Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
FedEx

FedEx Vendor Cyber Rating & Cyber Score

fedex.com

FedEx connects people and possibilities through our worldwide portfolio of shipping, transportation, e-commerce and digital supply chain services. For decades, we’ve been innovating to deliver more for you. Strengthening supply chains with our global network. Simplifying logistics. Enhancing tracking and visibility. And using data from every journey to make your experience better. Our people are the foundation of our success, and FedEx has consistently ranked among the world’s most admired and trusted employers. We inspire our global workforce of more than 575,000 team members to remain absolutely, positively focused on safety, the highest ethical and professional standards, and the needs of their customers and communities. Day one: 186


FedEx A.I CyberSecurity Scoring

FedEx
Company Information
Website:http://careers.fedex.com
Employees number:196,814
Number of followers:2,470,203
NAICS:492
Industry Type:Freight and Package Transportation
Homepage:fedex.com
FedEx Risk Score (AI oriented)
Between 650 and 699
logo
FedExFreight and Package Transportation
Updated:
15/09/2026
688/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
FedEx Global Score (TPRM)
xxxx
logo
FedExFreight and Package Transportation
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

FedExWeak
Current Score
688B (WEAK)
01000
9 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
699Before Incident
Cyber Attack
07 Sep 2026FedEx
FedEx, Microsoft, Intuit QuickBooks and Google: Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

Large-Scale Phishing Campaign Abuses Google Services to Bypass Security Controls

688After Incident
CRITICAL-11
MICINTFEDGOO1788783925
Large-Scale Phishing Campaign Abuses Google Services to Bypass Security Controls A sophisticated phishing operation is leveraging trusted Google services including Google Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics to evade email security defenses and deliver highly personalized credential-harvesting pages. In some cases, the attack also deploys ScreenConnect, a legitimate remote-access tool, to establish persistent access to compromised systems. ### How the Attack Works The campaign exploits Google’s redirect and tracking infrastructure to mask malicious URLs behind legitimate domains, delaying exposure of the final phishing destination until after initial security scans. Attackers use multiple URL permutations, such as: - Google Meet’s `linkredirect` endpoint - Google Search and DoubleClick click-tracking URLs - Google Custom Search and regional Image Search domains - Tag Manager debug functionality and Analytics parameters Victims are lured with brand-impersonation emails mimicking DocuSign, Microsoft, OneDrive, FedEx, Intuit QuickBooks, and government services, exploiting routine business workflows. A key evasion tactic involves URL hash fragments containing the victim’s Base64-encoded email address, which remains hidden from server-side logs and many URL-scanning tools. After navigating the redirect chain, victims land on attacker-controlled `.vu` domains, compromised sites, or Cloudflare Workers endpoints. Some pages display fake CAPTCHAs or interstitial messages to thwart automated analysis. ### Personalized Phishing Pages & Credential Theft The phishing kit dynamically customizes pages using the victim’s email address, pulling: - Company logos (via Clearbit or Google’s favicon service) - Live screenshots of the target organization’s public website - Localized interfaces in 16 languages - Pre-filled email fields and browser tab titles matching the victim’s company The kit also profiles victims by collecting: - IP addresses & geolocation data - Browser fingerprints & language settings - MX records (to verify corporate email domains and filter out researchers/sandboxes) ### Two Monetization Paths 1. Credential Harvesting - Fake Microsoft 365 or OneDrive portals capture passwords, with some variants forcing a second password submission before redirecting to the real corporate site. - Stolen credentials, along with IP, location, and browser details, are exfiltrated to an attacker-controlled Telegram bot. 2. ScreenConnect Deployment - Fake document-access or identity-verification prompts install ScreenConnect, granting attackers persistent remote access bypassing MFA and password resets. ### Targeted Sectors & Lures The campaign focuses on manufacturing, government, finance, and non-profits, using lures such as: - Expired credentials (Microsoft 365) - FedEx delivery notifications - QuickBooks payment alerts - Social Security or voicemail messages ### Known Infrastructure & IOCs Security researchers have identified multiple malicious domains and endpoints, including: - `vazquezfleytas[.]com` (credential harvester) - `zh-l-haixing[.]com` (credential harvester) - `.vu` domains (e.g., `cloudbemismanufacturingcompanygroup[.]rydezyhrsysteminc[.]vu`) - Compromised sites (e.g., `odahlzr5lm[.]reliabilityinoperations[.]de`) - Malicious Cloudflare Workers endpoints The operation demonstrates how attackers abuse trusted cloud services to bypass security controls while delivering highly convincing, personalized phishing attacks.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Credential harvesting, persistent remote access, financial gain
IMPACT
Data Compromised: Credentials, IP addresses, geolocation data, browser fingerprints, MX recordsSystems Affected: Compromised systems via ScreenConnect remote-access toolOperational Impact: Potential unauthorized access to corporate systems, data exfiltrationBrand Reputation Impact: Potential damage due to brand impersonation (DocuSign, Microsoft, FedEx, etc.)Identity Theft Risk: High (stolen credentials, PII)
DATA BREACH
CredentialsIP addressesGeolocation dataBrowser fingerprintsMX recordsSensitivity Of Data: High (Personally Identifiable Information, corporate credentials)Data Exfiltration: Yes (to attacker-controlled Telegram bot)Personally Identifiable Information: Yes (email addresses, corporate credentials)
SEPTEMBER 2026
750Before Incident
Breach
01 Sep 2026FedEx
GameStop: NOLA tech company has grown steadily, now may be connected to identity theft data breach

New Orleans-Based Identity Verification Firm Linked to Massive Driver’s License Data Breach

699After Incident
CRITICAL-51
GAM1788546490
New Orleans-Based Identity Verification Firm Linked to Massive Driver’s License Data Breach A New Orleans tech company, founded in 2003 by Russian immigrants Denis Petrov and Andrey Stanovnov, has come under FBI scrutiny following reports that data from over 150 million U.S. and Canadian driver’s licenses was exposed for sale on the dark web. The firm, which specializes in identity verification for industries like hospitality, finance, and secure facility access, serves nearly 4,000 customers, including major brands such as Hertz, GameStop, AMC Theatres, and Shell. The company, which processes 22 million scans monthly across 30,000 North American locations, expanded from its early focus on age verification for bars and hotels to advanced fraud prevention services. Despite its growth generating tens of millions in annual revenue and employing 150 people globally its New Orleans headquarters remains at the LSU Research & Technology Park ("The Beach"). Cybersecurity journalist Brian Krebs first reported the potential breach, suggesting attackers may have been "siphoning" data from the firm’s systems. The FBI’s New Orleans Field Office confirmed an ongoing investigation but declined further comment. Company officials, including spokesperson Jillian Kossman, acknowledged the reports as part of their internal review but provided no additional details. The firm’s leadership has seen recent changes, with Mike Eckert, former CEO of The Weather Channel, serving as chairman. Petrov, one of the co-founders, has since left the company. The incident underscores the risks in the $14 billion global identity verification market, where sensitive government-issued documents are increasingly targeted by cybercriminals.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Over 150 million U.S. and Canadian driver’s licensesIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Driver’s licenses, personally identifiable informationNumber Of Records Exposed: Over 150 millionSensitivity Of Data: HighData Exfiltration: Data for sale on the dark webPersonally Identifiable Information: Driver’s license details
AUGUST 2026
750Before Incident
JULY 2026
750Before Incident
JUNE 2026
750Before Incident
Vulnerability
01 Jun 2026FedEx
LiteLLM: LiteLLM RCE Vulnerability Exploited in the Wild to Run Commands

Critical LiteLLM RCE Vulnerability Actively Exploited in the Wild

747After Incident
CRITICAL-3
LIT1781000708
Critical LiteLLM RCE Vulnerability Actively Exploited in the Wild Threat actors are actively exploiting a critical unauthenticated remote code execution (RCE) vulnerability in LiteLLM, a widely used open-source AI proxy gateway, by chaining two CVEs to bypass authentication and execute arbitrary commands on vulnerable systems. Researchers at Horizon3.ai confirmed the exploitation path on June 1, 2026, revealing that CVE-2026-42271 a command injection flaw in LiteLLM’s MCP server test endpoints can be combined with CVE-2026-48710, a Starlette "BadHost" Host Header validation bypass, to achieve unauthenticated RCE. The combined attack chain carries a CVSS score of 10.0 (Critical). ### Exploitation Details CVE-2026-42271 targets two LiteLLM MCP server endpoints: - `POST /mcp-rest/test/connection` - `POST /mcp-rest/test/tools/list` These endpoints allow attackers to supply malicious commands, arguments, and environment variables, which are then executed as subprocesses on the host. Initially, exploitation required a valid proxy API key, limiting its severity. However, CVE-2026-48710 affecting Starlette versions 1.0.0 and earlier enables attackers to manipulate Host header values, bypassing authentication entirely. When both vulnerabilities are present, threat actors can gain unauthenticated RCE on vulnerable LiteLLM deployments. ### Impact of Successful Exploitation A compromised LiteLLM instance grants attackers: - Arbitrary OS command execution on the host - Access to model provider credentials and API keys (e.g., OpenAI, Anthropic, Azure OpenAI) - Theft of stored secrets within the proxy - Lateral movement into connected AI infrastructure - Compromise of downstream systems integrated with the gateway Given LiteLLM’s role in enterprise AI pipelines, a breach could expose an organization’s entire AI operations layer. ### Affected Versions & Mitigation - Vulnerable: LiteLLM 1.74.2–1.83.6 + Starlette 1.0.0 or earlier - Patch: LiteLLM 1.83.7 (released May 8, 2026) introduces authorization controls and updates Starlette dependencies. Starlette should be upgraded to 1.0.1 or later. - Interim Mitigations: - Block external access to `/mcp-rest/test/connection` and `/mcp-rest/test/tools/list` - Restrict network access to trusted segments - Rotate all stored credentials and API keys - Monitor logs for unusual Host header values and unexpected subprocess execution Active exploitation makes this a high-priority patch for organizations running self-hosted LiteLLM instances.
INCIDENT DETAILS -
TYPE
Remote Code Execution (RCE)
IMPACT
Data Compromised: Model provider credentials, API keys, stored secrets, and downstream AI infrastructure dataSystems Affected: LiteLLM proxy gateway and connected AI systemsOperational Impact: Arbitrary OS command execution, lateral movement into AI infrastructure, compromise of downstream systems
DATA BREACH
Model provider credentialsAPI keysStored secretsSensitivity Of Data: High (AI infrastructure credentials and secrets)
MAY 2026
751Before Incident
Vulnerability
04 May 2026FedEx
Lovable, Base44, Replit, Netlify and FedEx: AI vibe-coding apps leak sensitive data

AI Coding Tools Expose Sensitive Data in Massive Security Oversight

748After Incident
CRITICAL-3
FEDLOVBASNETREP1778156932
AI Coding Tools Expose Sensitive Data in Massive Security Oversight Israeli cybersecurity firm RedAccess uncovered over 380,000 publicly accessible applications built using low-code and AI-powered tools from Lovable, Base44, Replit, and Netlify, including roughly 5,000 containing sensitive corporate and personal data. The findings, shared with Axios on Monday, highlight how employees without cybersecurity training are inadvertently exposing confidential information through misconfigured privacy settings. RedAccess CEO Dor Zvi revealed the apps were discovered while investigating "shadow AI" unauthorized use of AI tools by employees. Many applications were set to public by default, requiring manual adjustments to restrict access. Some exposed data included: - Medical records (doctor-patient conversations, clinical trial details, hospital staff schedules) - Financial data (internal bank records, customer service logs) - Corporate intelligence (shipping vessel routes, internal incident reports) - Phishing sites impersonating brands like Bank of America, FedEx, and McDonald’s Representatives from the affected platforms responded with mixed reactions. Base44 accused RedAccess of withholding URLs needed for verification, while Lovable acknowledged the reports but noted they lacked technical specifics to act immediately. Replit emphasized that users control app visibility, with CEO Amjad Masad stating RedAccess gave only 24 hours’ notice before public disclosure. Netlify did not respond to requests for comment. Security researchers confirmed that many exposed apps were indexed by Google, making them easily discoverable. Axios independently verified several cases, including: - A hospital app with unredacted patient complaints and staff schedules - A Brazilian bank’s internal financial records - A school app containing lesson recordings and student data The incident underscores how AI-driven "vibe coding" tools designed for non-technical users are enabling rapid, large-scale data exposure. As Zvi noted, the lack of built-in safeguards means even basic security oversights can lead to unintentional public leaks of critical information. Some exposed apps were taken down after companies were notified, but the broader issue of unauthorized AI tool usage in enterprises remains unaddressed.
INCIDENT DETAILS -
TYPE
Data Exposure
MOTIVATION
Unintentional exposure by employees
IMPACT
Data Compromised: Sensitive corporate and personal dataSystems Affected: 380,000+ applications built using Lovable, Base44, Replit, and NetlifyOperational Impact: Exposure of internal records and systemsBrand Reputation Impact: Potential brand reputation damage for affected entitiesLegal Liabilities: Potential legal liabilities due to data exposureIdentity Theft Risk: HighPayment Information Risk: High (for financial data exposed)
DATA BREACH
Medical recordsFinancial dataCorporate intelligencePhishing sitesInternal bank recordsCustomer service logsShipping vessel routesInternal incident reportsPatient complaintsStaff schedulesLesson recordingsStudent dataNumber Of Records Exposed: Roughly 5,000 applications with sensitive dataSensitivity Of Data: HighPersonally Identifiable Information: Yes
APRIL 2026
750Before Incident
MARCH 2026
748Before Incident
FEBRUARY 2026
747Before Incident
JANUARY 2026
746Before Incident
DECEMBER 2025
744Before Incident
NOVEMBER 2025
742Before Incident
OCTOBER 2025
740Before Incident
AUGUST 2025
796Before Incident
Ransomware
01 Aug 2025FedEx
Disney, FedEx and Toyota: Rogues gallery: 15 worst ransomware groups active today

Emerging and Evolving Ransomware Threats: A 2024–2025 Overview

734After Incident
CRITICAL-62
TOYTHEFED1773051888
Emerging and Evolving Ransomware Threats: A 2024–2025 Overview Recent years have seen a surge in sophisticated ransomware operations, with several groups refining tactics, expanding targets, and adapting to law enforcement disruptions. Below is a breakdown of the most active and evolving threats as of late 2024 and early 2025. ### LockBit: A Persistent Threat with Ties to Russia Once the most prolific ransomware-as-a-service (RaaS) operation, LockBit targeted thousands of victims worldwide, including government agencies, critical infrastructure, and private enterprises. Western law enforcement linked the group to Russian national Dmitry Yuryevich Khoroshev, indicted in 2023 alongside two other Russian affiliates. Despite crackdowns, LockBit’s infrastructure and tactics remain influential, with former affiliates migrating to newer RaaS platforms. ### Lynx: A Rebranded RaaS with Aggressive Tactics Emerging as a potential successor to the INC ransomware (sharing 48% of its code), Lynx operates a RaaS model and employs double extortion stealing data before encrypting files with the `.lynx` extension while deleting backups. Between July and November 2024, the group targeted U.S. and U.K. sectors, including energy, oil and gas, retail, and financial services. Despite claims of "ethical" victim selection, its rapid expansion suggests a calculated focus on high-value industries. ### Medusa: A Global RaaS Operation with Russian Links Active since 2022, Medusa exploits vulnerabilities in public-facing systems, phishing, and initial access brokers to breach organizations. Its victims span healthcare, education, manufacturing, and retail across the U.S., Europe, and India. While its core operators are suspected to be Russian-speaking, attribution remains unconfirmed. ### Play: A Low-Profile but High-Impact Threat First detected in June 2022, Play ransomware intensified operations following the disruption of other major groups. Unlike typical RaaS operations, Play avoids dark web advertising, claiming to be a "closed group" for secrecy. However, evidence suggests it collaborates with affiliates. Targets include healthcare, telecommunications, finance, and government services. In October 2024, researchers at Palo Alto Networks’ Unit 42 linked a Play ransomware deployment to North Korea’s APT45, highlighting potential state-sponsored cybercrime crossover. ### Qilin (Agenda): A Russia-Based RaaS with Growing Reach Operating since May 2022, Qilin targets Windows, Linux, and VMware ESXi servers using ransomware written in Golang and Rust. The group avoids attacks in CIS countries but aggressively recruits affiliates, leading to a five-fold increase in victim postings in the second half of 2025. Its rise is attributed to partnerships with initial access brokers, who supply stolen VPN credentials. ### RansomHub: A Rising RaaS with Affiliate-Friendly Terms Emerging in February 2024, RansomHub (formerly Cyclops/Knight) quickly became a dominant threat by recruiting affiliates from disrupted groups like LockBit and ALPHV/BlackCat. Its model offers affiliates a 10% fee or direct ransom collection, making it attractive to cybercriminals. With over 210 victims across healthcare, finance, government, and critical infrastructure in North America and Europe, RansomHub’s rapid growth underscores the resilience of the RaaS ecosystem. ### Scattered Lapsus$ Hunters: A Cybercrime Supergroup Formed in August 2025, this alliance merges Scattered Spider, LAPSUS$, and ShinyHunters, combining expertise in social engineering, help desk compromise, and ransomware deployment. The group ran a Salesforce campaign in August and October 2025, exposing data from Toyota, FedEx, and Disney. Though its leak site was seized in October 2025, the collective’s loose structure and technical sophistication suggest it remains a persistent threat. ### Key Trends - RaaS Dominance: Most groups operate under affiliate models, lowering the barrier for entry. - Double Extortion: Nearly all groups now steal data before encryption to increase leverage. - Geopolitical Ties: Many operations are linked to Russia or North Korea, though direct state sponsorship remains debated. - Rebranding & Adaptation: Disrupted groups often reemerge under new names (e.g., Lynx, RansomHub). - Critical Infrastructure Targeting: Energy, healthcare, and government sectors remain prime targets. As ransomware groups refine their tactics and expand their reach, the threat landscape continues to evolve, with law enforcement actions only temporarily slowing their operations.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortionCybercrime
IMPACT
Data Compromised: YesWindowsLinuxVMware ESXi servers
DATA BREACH
Personally identifiable informationCorporate dataSensitivity Of Data: HighData Exfiltration: YesData Encryption: YesPersonally Identifiable Information: Yes
JUNE 2022
780Before Incident
Cyber Attack
25 Jun 2022FedEx
FedEx, TNT Express and MGM Resorts: Are you ready for AI security threats? Time to act

AI-Powered Cyberattacks Escalation and Traditional Defense Failures

764After Incident
CRITICAL-16
FEDTNTICS1775472837
AI-Powered Cyberattacks Escalate: Why Traditional Defenses Are Failing AI is transforming cyber threats, making attacks faster, more deceptive, and far costlier with the average AI-enabled breach now exceeding $4.88 million in direct costs, excluding reputational damage or regulatory penalties. Yet the greatest risk isn’t the breach itself; it’s leadership unprepared for an era where attacks evolve in real time, bypass traditional defenses, and exploit human psychology. ### The New Threat Landscape AI-driven attacks are no longer hypothetical. In 2022, a deepfake video of Ukrainian President Volodymyr Zelensky falsely ordering troops to surrender spread rapidly online, demonstrating how easily synthetic media can manipulate public perception. Once requiring Hollywood-level resources, such tools now run on standard laptops, lowering the barrier for attackers while increasing the potential for widespread deception. The impact is already measurable. A 2026 IBM study found that AI-enabled cyberattacks contributed to a 44% rise in breaches targeting public-facing systems in just one year. These attacks don’t follow predictable patterns they learn, adapt, and exploit vulnerabilities autonomously, testing defenses without human intervention. Meanwhile, 77% of executives admit their organizations lack confidence in handling AI-driven threats, according to Accenture’s 2025 State of Cybersecurity Resilience report. ### Why Old Frameworks Fail Traditional risk models, like VUCA (volatile, uncertain, complex, ambiguous), no longer capture the realities of AI-driven threats. Instead, experts describe the current environment as BANI (brittle, anxious, nonlinear, incomprehensible) a paradigm where: - Brittle systems appear robust but collapse under stress (e.g., NotPetya’s 2017 attack, which crippled TNT Express in 40 minutes). - Anxious leaders freeze under pressure, deferring critical decisions due to information overload. - Nonlinear threats defy proportionality small errors (a stolen password, a misconfigured setting) trigger catastrophic failures. - Incomprehensible AI operates as a "black box," making it difficult to predict or govern. ### A New Playbook for Resilience To counter these challenges, organizations must adopt a proactive, adaptive approach. Key strategies include: 1. Assume Breach Is Inevitable - Deploy zero-trust architectures, network segmentation, and manual backups. - FedEx’s 2017 NotPetya response minimized losses through pre-rehearsed crisis protocols, while MGM Resorts’ 2023 ransomware attack triggered by a 10-minute social engineering call cost $100 million due to unprepared leadership. 2. Cultivate AI Fluency Across Leadership - Reverse mentoring programs can bridge knowledge gaps, ensuring executives understand AI’s risks and capabilities. - Hiring should prioritize adaptability over static skills. 3. Align AI Investments with Core Operations - Avoid "pilot purgatory" every AI initiative must tie to measurable business outcomes and resilience, not just growth. 4. Strengthen Governance - Establish cross-functional AI councils to oversee ethics, bias testing, and accountability. - Define clear responsibility for AI failures before incidents occur. ### Critical Questions for Leadership Boards and executives should assess readiness by asking: - Can the business operate for 48 hours without digital systems? - Have leaders completed meaningful AI security training (not just compliance checklists)? - Are AI deployments strengthening resilience, or creating new vulnerabilities? - Can teams make sound decisions without real-time data? The gap between AI’s capabilities and organizational preparedness is widening. The question is no longer if an attack will occur, but whether leaders are equipped to respond when it does.
INCIDENT DETAILS -
TYPE
AI-driven cyberattackDeepfake attackRansomwareSocial engineering
MOTIVATION
Financial gainPublic manipulationOperational disruption
IMPACT
Financial Loss: $4.88 million (average direct costs per breach)Public-facing systems44% rise in breaches targeting public-facing systems (2026 IBM study)Collapse of brittle systems under stress (e.g., NotPetya)Revenue Loss: $100 million (MGM Resorts 2023 ransomware attack)Public perception manipulation (e.g., deepfake of Ukrainian President Zelensky)
FEBRUARY 2018
738Before Incident
Data Leak
01 Feb 2018FedEx
FedEx

FedEx Data Exposure Incident

703After Incident
CRITICAL-35
FED10267622
FedEx has exposed private information belonging to thousands of its customers. It happened after a legacy server was left open without a password. Unencrypted private customer records that were exposed on the server.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Private customer recordsLegacy server
DATA BREACH
Private customer recordsData Encryption: Unencrypted
MAY 2017
785Before Incident
Ransomware
12 May 2017FedEx
FedEx: NHS seeks to recover from global cyber-attack as security concerns resurface

Global Ransomware Attack Disrupts NHS, Hospitals Across 100 Countries

717After Incident
CRITICAL-68
FED1781749923
Global Ransomware Attack Disrupts NHS, Hospitals Across 100 Countries A massive ransomware attack struck the UK’s National Health Service (NHS) and organizations worldwide on Friday, crippling hospital systems, canceling operations, and diverting ambulances. The attack, which exploited a Windows vulnerability, affected nearly 100 countries, with the NHS among the most severely impacted. The malware, identified as WanaCrypt0r 2.0 (or WannaCry), encrypted files on infected computers, demanding a $300 ransom in Bitcoin per machine. The attack leveraged a flaw in Microsoft Windows, for which a patch had been released in March but many systems, including those in the NHS, had not applied the update. Reports indicated that 90% of NHS trusts were still using Windows XP, an outdated operating system no longer supported by Microsoft. Impact on the NHS At least 40 NHS organizations in England and Scotland were hit, forcing staff to revert to pen-and-paper records and personal phones. Hospitals canceled non-emergency procedures, diverted ambulances, and struggled with inaccessible patient records and appointment systems. One NHS worker reported the attack began after an employee opened a malicious email attachment, suggesting a phishing vector. Global Reach Beyond the UK, the ransomware disrupted major companies, including Telefónica (Spain), FedEx (US), and organizations in Russia, Ukraine, and Taiwan. Cybersecurity firm Kaspersky Lab estimated 45,000 attacks across 99 countries, with Russia the hardest hit. Response and Recovery The National Cyber Security Centre (NCSC) and NHS Digital worked urgently to restore systems, though officials could not confirm whether patient data had been backed up. Home Secretary Amber Rudd acknowledged the need for software upgrades but did not verify backup protocols. Prime Minister Theresa May emphasized the attack was not NHS-targeted but part of a broader international campaign. Experts warned that recovery would be slow, requiring a full system wipe and reinstallation to prevent reinfection. The attack underscored long-standing concerns about the NHS’s outdated IT infrastructure, with critics noting that warnings of such an incident had been ignored. Authorities confirmed the attack was criminal in nature, not state-sponsored, and had no immediate national security implications. The ransomware’s rapid spread highlighted the risks of unpatched systems and the challenges of securing large, complex networks.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransom)
IMPACT
Data Compromised: Patient records, appointment systemsSystems Affected: Hospital IT systems, Windows-based computersDowntime: Non-emergency procedures canceled, ambulances divertedOperational Impact: Reverted to pen-and-paper records, inaccessible patient data, disrupted hospital operationsBrand Reputation Impact: Significant (criticism of outdated IT infrastructure)Identity Theft Risk: Potential (patient data exposure)
DATA BREACH
Type Of Data Compromised: Patient records, appointment dataSensitivity Of Data: High (personally identifiable information, medical data)Data Encryption: Yes (files encrypted by ransomware)Personally Identifiable Information: Yes (patient data)
SEPTEMBER 2013
821Before Incident
Ransomware
01 Sep 2013FedEx
FedEx and UPS: Cryptolocker ransomware: A look back at its widespread impact

Cryptolocker Ransomware Attack

735After Incident
CRITICAL-86
FEDUPS1788791163
Cryptolocker: The Ransomware That Redefined Cybersecurity Threats In 2013, a new strain of ransomware called Cryptolocker emerged, reshaping public awareness of digital extortion. Unlike earlier variants, Cryptolocker leveraged sophisticated social engineering tactics, spreading primarily through spam emails disguised as legitimate communications. Early campaigns used fake customer complaints, while later versions impersonated UPS and FedEx shipping alerts or flagged "problematic check transactions." These emails contained ZIP file attachments that, when opened, deployed a Trojan horse, infecting systems and linking them to a botnet. Once activated, Cryptolocker encrypted users' files, demanding ransom payments typically in bitcoin for decryption. By December 2013, the malware had infected an estimated 250,000 computers, with nearly half in the U.S., generating roughly $27 million in ransom payments. The following year, Operation Tovar, a coordinated multinational effort, disrupted the Gameover Zeus botnet a key infrastructure for Cryptolocker and dismantled its command servers. Despite the takedown, the suspected mastermind, Evgeniy Mikhailovich Bogachev, remains at large. Cryptolocker’s impact extended beyond financial losses, serving as a turning point in cybersecurity by demonstrating the scale and profitability of ransomware attacks. Its legacy persists as a cautionary example of how quickly digital threats can evolve and spread.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Financial Loss: $27 million in ransom paymentsData Compromised: Encrypted user filesSystems Affected: 250,000 computers
DATA BREACH
Type Of Data Compromised: User filesData Encryption: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for FedEx ?
?
What was FedEx's A.I Rankiteo Cyber Score in August 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in July 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in June 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in May 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in April 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in March 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in February 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in January 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in December 2025 ?
?
What was FedEx's A.I Rankiteo Cyber Score in November 2025 ?
?
What was FedEx's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on FedEx's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with FedEx ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view FedEx's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?