DigitalOcean A.I CyberSecurity Scoring
DigitalOcean
Company Information
Website:https://www.digitalocean.com
Employees number:2,363
Number of followers:158,363
NAICS:5112
Industry Type:Software Development
Homepage:digitalocean.com
DigitalOcean Risk Score (AI oriented)
Between 700 and 749
DigitalOceanSoftware Development
Updated:
10/07/2026
10/07/2026
703/1000
Moderate
Ba
DigitalOcean Global Score (TPRM)
xxxx
DigitalOceanSoftware Development
Score locked

DigitalOceanModerate
Current Score
703Ba (MODERATE)
01000
4 incidents
-32.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
706
JULY 2026
703
JUNE 2026
707
Vulnerability
11 Jun 2026 • DigitalOcean
ThemeREX, Joomla, Simple File List, WP File Manager, Oracle and DigitalOcean: Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
WP-SHELLSTORM Cybercrime Group's Exposed Server Reveals Mass Webshell Operation Targeting 1.4 Million Sites
701
CRITICAL-6
ORAJOOMANWPMDIGTHE1783693992
Cybercrime Crew’s Exposed Server Reveals Mass Webshell Operation Targeting 1.4 Million Sites
A cybercrime group, tracked as WP-SHELLSTORM, inadvertently exposed its operations for three weeks after leaving an unsecured server online. The incident, discovered by researchers at SOCRadar and Ctrl-Alt-Intel, provided an unprecedented look into a webshell access brokerage a scheme where attackers compromise websites en masse, install backdoors, and sell access to other criminals.
### The Exposure
On June 11, 2026, SOCRadar identified an unprotected server (IP: 137.175.93[.]126) hosting 800MB of data, including:
- Hacking tools (exploit scripts, webshells)
- Activity logs (command histories, scan results)
- Target lists naming 1.4 million websites (WordPress, Joomla, and others)
- Command-and-control (C2) configurations
The server, rented in the U.S., was left open due to a Python web server left running for 22 days a simple but costly oversight. Ctrl-Alt-Intel independently analyzed the same directory, publishing findings on June 22, before SOCRadar’s July 9 report.
### The Attack Method
The group exploited 27 known vulnerabilities, primarily in WordPress plugins, to deploy webshells small scripts granting remote control over compromised servers. Key flaws included:
- Breeze caching plugin (CVE-2026-3844) – Exploited against 45,000+ sites, successfully backdooring 17,000+ (only effective with a non-default setting enabled).
- Joomla JCE editor (CVE-2026-48907) – Targeted 560,000+ sites but only breached 77.
- Other WordPress plugins (e.g., ThemeREX Addons, Simple File List, WP File Manager).
The attackers used FOFA, a Chinese search engine for internet-connected systems, to build target lists. Their toolkit included:
- down.php – A heavily obfuscated webshell derived from BestShell (open-source Chinese malware).
- VShell – A stealthy backdoor disguised as a kernel process ([kworker/0:2]) to evade detection.
### Compromise Scale
While the 1.4 million figure represents targets, not breaches, researchers confirmed:
- Ctrl-Alt-Intel: 25,195 sites with evidence of compromise.
- SOCRadar: 5,700+ active webshells.
### Earlier Corporate Espionage Campaign
Before the WordPress spree, the same group ran a quieter operation in May 2026, targeting Java-based corporate systems via a Nacos configuration server flaw (CVE-2021-29441). They extracted:
- 613 configuration files from 11 systems across nine companies (fintech, e-commerce, logistics, gaming, electronics).
- Cloud credentials (AWS, Alibaba, Oracle, Tencent, DigitalOcean).
- Database passwords and Alipay RSA private keys.
SOCRadar suggests this was a "funding round" before scaling up the higher-volume webshell operation.
### Attribution & Sloppy Tradecraft
Researchers assess with medium-to-high confidence that the group is Chinese or Chinese-speaking, citing:
- Simplified Chinese in code and command logs.
- Use of FOFA (requiring a Chinese phone number for registration).
- Tools like Godzilla and VShell, common in Chinese-speaking cybercrime forums.
Despite a sophisticated toolchain, the group made basic errors:
- Left the server unprotected for weeks.
- Exposed a FOFA config file, traceable via law enforcement.
- Failed to sanitize command histories, revealing the full operation.
When alerted, the group deleted log entries between July 2–4, but the damage was already done.
### Broader Implications
WP-SHELLSTORM stands out not for its technical sophistication, but for its scale and opportunism. Using publicly known vulnerabilities and automated scanning, the group compromised thousands of sites without needing zero-days.
The incident mirrors a March 2026 exposure of Russia’s APT28 (Fancy Bear), where an open directory revealed phishing tools and logs. In both cases, human error not advanced hacking led to the unraveling of major cybercrime operations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
709
APRIL 2026
684
MARCH 2026
711
Cyber Attack
15 Mar 2026 • DigitalOcean
DigitalOcean: Notorious online data leak market BreachForums taken down by whitehat heroes
BreachForums Shut Down After CCITIC Abuse Reports
687
LOW-24
DIG1773779139
BreachForums Shut Down After CCITIC Abuse Reports, Admin Seeks New Leadership
BreachForums, a prominent underground marketplace for malware and stolen data, was taken offline over the weekend following targeted action by the Cyber Counter-Intelligence Threat Investigation Consortium (CCITIC). The nonprofit organization, which supports law enforcement in cybercrime takedowns, identified the forum’s upstream servers hosted on DigitalOcean’s Frankfurt datacenter (ASN 14061) and filed abuse reports that led to their shutdown. Both the clearnet and Tor versions of the site displayed a 502 Bad Gateway error.
The forum’s admin later announced plans to step down, posting a message seeking a successor to take over leadership. While BreachForums has previously been seized by law enforcement first in June 2023 and again in May 2024 it has repeatedly resurfaced under new management. However, CCITIC suggests this shutdown may be permanent, citing a January 2026 data breach that exposed the forum’s user database of approximately 324,000 accounts. The incident has reportedly eroded trust among threat actors, fracturing the underground ecosystem.
The takedown highlights how persistent investigative efforts, including OSINT (open-source intelligence) and coordinated abuse reports, can disrupt cybercriminal operations without direct law enforcement intervention. BreachForums’ future remains uncertain as its community grapples with the fallout.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
694
JANUARY 2026
761
Breach
30 Jan 2026 • DigitalOcean
DigitalOcean, OVH and AWS: Moltbot Operators Leak Control Panels via Exposed mDNS Traffic
Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations
694
CRITICAL-67
AWSDIGOVH1769784401
Moltbot Framework Exposes 1,400+ Instances via mDNS Misconfigurations
Security researchers have uncovered a widespread exposure of 1,487 Moltbot instances globally, leaking sensitive operational metadata and messaging platform credentials through misconfigured multicast DNS (mDNS) broadcasts. The open-source framework, designed for autonomous agent orchestration, inadvertently disclosed system-level details including hostnames, filesystem paths, service ports, and identity artifacts to any device on the same network segment.
### Key Findings
- Exposed Data: Full machine hostnames, Clawdbot Control panel ports (18789), SSH ports, internal IPs, and messaging platform credentials (Signal, Telegram, WhatsApp) containing registration secrets and identity keys.
- Geographic Spread: Instances were found across 53 countries, with the highest concentration in the U.S. Major hosting providers included DigitalOcean, AWS, and OVH.
- Accessible Control Panels: 88 instances had publicly exposed web interfaces, with 66 leaking both mDNS and web access simultaneously.
- Credential Leakage: Open directory listings revealed operational logs, cryptographic material, and runtime caches, enabling full agent impersonation without exploiting vulnerabilities.
- Network Reconnaissance: mDNS broadcasts, intended for local service discovery, acted as pre-authentication metadata leaks, exposing systems in workplace Wi-Fi, co-working spaces, and university networks.
### Deployment Failures & Attack Surface
The exposure stems from poor deployment hygiene rather than software flaws. Many instances self-announced internal structures via mDNS, providing attackers with reconnaissance data without active probing. A dedicated honeypot with 25 open ports suggested early attacker interest, while 635 accessible web control interfaces further expanded the attack surface.
The combination of service advertisements, open directories, and credential leaks creates pre-authentication compromise risks, allowing adversaries to bypass authentication, hijack agent identities, or conduct phishing and lateral movement attacks. The findings highlight systemic misconfigurations in Moltbot deployments, where operators often overlook mDNS implications and basic access controls.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
761
NOVEMBER 2025
761
OCTOBER 2025
760
SEPTEMBER 2025
760
JUNE 2018
771
Data Leak
16 Jun 2018 • DigitalOcean
DigitalOcean
Digital Ocean Customer Details Exposure
715
MEDIUM-56
DIG032301222
Web hosting provider Digital Ocean experienced a security lapse that exposed some of customer details.
An internal Digital Ocean document was mistakenly left accessible online.
Digital Ocean says the document contained several types of user account details.
This included personally identifiable information such as customer email addresses and their respective Digital Ocean usernames, but also account technical details such as the number of droplets (servers) owned by the customer, the user's bandwidth usage, support or sales communications notes, and the amount of money the customer paid during the calendar year 2018.
Digital Ocean said that the internal document was accessed at least 15 times while it was left available online.
Digital Ocean said the file contained details for less than 1% of the company's total customer base.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for DigitalOcean ??
What was DigitalOcean's A.I Rankiteo Cyber Score in July 2026 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in June 2026 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in May 2026 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in April 2026 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in March 2026 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in February 2026 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in January 2026 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in December 2025 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in November 2025 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in October 2025 ??
What was DigitalOcean's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on DigitalOcean's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with DigitalOcean ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view DigitalOcean's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?