Elastic A.I CyberSecurity Scoring
Elastic
Company Information
Website:http://www.elastic.co
Employees number:5,047
Number of followers:540,594
NAICS:5112
Industry Type:Software Development
Homepage:elastic.co
Elastic Risk Score (AI oriented)
Between 0 and 549
ElasticSoftware Development
Updated:
17/06/2026
17/06/2026
485/1000
Critical
C
Elastic Global Score (TPRM)
xxxx
ElasticSoftware Development
Score locked

ElasticCritical
Current Score
485C (CRITICAL)
01000
5 incidents
-90.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
498
JULY 2026
492
JUNE 2026
651
Breach
17 Jun 2026 • Elastic
Elasticsearch and Leak-Lookup: 24 billion stolen records found in giant data dump. Check if you’re affected
Massive 24-Billion-Record Database of Stolen Credentials Exposed Online
488
CRITICAL-163
INTELA1781699483
Massive 24-Billion-Record Database of Stolen Credentials Exposed Online
Researchers at Cybernews uncovered a publicly accessible Elasticsearch database containing 24 billion stolen credential records, totaling 8.3 terabytes of data. The exposed cluster, which was briefly available online before being secured, aggregated information from 36 sources, including Telegram channels, prior breach compilations, infostealer logs, and direct server exports.
The dataset included 1.7 billion records from hacking-related Telegram channels primarily in English and Russian alongside structured infostealer logs with usernames, email addresses, plaintext passwords, and login URLs. Some entries also contained stolen credit card data, while others featured vulnerability reports, breach articles, and cyberattack discussions, suggesting the database was actively maintained for either commercial monitoring or offensive cyber operations.
The breach rivals the scale of past "mega-dumps," such as the "mother of all breaches" linked to the Leak-Lookup search engine, but with a heavier focus on fresh infostealer logs rather than older breach data. Infostealer logs often capture browser-stored passwords, session cookies (including MFA bypass tokens), autofill data, device fingerprints, and even crypto wallet details from infected devices.
While the database was taken offline shortly after discovery limiting further exposure researchers could not fully analyze duplicates or confirm all affected individuals. However, the presence of reused passwords still poses a significant risk to compromised accounts.
The incident underscores the persistent circulation of stolen credentials from phishing, data breaches, and malware infections, reinforcing the need for heightened security measures.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
667
Cyber Attack
28 May 2026 • Elastic
OpenSearch, npm, ElasticSearch, Amazon Web Services and GitHub: Typosquatted npm Packages Steal Cloud and CI/CD Secrets
Sophisticated npm Supply Chain Attack Targets OpenSearch, ElasticSearch, and DevOps Tools
649
CRITICAL-18
ELAGITAMAOPENPM1780050263
Sophisticated npm Supply Chain Attack Targets OpenSearch, ElasticSearch, and DevOps Tools
A recently uncovered npm supply chain attack has targeted developers working with OpenSearch, ElasticSearch, and DevOps tooling, stealing cloud credentials and CI/CD secrets from compromised systems. The campaign, attributed to a threat actor using the alias vpmdhaj, involved 14 malicious packages published on May 28, 2026, within a four-hour window.
The attackers employed typosquatting and metadata spoofing, mimicking legitimate libraries with names like opensearch-setup and elastic-opensearch-helper while falsely linking to the official OpenSearch GitHub repository. To appear credible, the packages were assigned inflated version numbers, suggesting maturity and widespread use.
Upon installation, the malicious packages executed code via npm preinstall scripts, triggering automatically without user interaction. The attack employed a two-stage payload system:
- Early versions used a JavaScript stager to collect system details (hostname, OS, Node.js version, environment variables) and send them to a command-and-control (C2) server. The server responded with a compressed binary payload, identifiable by the “X-Supply: 1” HTTP header in network logs.
- Later variants improved stealth by eliminating direct C2 communication, instead downloading the Bun runtime from GitHub to execute an embedded second-stage payload. This reduced suspicious outbound traffic and evaded traditional detection.
The second-stage payload, a Bun-compiled binary, targeted credentials across multiple platforms, including:
- Amazon Web Services (AWS) – Extracting environment variables, querying EC2 Instance Metadata Service and ECS task metadata, and enumerating secrets in AWS Secrets Manager.
- HashiCorp Vault – Harvesting tokens.
- GitHub Actions & npm – Validating publish tokens to hijack package maintainers and propagate further supply chain attacks.
A persistence mechanism ensured the payload re-executed whenever the malicious module was imported, allowing it to survive across development cycles and CI/CD pipeline runs.
The impact of the campaign is severe:
- Stolen AWS credentials could enable lateral movement in cloud environments.
- Compromised CI/CD tokens may allow attackers to manipulate build pipelines or inject malicious code into production.
- Hijacked npm publish tokens pose a risk of malicious updates to legitimate packages, expanding the attack’s reach.
Following responsible disclosure, the malicious packages and associated accounts were removed from the npm registry. However, organizations that installed these dependencies remain at risk. Security teams are urged to audit systems for affected packages, rotate exposed credentials, and monitor for indicators of compromise, including the “X-Supply: 1” header and unusual CloudTrail activity.
The incident underscores the growing sophistication of supply chain attacks, where trusted ecosystems like npm are exploited to gain access to sensitive cloud and development infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
663
MARCH 2026
660
FEBRUARY 2026
657
JANUARY 2026
656
DECEMBER 2025
652
NOVEMBER 2025
651
OCTOBER 2025
648
SEPTEMBER 2025
646
JUNE 2025
776
Vulnerability
01 Jun 2025 • Elastic
Elastic
Elastic EDR Zero-Day Vulnerability Leading to BSOD and System Compromise
771
CRITICAL-5
ELA627081725
A critical zero-day vulnerability in Elastic’s Endpoint Detection and Response (EDR) solution—specifically in the elastic-endpoint-driver.sys kernel driver—allows attackers to bypass security, execute arbitrary code, and trigger Blue Screen of Death (BSOD) crashes, rendering systems unusable. The flaw stems from a NULL Pointer Dereference (CWE-476), enabling a four-stage attack chain: EDR bypass, Remote Code Execution (RCE), persistence via a malicious kernel driver, and privileged Denial-of-Service (DoS). The exploit turns Elastic’s own security tool into a weapon, risking large-scale endpoint disablement across enterprises. No patch exists for versions 8.17.6 and later, leaving customers exposed since disclosure attempts (June–August 2025). The vulnerability erodes trust in Elastic’s SIEM/EDR products, as a signed driver can now behave like malware, crashing systems on demand. Organizations face operational paralysis, potential data exposure during crashes, and loss of defensive capabilities until mitigation is deployed.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2025
634
Vulnerability
01 Mar 2025 • Elastic
Elastic
Critical Vulnerability in Kibana (CVE-2025-25012)
630
CRITICAL-4
ELA921030725
Elastic released a critical update to address a severe vulnerability in Kibana, identified as CVE-2025-25012. With a CVSS score of 9.9, the flaw allows for arbitrary code execution and primarily affects versions 8.15.0 to 8.17.2. The vulnerability, resulting from unsafe handling of prototype pollution, could be exploited by users with low privileges in earlier versions, and more advanced privileges in later versions. This security gap has the potential for severe consequences, such as unauthorized data access, system compromise, and service disruption, leading to theft or destruction of sensitive information. In response, Elastic urges users to upgrade to version 8.17.3 or later and recommends additional security measures for those unable to upgrade immediately.
INCIDENT DETAILS -
TYPE
REFERENCES
JANUARY 2025
778
Breach
01 Jan 2025 • Elastic
WeChat and Elasticsearch: Massive Data Leak Exposes 8.7 Billion Records From Hundreds of Millions of Chinese Individuals
Massive Chinese Data Leak Exposes 8.7 Billion Records in Unsecured Database
629
CRITICAL-149
TEAELA1770659583
Massive Chinese Data Leak Exposes 8.7 Billion Records in Unsecured Database
A significant data leak has exposed over 8.7 billion personal and business records, primarily affecting Chinese individuals. The unsecured Elasticsearch cluster, hosted on bulletproof infrastructure, remained accessible for three weeks before being secured, giving threat actors ample time to exfiltrate the data.
The exposed dataset included full names, phone numbers, national ID numbers, home addresses, email accounts, social media identifiers, and passwords many stored in plaintext or weakly protected. This sensitive information heightens risks of phishing, account takeovers, fraud, and identity theft, particularly for individuals who reuse passwords across services. Corporate data, such as company registration details and business contacts, was also compromised, enabling potential impersonation and targeted scams.
Security researchers suspect the leak was deliberate, given the data’s highly organized structure and storage on bulletproof infrastructure commonly used by high-risk entities. The records included up-to-date information from 2025, suggesting long-term aggregation rather than a historical breach. While the exact number of affected individuals remains unclear due to duplicated records, estimates place the impact in the hundreds of millions.
The incident underscores China’s ongoing struggle with large-scale data breaches, following previous leaks from major platforms like WeChat, Alipay, QQ, and Weibo, as well as government-linked entities. In September 2025, a separate breach exposed 500 GB of internal documents from China’s Great Firewall, while a 2022 Shanghai police leak compromised 23 terabytes of data for over a billion people. The identity of the threat actor behind this latest breach remains unknown, with no entity claiming responsibility.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Elastic ??
What was Elastic's A.I Rankiteo Cyber Score in July 2026 ??
What was Elastic's A.I Rankiteo Cyber Score in June 2026 ??
What was Elastic's A.I Rankiteo Cyber Score in May 2026 ??
What was Elastic's A.I Rankiteo Cyber Score in April 2026 ??
What was Elastic's A.I Rankiteo Cyber Score in March 2026 ??
What was Elastic's A.I Rankiteo Cyber Score in February 2026 ??
What was Elastic's A.I Rankiteo Cyber Score in January 2026 ??
What was Elastic's A.I Rankiteo Cyber Score in December 2025 ??
What was Elastic's A.I Rankiteo Cyber Score in November 2025 ??
What was Elastic's A.I Rankiteo Cyber Score in October 2025 ??
What was Elastic's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Elastic's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Elastic ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Elastic's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?