Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Elastic

Elastic Vendor Cyber Rating & Cyber Score

elastic.co

Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale. Elastic’s solutions for search, observability, and security are built on the Elastic Search AI Platform — the development platform used by thousands of companies, including more than 50% of the Fortune 500.


Elastic A.I CyberSecurity Scoring

Elastic
Company Information
Website:http://www.elastic.co
Employees number:5,047
Number of followers:540,594
NAICS:5112
Industry Type:Software Development
Homepage:elastic.co
Elastic Risk Score (AI oriented)
Between 0 and 549
logo
ElasticSoftware Development
Updated:
17/06/2026
485/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Elastic Global Score (TPRM)
xxxx
logo
ElasticSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Elastic
ElasticCritical
Current Score
485C (CRITICAL)
01000
5 incidents
-90.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
498Before Incident
JULY 2026
492Before Incident
JUNE 2026
651Before Incident
Breach
17 Jun 2026Elastic
Elasticsearch and Leak-Lookup: 24 billion stolen records found in giant data dump. Check if you’re affected

Massive 24-Billion-Record Database of Stolen Credentials Exposed Online

488After Incident
CRITICAL-163
INTELA1781699483
Massive 24-Billion-Record Database of Stolen Credentials Exposed Online Researchers at Cybernews uncovered a publicly accessible Elasticsearch database containing 24 billion stolen credential records, totaling 8.3 terabytes of data. The exposed cluster, which was briefly available online before being secured, aggregated information from 36 sources, including Telegram channels, prior breach compilations, infostealer logs, and direct server exports. The dataset included 1.7 billion records from hacking-related Telegram channels primarily in English and Russian alongside structured infostealer logs with usernames, email addresses, plaintext passwords, and login URLs. Some entries also contained stolen credit card data, while others featured vulnerability reports, breach articles, and cyberattack discussions, suggesting the database was actively maintained for either commercial monitoring or offensive cyber operations. The breach rivals the scale of past "mega-dumps," such as the "mother of all breaches" linked to the Leak-Lookup search engine, but with a heavier focus on fresh infostealer logs rather than older breach data. Infostealer logs often capture browser-stored passwords, session cookies (including MFA bypass tokens), autofill data, device fingerprints, and even crypto wallet details from infected devices. While the database was taken offline shortly after discovery limiting further exposure researchers could not fully analyze duplicates or confirm all affected individuals. However, the presence of reused passwords still poses a significant risk to compromised accounts. The incident underscores the persistent circulation of stolen credentials from phishing, data breaches, and malware infections, reinforcing the need for heightened security measures.
INCIDENT DETAILS -
TYPE
Data Exposure
MOTIVATION
Commercial MonitoringOffensive Cyber Operations
IMPACT
Data Compromised: 24 billion records (8.3 TB)Systems Affected: Elasticsearch databaseIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
CredentialsCredit Card DataSession CookiesAutofill DataDevice FingerprintsCrypto Wallet DetailsVulnerability ReportsBreach ArticlesNumber Of Records Exposed: 24 billionSensitivity Of Data: HighUsernamesEmail AddressesPlaintext PasswordsLogin URLsSession CookiesAutofill DataDevice Fingerprints
MAY 2026
667Before Incident
Cyber Attack
28 May 2026Elastic
OpenSearch, npm, ElasticSearch, Amazon Web Services and GitHub: Typosquatted npm Packages Steal Cloud and CI/CD Secrets

Sophisticated npm Supply Chain Attack Targets OpenSearch, ElasticSearch, and DevOps Tools

649After Incident
CRITICAL-18
ELAGITAMAOPENPM1780050263
Sophisticated npm Supply Chain Attack Targets OpenSearch, ElasticSearch, and DevOps Tools A recently uncovered npm supply chain attack has targeted developers working with OpenSearch, ElasticSearch, and DevOps tooling, stealing cloud credentials and CI/CD secrets from compromised systems. The campaign, attributed to a threat actor using the alias vpmdhaj, involved 14 malicious packages published on May 28, 2026, within a four-hour window. The attackers employed typosquatting and metadata spoofing, mimicking legitimate libraries with names like opensearch-setup and elastic-opensearch-helper while falsely linking to the official OpenSearch GitHub repository. To appear credible, the packages were assigned inflated version numbers, suggesting maturity and widespread use. Upon installation, the malicious packages executed code via npm preinstall scripts, triggering automatically without user interaction. The attack employed a two-stage payload system: - Early versions used a JavaScript stager to collect system details (hostname, OS, Node.js version, environment variables) and send them to a command-and-control (C2) server. The server responded with a compressed binary payload, identifiable by the “X-Supply: 1” HTTP header in network logs. - Later variants improved stealth by eliminating direct C2 communication, instead downloading the Bun runtime from GitHub to execute an embedded second-stage payload. This reduced suspicious outbound traffic and evaded traditional detection. The second-stage payload, a Bun-compiled binary, targeted credentials across multiple platforms, including: - Amazon Web Services (AWS) – Extracting environment variables, querying EC2 Instance Metadata Service and ECS task metadata, and enumerating secrets in AWS Secrets Manager. - HashiCorp Vault – Harvesting tokens. - GitHub Actions & npm – Validating publish tokens to hijack package maintainers and propagate further supply chain attacks. A persistence mechanism ensured the payload re-executed whenever the malicious module was imported, allowing it to survive across development cycles and CI/CD pipeline runs. The impact of the campaign is severe: - Stolen AWS credentials could enable lateral movement in cloud environments. - Compromised CI/CD tokens may allow attackers to manipulate build pipelines or inject malicious code into production. - Hijacked npm publish tokens pose a risk of malicious updates to legitimate packages, expanding the attack’s reach. Following responsible disclosure, the malicious packages and associated accounts were removed from the npm registry. However, organizations that installed these dependencies remain at risk. Security teams are urged to audit systems for affected packages, rotate exposed credentials, and monitor for indicators of compromise, including the “X-Supply: 1” header and unusual CloudTrail activity. The incident underscores the growing sophistication of supply chain attacks, where trusted ecosystems like npm are exploited to gain access to sensitive cloud and development infrastructure.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Credential TheftSupply Chain Compromise
IMPACT
Cloud credentialsCI/CD secretsAWS secretsHashiCorp Vault tokensGitHub Actions tokensnpm publish tokensDevelopment environmentsCI/CD pipelinesCloud infrastructure (AWS)Operational Impact: Potential lateral movement in cloud environments, manipulation of build pipelines, injection of malicious code into production
DATA BREACH
Cloud credentialsCI/CD secretsAWS secretsHashiCorp Vault tokensGitHub Actions tokensnpm publish tokensSensitivity Of Data: High
APRIL 2026
663Before Incident
MARCH 2026
660Before Incident
FEBRUARY 2026
657Before Incident
JANUARY 2026
656Before Incident
DECEMBER 2025
652Before Incident
NOVEMBER 2025
651Before Incident
OCTOBER 2025
648Before Incident
SEPTEMBER 2025
646Before Incident
JUNE 2025
776Before Incident
Vulnerability
01 Jun 2025Elastic
Elastic

Elastic EDR Zero-Day Vulnerability Leading to BSOD and System Compromise

771After Incident
CRITICAL-5
ELA627081725
A critical zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) solution—specifically in the elastic-endpoint-driver.sys kernel driver—allows attackers to bypass security, execute arbitrary code, and trigger Blue Screen of Death (BSOD) crashes, rendering systems unusable. The flaw stems from a NULL Pointer Dereference (CWE-476), enabling a four-stage attack chain: EDR bypass, Remote Code Execution (RCE), persistence via a malicious kernel driver, and privileged Denial-of-Service (DoS). The exploit turns Elastic’s own security tool into a weapon, risking large-scale endpoint disablement across enterprises. No patch exists for versions 8.17.6 and later, leaving customers exposed since disclosure attempts (June–August 2025). The vulnerability erodes trust in Elastic’s SIEM/EDR products, as a signed driver can now behave like malware, crashing systems on demand. Organizations face operational paralysis, potential data exposure during crashes, and loss of defensive capabilities until mitigation is deployed.
INCIDENT DETAILS -
TYPE
Zero-Day VulnerabilityPrivilege EscalationDenial of Service (DoS)Remote Code Execution (RCE)Persistence Mechanism
IMPACT
Endpoints running Elastic EDR/AgentSystems with 'elastic-endpoint-driver.sys'Persistent system crashes (BSOD)Potential large-scale endpoint disablementLoss of EDR/SIEM protectionSystem instabilityPotential for follow-on attacks (e.g., malware deployment)Erosion of trust in Elastic’s security productsBroader industry skepticism toward EDR solutions
MARCH 2025
634Before Incident
Vulnerability
01 Mar 2025Elastic
Elastic

Critical Vulnerability in Kibana (CVE-2025-25012)

630After Incident
CRITICAL-4
ELA921030725
Elastic released a critical update to address a severe vulnerability in Kibana, identified as CVE-2025-25012. With a CVSS score of 9.9, the flaw allows for arbitrary code execution and primarily affects versions 8.15.0 to 8.17.2. The vulnerability, resulting from unsafe handling of prototype pollution, could be exploited by users with low privileges in earlier versions, and more advanced privileges in later versions. This security gap has the potential for severe consequences, such as unauthorized data access, system compromise, and service disruption, leading to theft or destruction of sensitive information. In response, Elastic urges users to upgrade to version 8.17.3 or later and recommends additional security measures for those unable to upgrade immediately.
INCIDENT DETAILS -
TYPE
Vulnerability Exploit
JANUARY 2025
778Before Incident
Breach
01 Jan 2025Elastic
WeChat and Elasticsearch: Massive Data Leak Exposes 8.7 Billion Records From Hundreds of Millions of Chinese Individuals

Massive Chinese Data Leak Exposes 8.7 Billion Records in Unsecured Database

629After Incident
CRITICAL-149
TEAELA1770659583
Massive Chinese Data Leak Exposes 8.7 Billion Records in Unsecured Database A significant data leak has exposed over 8.7 billion personal and business records, primarily affecting Chinese individuals. The unsecured Elasticsearch cluster, hosted on bulletproof infrastructure, remained accessible for three weeks before being secured, giving threat actors ample time to exfiltrate the data. The exposed dataset included full names, phone numbers, national ID numbers, home addresses, email accounts, social media identifiers, and passwords many stored in plaintext or weakly protected. This sensitive information heightens risks of phishing, account takeovers, fraud, and identity theft, particularly for individuals who reuse passwords across services. Corporate data, such as company registration details and business contacts, was also compromised, enabling potential impersonation and targeted scams. Security researchers suspect the leak was deliberate, given the data’s highly organized structure and storage on bulletproof infrastructure commonly used by high-risk entities. The records included up-to-date information from 2025, suggesting long-term aggregation rather than a historical breach. While the exact number of affected individuals remains unclear due to duplicated records, estimates place the impact in the hundreds of millions. The incident underscores China’s ongoing struggle with large-scale data breaches, following previous leaks from major platforms like WeChat, Alipay, QQ, and Weibo, as well as government-linked entities. In September 2025, a separate breach exposed 500 GB of internal documents from China’s Great Firewall, while a 2022 Shanghai police leak compromised 23 terabytes of data for over a billion people. The identity of the threat actor behind this latest breach remains unknown, with no entity claiming responsibility.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Likely deliberate (data aggregation for malicious use)
IMPACT
Data Compromised: 8.7 billion recordsSystems Affected: Unsecured Elasticsearch clusterBrand Reputation Impact: High (China's ongoing struggle with data breaches)Identity Theft Risk: High
DATA BREACH
Personal dataBusiness dataNumber Of Records Exposed: 8.7 billionSensitivity Of Data: High (national ID numbers, passwords, home addresses, etc.)Data Exfiltration: Likely (threat actors had three weeks of access)Data Encryption: Weak or none (plaintext passwords)Full namesPhone numbersNational ID numbersHome addressesEmail accountsSocial media identifiersPasswords

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Elastic ?
?
What was Elastic's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Elastic's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Elastic's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Elastic's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Elastic's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Elastic's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Elastic's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Elastic's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Elastic's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Elastic's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Elastic's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Elastic's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Elastic ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Elastic's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Elastic Cyber Scoring History | Rankiteo