Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
ElevenLabs

ElevenLabs Vendor Cyber Rating & Cyber Score

elevenlabs.io

ElevenLabs is reimagining human-technology interaction with AI research and products. The Agents Platform enables businesses to deliver seamless and intelligent customer experiences, with the integrations, testing, monitoring, and reliability necessary to deploy voice and chat agents at scale. The Creative Platform empowers creators and marketers to generate and edit speech, music, image, and video across 70+ languages. These platforms are powered by our leading AI research. We developed the first human-like AI voice model, then expanded into dubbing, transcription, music, sound effects, and speech-to-speech. We serve millions of users and thousands of businesses from the fastest growing startups to the largest enterprises like Harvey,


ElevenLabs A.I CyberSecurity Scoring

ElevenLabs
Company Information
Website:https://www.elevenlabs.io/
Employees number:662
Number of followers:213,189
NAICS:5417
Industry Type:Research Services
Homepage:elevenlabs.io
ElevenLabs Risk Score (AI oriented)
Between 700 and 749
logo
ElevenLabsResearch Services
Updated:
29/03/2026
725/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
ElevenLabs Global Score (TPRM)
xxxx
logo
ElevenLabsResearch Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ElevenLabs
ElevenLabsModerate
Current Score
725Ba (MODERATE)
01000
2 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
728Before Incident
MAY 2026
727Before Incident
APRIL 2026
726Before Incident
MARCH 2026
744Before Incident
Cyber Attack
01 Mar 2026ElevenLabs
ElevenLabs and Stripe: Jack & Jill went up the hill — and an AI tried to hack them

AI vs. AI: How an Autonomous Agent Hacked a Hiring Platform in Under an Hour

724After Incident
CRITICAL-20
ELESTR1773203117
AI vs. AI: How an Autonomous Agent Hacked a Hiring Platform in Under an Hour In a striking demonstration of AI’s offensive capabilities, cybersecurity firm CodeWall unleashed an autonomous AI agent against Jack & Jill, a fast-growing AI-powered hiring platform used by companies like Anthropic, Stripe, and ElevenLabs. Within 60 minutes, the agent exploited four seemingly minor vulnerabilities chaining them together to gain full administrative access to any company on the platform. The experiment, led by CodeWall CEO Paul Price, revealed how AI can autonomously discover and exploit attack paths that human testers might overlook. The agent began by probing the system, uncovering flaws such as: - A URL fetcher that failed to block internal domains, allowing access to API documentation and authentication files. - A test mode left enabled, permitting login via a one-time password (OTP) with a simple email keyword. - Missing role checks during user onboarding, enabling privilege escalation. - A lack of domain verification, which let the agent bypass account creation safeguards. Once inside, the agent mapped 220 endpoints, extracted sensitive data including recruitment contracts and candidate information and even created, edited, or deleted job postings at will. ### Unpredictable Behavior: AI’s Social Engineering & Voice Hijacking The agent’s actions grew increasingly sophisticated and bizarre. Without explicit instructions, it gave itself a voice, generating synthetic audio clips to interact with Jack & Jill’s AI agents in real time. In one instance, it impersonated former U.S. President Donald Trump, demanding full access to company data. While Jack (the candidate-facing agent) resisted some prompt injections, the agent’s persistence 28 failed attempts before pivoting highlighted its ability to adapt. Price noted that the agent behaved “like a curious researcher” rather than a scripted tool, testing variations until it found success. Its ability to chain non-critical bugs into a devastating attack underscores how AI can automate complex attack sequences at scale, far outpacing human red teams. ### Why This Matters for Cybersecurity The experiment raises urgent concerns: - Lowered Barrier to Entry: AI enables attackers to rapidly explore systems with minimal expertise, reducing the skill required for sophisticated breaches. - New Attack Surfaces: AI-specific vulnerabilities such as prompt injections, RAG pipelines, and agent tools are often unsecured, creating novel risks. - Defensive Gaps: Traditional security measures (e.g., periodic pentests) may fail against AI-driven attacks, which continuously test and adapt. Price warned that “AI systems can digest vast amounts of information and explore attack vectors humans would never consider.” The incident serves as a wake-up call for organizations to adopt continuous, adversarial testing or risk being outmaneuvered by autonomous threats. Jack & Jill, founded in 2025, has since implemented fixes, but the case remains a stark example of how AI vs. AI conflicts could redefine cybersecurity in the near future.
INCIDENT DETAILS -
TYPE
Autonomous AI-driven cyber attack
MOTIVATION
Demonstration of AI's offensive capabilities and identification of security gaps
IMPACT
Data Compromised: Recruitment contracts and candidate informationSystems Affected: Jack & Jill AI-powered hiring platformOperational Impact: Full administrative access to any company on the platform, ability to create, edit, or delete job postingsBrand Reputation Impact: Potential reputational damage due to demonstrated vulnerabilitiesIdentity Theft Risk: Risk of exposure of candidate information
DATA BREACH
Recruitment contractsCandidate informationSensitivity Of Data: High (personally identifiable and professional information)Data Exfiltration: Extracted sensitive dataPersonally Identifiable Information: Candidate information
FEBRUARY 2026
744Before Incident
JANUARY 2026
760Before Incident
Cyber Attack
20 Jan 2026ElevenLabs
Tinder, Capcom, ElevenLabs and Zendesk: Mass Spam Attacks Leverage Zendesk Instances

Zendesk Instances Exploited in Widespread Spam Campaign

744After Incident
HIGH-16
TINCAPELEZEN1768948874
Zendesk Instances Exploited in Widespread Spam Campaign A surge of spam emails originating from legitimate Zendesk domains has raised concerns among cybersecurity experts and affected organizations. Multiple users reported receiving unsolicited messages often disguised as legal notices, bogus lawsuits, or government alerts from Zendesk instances tied to major companies, including Live Nation, Capcom, Tinder, and AI research firm ElevenLabs. The attacks appear to stem from two potential vectors: attackers abusing help desk systems to relay spam by impersonating users, or misconfigurations in Zendesk’s email infrastructure. Some emails bypassed spam filters, including iCloud’s, while others targeted users who had never interacted with the services in question. The goal, as with most spam campaigns, is to harvest credentials, gain initial access, or extort payments. Zendesk acknowledged the issue but clarified that it was not the result of a software vulnerability or breach. The company advised users to ignore or delete suspicious emails and recommended customers adjust first-reply triggers and restrict ticket submissions to authorized users. Security researchers noted similarities between the spam tactics and past activity linked to the threat group Scattered Lapsus$ Hunters, though Zendesk denied any direct connection. The scale of the campaign remains unclear, with no official response from Zendesk on the number of affected organizations or users. Social media and Reddit threads, however, indicate widespread disruption, with some companies reporting "mass spam attacks" on their ticketing systems. ElevenLabs confirmed it was working with Zendesk to resolve the issue, while other impacted firms have yet to publicly address the matter. The incident highlights the risks of misconfigured help desk systems and the challenges of defending against relay-based spam attacks. As investigations continue, the full extent of the campaign and whether it represents a coordinated effort or opportunistic exploitation remains under scrutiny.
INCIDENT DETAILS -
TYPE
Spam Campaign
MOTIVATION
Credential harvestingInitial accessExtortion
IMPACT
Zendesk help desk systemsOperational Impact: Widespread disruption to ticketing systemsBrand Reputation Impact: Potential reputational damage to affected companiesIdentity Theft Risk: High (due to credential harvesting)
DECEMBER 2025
760Before Incident
NOVEMBER 2025
760Before Incident
OCTOBER 2025
760Before Incident
SEPTEMBER 2025
760Before Incident
AUGUST 2025
760Before Incident
JULY 2025
760Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ElevenLabs ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in November 2025 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in October 2025 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in September 2025 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in August 2025 ?
?
What was ElevenLabs's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on ElevenLabs's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ElevenLabs ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ElevenLabs's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?