law enforcement intervention. BreachForums’ future remains uncertain as its community grapples with the fallout.
INCIDENT DETAILS -
TYPE
Marketplace Takedown
MOTIVATION
Cybercriminal operations (data and malware trading)
IMPACT
Data Compromised: 324,000 user accounts exposed in a January 2026 data breachSystems Affected: BreachForums (clearnet and Tor versions)Downtime: Site displayed 502 Bad Gateway errorOperational Impact: Disruption of underground marketplace operationsBrand Reputation Impact: Eroded trust among threat actors, fracturing the underground ecosystemIdentity Theft Risk: High (user database exposed)
DATA BREACH
Type Of Data Compromised: User databaseNumber Of Records Exposed: 324,000Sensitivity Of Data: High (underground marketplace user accounts)Personally Identifiable Information: Likely (user accounts)
FEBRUARY 2026
694Before Incident
JANUARY 2026
761Before Incident
Breach
30 Jan 2026DigitalOcean
DigitalOcean, OVH and AWS: Moltbot Operators Leak Control Panels via Exposed mDNS Traffic

Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations

694After Incident
CRITICAL-67
AWSDIGOVH1769784401
Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations Security researchers have uncovered a widespread exposure of 1,487 Moltbot instances globally, leaking sensitive operational metadata and messaging platform credentials through misconfigured multicast DNS (mDNS) broadcasts. The open-source framework, designed for autonomous agent orchestration, inadvertently disclosed system-level details including hostnames, filesystem paths, service ports, and identity artifacts to any device on the same network segment. ### Key Findings - Exposed Data: Full machine hostnames, Clawdbot Control panel ports (18789), SSH ports, internal IPs, and messaging platform credentials (Signal, Telegram, WhatsApp) containing registration secrets and identity keys. - Geographic Spread: Instances were found across 53 countries, with the highest concentration in the U.S. Major hosting providers included DigitalOcean, AWS, and OVH. - Accessible Control Panels: 88 instances had publicly exposed web interfaces, with 66 leaking both mDNS and web access simultaneously. - Credential Leakage: Open directory listings revealed operational logs, cryptographic material, and runtime caches, enabling full agent impersonation without exploiting vulnerabilities. - Network Reconnaissance: mDNS broadcasts, intended for local service discovery, acted as pre-authentication metadata leaks, exposing systems in workplace Wi-Fi, co-working spaces, and university networks. ### Deployment Failures & Attack Surface The exposure stems from poor deployment hygiene rather than software flaws. Many instances self-announced internal structures via mDNS, providing attackers with reconnaissance data without active probing. A dedicated honeypot with 25 open ports suggested early attacker interest, while 635 accessible web control interfaces further expanded the attack surface. The combination of service advertisements, open directories, and credential leaks creates pre-authentication compromise risks, allowing adversaries to bypass authentication, hijack agent identities, or conduct phishing and lateral movement attacks. The findings highlight systemic misconfigurations in Moltbot deployments, where operators often overlook mDNS implications and basic access controls.
INCIDENT DETAILS -
TYPE
Misconfiguration
IMPACT
Data Compromised: Hostnames, filesystem paths, service ports, messaging platform credentials (Signal, Telegram, WhatsApp), operational logs, cryptographic material, runtime cachesSystems Affected: 1,487 Moltbot instancesOperational Impact: Pre-authentication compromise risks, agent identity hijacking, phishing, lateral movement attacksIdentity Theft Risk: High (identity artifacts and credentials exposed)
DATA BREACH
Type Of Data Compromised: Operational metadata, messaging platform credentials, cryptographic material, runtime cachesNumber Of Records Exposed: 1,487 instancesSensitivity Of Data: High (identity artifacts, credentials, internal IPs, service ports)File Types Exposed: Logs, cryptographic material, runtime cachesPersonally Identifiable Information: Hostnames, identity artifacts, messaging platform credentials
DECEMBER 2025
761Before Incident
NOVEMBER 2025
761Before Incident
OCTOBER 2025
760Before Incident
SEPTEMBER 2025
760Before Incident
JUNE 2018
771Before Incident
Data Leak
16 Jun 2018DigitalOcean
DigitalOcean

Digital Ocean Customer Details Exposure

715After Incident
MEDIUM-56
DIG032301222
Web hosting provider Digital Ocean experienced a security lapse that exposed some of customer details. An internal Digital Ocean document was mistakenly left accessible online. Digital Ocean says the document contained several types of user account details. This included personally identifiable information such as customer email addresses and their respective Digital Ocean usernames, but also account technical details such as the number of droplets (servers) owned by the customer, the user's bandwidth usage, support or sales communications notes, and the amount of money the customer paid during the calendar year 2018. Digital Ocean said that the internal document was accessed at least 15 times while it was left available online. Digital Ocean said the file contained details for less than 1% of the company's total customer base.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Customer email addresses, Digital Ocean usernames, number of droplets owned, bandwidth usage, support or sales communications notes, amount paid in 2018
DATA BREACH
Type Of Data Compromised: Personally identifiable information, Account technical detailsPersonally Identifiable Information: Customer email addresses, Digital Ocean usernames

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for DigitalOcean ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in July 2026 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in June 2026 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in May 2026 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in April 2026 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in March 2026 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in February 2026 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in January 2026 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in December 2025 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in November 2025 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in October 2025 ?
?
What was DigitalOcean's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on DigitalOcean's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with DigitalOcean ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view DigitalOcean's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?