Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
FedEx

FedEx Vendor Cyber Rating & Cyber Score

fedex.com

FedEx connects people and possibilities through our worldwide portfolio of shipping, transportation, e-commerce and digital supply chain services. For decades, we’ve been innovating to deliver more for you. Strengthening supply chains with our global network. Simplifying logistics. Enhancing tracking and visibility. And using data from every journey to make your experience better. Our people are the foundation of our success, and FedEx has consistently ranked among the world’s most admired and trusted employers. We inspire our global workforce of more than 575,000 team members to remain absolutely, positively focused on safety, the highest ethical and professional standards, and the needs of their customers and communities. Day one: 186


FedEx A.I CyberSecurity Scoring

FedEx
Company Information
Website:http://careers.fedex.com
Employees number:194,419
Number of followers:2,256,620
NAICS:492
Industry Type:Freight and Package Transportation
Homepage:fedex.com
FedEx Risk Score (AI oriented)
Between 750 and 799
logo
FedExFreight and Package Transportation
Updated:
01/07/2026
755/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
FedEx Global Score (TPRM)
xxxx
logo
FedExFreight and Package Transportation
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

FedEx
FedExFair
Current Score
755Baa (FAIR)
01000
5 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
755Before Incident
JULY 2026
755Before Incident
JUNE 2026
756Before Incident
MAY 2026
757Before Incident
Vulnerability
04 May 2026FedEx
Lovable, Base44, Replit, Netlify and FedEx: AI vibe-coding apps leak sensitive data

AI Coding Tools Expose Sensitive Data in Massive Security Oversight

754After Incident
CRITICAL-3
FEDLOVBASNETREP1778156932
AI Coding Tools Expose Sensitive Data in Massive Security Oversight Israeli cybersecurity firm RedAccess uncovered over 380,000 publicly accessible applications built using low-code and AI-powered tools from Lovable, Base44, Replit, and Netlify, including roughly 5,000 containing sensitive corporate and personal data. The findings, shared with Axios on Monday, highlight how employees without cybersecurity training are inadvertently exposing confidential information through misconfigured privacy settings. RedAccess CEO Dor Zvi revealed the apps were discovered while investigating "shadow AI" unauthorized use of AI tools by employees. Many applications were set to public by default, requiring manual adjustments to restrict access. Some exposed data included: - Medical records (doctor-patient conversations, clinical trial details, hospital staff schedules) - Financial data (internal bank records, customer service logs) - Corporate intelligence (shipping vessel routes, internal incident reports) - Phishing sites impersonating brands like Bank of America, FedEx, and McDonald’s Representatives from the affected platforms responded with mixed reactions. Base44 accused RedAccess of withholding URLs needed for verification, while Lovable acknowledged the reports but noted they lacked technical specifics to act immediately. Replit emphasized that users control app visibility, with CEO Amjad Masad stating RedAccess gave only 24 hours’ notice before public disclosure. Netlify did not respond to requests for comment. Security researchers confirmed that many exposed apps were indexed by Google, making them easily discoverable. Axios independently verified several cases, including: - A hospital app with unredacted patient complaints and staff schedules - A Brazilian bank’s internal financial records - A school app containing lesson recordings and student data The incident underscores how AI-driven "vibe coding" tools designed for non-technical users are enabling rapid, large-scale data exposure. As Zvi noted, the lack of built-in safeguards means even basic security oversights can lead to unintentional public leaks of critical information. Some exposed apps were taken down after companies were notified, but the broader issue of unauthorized AI tool usage in enterprises remains unaddressed.
INCIDENT DETAILS -
TYPE
Data Exposure
MOTIVATION
Unintentional exposure by employees
IMPACT
Data Compromised: Sensitive corporate and personal dataSystems Affected: 380,000+ applications built using Lovable, Base44, Replit, and NetlifyOperational Impact: Exposure of internal records and systemsBrand Reputation Impact: Potential brand reputation damage for affected entitiesLegal Liabilities: Potential legal liabilities due to data exposureIdentity Theft Risk: HighPayment Information Risk: High (for financial data exposed)
DATA BREACH
Medical recordsFinancial dataCorporate intelligencePhishing sitesInternal bank recordsCustomer service logsShipping vessel routesInternal incident reportsPatient complaintsStaff schedulesLesson recordingsStudent dataNumber Of Records Exposed: Roughly 5,000 applications with sensitive dataSensitivity Of Data: HighPersonally Identifiable Information: Yes
APRIL 2026
756Before Incident
MARCH 2026
755Before Incident
FEBRUARY 2026
754Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
751Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
748Before Incident
SEPTEMBER 2025
746Before Incident
AUGUST 2025
802Before Incident
Ransomware
01 Aug 2025FedEx
Disney, FedEx and Toyota: Rogues gallery: 15 worst ransomware groups active today

Emerging and Evolving Ransomware Threats: A 2024–2025 Overview

742After Incident
CRITICAL-60
TOYTHEFED1773051888
Emerging and Evolving Ransomware Threats: A 2024–2025 Overview Recent years have seen a surge in sophisticated ransomware operations, with several groups refining tactics, expanding targets, and adapting to law enforcement disruptions. Below is a breakdown of the most active and evolving threats as of late 2024 and early 2025. ### LockBit: A Persistent Threat with Ties to Russia Once the most prolific ransomware-as-a-service (RaaS) operation, LockBit targeted thousands of victims worldwide, including government agencies, critical infrastructure, and private enterprises. Western law enforcement linked the group to Russian national Dmitry Yuryevich Khoroshev, indicted in 2023 alongside two other Russian affiliates. Despite crackdowns, LockBit’s infrastructure and tactics remain influential, with former affiliates migrating to newer RaaS platforms. ### Lynx: A Rebranded RaaS with Aggressive Tactics Emerging as a potential successor to the INC ransomware (sharing 48% of its code), Lynx operates a RaaS model and employs double extortion stealing data before encrypting files with the `.lynx` extension while deleting backups. Between July and November 2024, the group targeted U.S. and U.K. sectors, including energy, oil and gas, retail, and financial services. Despite claims of "ethical" victim selection, its rapid expansion suggests a calculated focus on high-value industries. ### Medusa: A Global RaaS Operation with Russian Links Active since 2022, Medusa exploits vulnerabilities in public-facing systems, phishing, and initial access brokers to breach organizations. Its victims span healthcare, education, manufacturing, and retail across the U.S., Europe, and India. While its core operators are suspected to be Russian-speaking, attribution remains unconfirmed. ### Play: A Low-Profile but High-Impact Threat First detected in June 2022, Play ransomware intensified operations following the disruption of other major groups. Unlike typical RaaS operations, Play avoids dark web advertising, claiming to be a "closed group" for secrecy. However, evidence suggests it collaborates with affiliates. Targets include healthcare, telecommunications, finance, and government services. In October 2024, researchers at Palo Alto Networks’ Unit 42 linked a Play ransomware deployment to North Korea’s APT45, highlighting potential state-sponsored cybercrime crossover. ### Qilin (Agenda): A Russia-Based RaaS with Growing Reach Operating since May 2022, Qilin targets Windows, Linux, and VMware ESXi servers using ransomware written in Golang and Rust. The group avoids attacks in CIS countries but aggressively recruits affiliates, leading to a five-fold increase in victim postings in the second half of 2025. Its rise is attributed to partnerships with initial access brokers, who supply stolen VPN credentials. ### RansomHub: A Rising RaaS with Affiliate-Friendly Terms Emerging in February 2024, RansomHub (formerly Cyclops/Knight) quickly became a dominant threat by recruiting affiliates from disrupted groups like LockBit and ALPHV/BlackCat. Its model offers affiliates a 10% fee or direct ransom collection, making it attractive to cybercriminals. With over 210 victims across healthcare, finance, government, and critical infrastructure in North America and Europe, RansomHub’s rapid growth underscores the resilience of the RaaS ecosystem. ### Scattered Lapsus$ Hunters: A Cybercrime Supergroup Formed in August 2025, this alliance merges Scattered Spider, LAPSUS$, and ShinyHunters, combining expertise in social engineering, help desk compromise, and ransomware deployment. The group ran a Salesforce campaign in August and October 2025, exposing data from Toyota, FedEx, and Disney. Though its leak site was seized in October 2025, the collective’s loose structure and technical sophistication suggest it remains a persistent threat. ### Key Trends - RaaS Dominance: Most groups operate under affiliate models, lowering the barrier for entry. - Double Extortion: Nearly all groups now steal data before encryption to increase leverage. - Geopolitical Ties: Many operations are linked to Russia or North Korea, though direct state sponsorship remains debated. - Rebranding & Adaptation: Disrupted groups often reemerge under new names (e.g., Lynx, RansomHub). - Critical Infrastructure Targeting: Energy, healthcare, and government sectors remain prime targets. As ransomware groups refine their tactics and expand their reach, the threat landscape continues to evolve, with law enforcement actions only temporarily slowing their operations.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortionCybercrime
IMPACT
Data Compromised: YesWindowsLinuxVMware ESXi servers
DATA BREACH
Personally identifiable informationCorporate dataSensitivity Of Data: HighData Exfiltration: YesData Encryption: YesPersonally Identifiable Information: Yes
JUNE 2022
792Before Incident
Cyber Attack
25 Jun 2022FedEx
FedEx, TNT Express and MGM Resorts: Are you ready for AI security threats? Time to act

AI-Powered Cyberattacks Escalation and Traditional Defense Failures

776After Incident
CRITICAL-16
FEDTNTICS1775472837
AI-Powered Cyberattacks Escalate: Why Traditional Defenses Are Failing AI is transforming cyber threats, making attacks faster, more deceptive, and far costlier with the average AI-enabled breach now exceeding $4.88 million in direct costs, excluding reputational damage or regulatory penalties. Yet the greatest risk isn’t the breach itself; it’s leadership unprepared for an era where attacks evolve in real time, bypass traditional defenses, and exploit human psychology. ### The New Threat Landscape AI-driven attacks are no longer hypothetical. In 2022, a deepfake video of Ukrainian President Volodymyr Zelensky falsely ordering troops to surrender spread rapidly online, demonstrating how easily synthetic media can manipulate public perception. Once requiring Hollywood-level resources, such tools now run on standard laptops, lowering the barrier for attackers while increasing the potential for widespread deception. The impact is already measurable. A 2026 IBM study found that AI-enabled cyberattacks contributed to a 44% rise in breaches targeting public-facing systems in just one year. These attacks don’t follow predictable patterns they learn, adapt, and exploit vulnerabilities autonomously, testing defenses without human intervention. Meanwhile, 77% of executives admit their organizations lack confidence in handling AI-driven threats, according to Accenture’s 2025 State of Cybersecurity Resilience report. ### Why Old Frameworks Fail Traditional risk models, like VUCA (volatile, uncertain, complex, ambiguous), no longer capture the realities of AI-driven threats. Instead, experts describe the current environment as BANI (brittle, anxious, nonlinear, incomprehensible) a paradigm where: - Brittle systems appear robust but collapse under stress (e.g., NotPetya’s 2017 attack, which crippled TNT Express in 40 minutes). - Anxious leaders freeze under pressure, deferring critical decisions due to information overload. - Nonlinear threats defy proportionality small errors (a stolen password, a misconfigured setting) trigger catastrophic failures. - Incomprehensible AI operates as a "black box," making it difficult to predict or govern. ### A New Playbook for Resilience To counter these challenges, organizations must adopt a proactive, adaptive approach. Key strategies include: 1. Assume Breach Is Inevitable - Deploy zero-trust architectures, network segmentation, and manual backups. - FedEx’s 2017 NotPetya response minimized losses through pre-rehearsed crisis protocols, while MGM Resorts’ 2023 ransomware attack triggered by a 10-minute social engineering call cost $100 million due to unprepared leadership. 2. Cultivate AI Fluency Across Leadership - Reverse mentoring programs can bridge knowledge gaps, ensuring executives understand AI’s risks and capabilities. - Hiring should prioritize adaptability over static skills. 3. Align AI Investments with Core Operations - Avoid "pilot purgatory" every AI initiative must tie to measurable business outcomes and resilience, not just growth. 4. Strengthen Governance - Establish cross-functional AI councils to oversee ethics, bias testing, and accountability. - Define clear responsibility for AI failures before incidents occur. ### Critical Questions for Leadership Boards and executives should assess readiness by asking: - Can the business operate for 48 hours without digital systems? - Have leaders completed meaningful AI security training (not just compliance checklists)? - Are AI deployments strengthening resilience, or creating new vulnerabilities? - Can teams make sound decisions without real-time data? The gap between AI’s capabilities and organizational preparedness is widening. The question is no longer if an attack will occur, but whether leaders are equipped to respond when it does.
INCIDENT DETAILS -
TYPE
AI-driven cyberattackDeepfake attackRansomwareSocial engineering
MOTIVATION
Financial gainPublic manipulationOperational disruption
IMPACT
Financial Loss: $4.88 million (average direct costs per breach)Public-facing systems44% rise in breaches targeting public-facing systems (2026 IBM study)Collapse of brittle systems under stress (e.g., NotPetya)Revenue Loss: $100 million (MGM Resorts 2023 ransomware attack)Public perception manipulation (e.g., deepfake of Ukrainian President Zelensky)
FEBRUARY 2018
774Before Incident
Data Leak
01 Feb 2018FedEx
FedEx

FedEx Data Exposure Incident

739After Incident
CRITICAL-35
FED10267622
FedEx has exposed private information belonging to thousands of its customers. It happened after a legacy server was left open without a password. Unencrypted private customer records that were exposed on the server.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Private customer recordsLegacy server
DATA BREACH
Private customer recordsData Encryption: Unencrypted
MAY 2017
821Before Incident
Ransomware
12 May 2017FedEx
FedEx: NHS seeks to recover from global cyber-attack as security concerns resurface

Global Ransomware Attack Disrupts NHS, Hospitals Across 100 Countries

763After Incident
CRITICAL-58
FED1781749923
Global Ransomware Attack Disrupts NHS, Hospitals Across 100 Countries A massive ransomware attack struck the UK’s National Health Service (NHS) and organizations worldwide on Friday, crippling hospital systems, canceling operations, and diverting ambulances. The attack, which exploited a Windows vulnerability, affected nearly 100 countries, with the NHS among the most severely impacted. The malware, identified as WanaCrypt0r 2.0 (or WannaCry), encrypted files on infected computers, demanding a $300 ransom in Bitcoin per machine. The attack leveraged a flaw in Microsoft Windows, for which a patch had been released in March but many systems, including those in the NHS, had not applied the update. Reports indicated that 90% of NHS trusts were still using Windows XP, an outdated operating system no longer supported by Microsoft. Impact on the NHS At least 40 NHS organizations in England and Scotland were hit, forcing staff to revert to pen-and-paper records and personal phones. Hospitals canceled non-emergency procedures, diverted ambulances, and struggled with inaccessible patient records and appointment systems. One NHS worker reported the attack began after an employee opened a malicious email attachment, suggesting a phishing vector. Global Reach Beyond the UK, the ransomware disrupted major companies, including Telefónica (Spain), FedEx (US), and organizations in Russia, Ukraine, and Taiwan. Cybersecurity firm Kaspersky Lab estimated 45,000 attacks across 99 countries, with Russia the hardest hit. Response and Recovery The National Cyber Security Centre (NCSC) and NHS Digital worked urgently to restore systems, though officials could not confirm whether patient data had been backed up. Home Secretary Amber Rudd acknowledged the need for software upgrades but did not verify backup protocols. Prime Minister Theresa May emphasized the attack was not NHS-targeted but part of a broader international campaign. Experts warned that recovery would be slow, requiring a full system wipe and reinstallation to prevent reinfection. The attack underscored long-standing concerns about the NHS’s outdated IT infrastructure, with critics noting that warnings of such an incident had been ignored. Authorities confirmed the attack was criminal in nature, not state-sponsored, and had no immediate national security implications. The ransomware’s rapid spread highlighted the risks of unpatched systems and the challenges of securing large, complex networks.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransom)
IMPACT
Data Compromised: Patient records, appointment systemsSystems Affected: Hospital IT systems, Windows-based computersDowntime: Non-emergency procedures canceled, ambulances divertedOperational Impact: Reverted to pen-and-paper records, inaccessible patient data, disrupted hospital operationsBrand Reputation Impact: Significant (criticism of outdated IT infrastructure)Identity Theft Risk: Potential (patient data exposure)
DATA BREACH
Type Of Data Compromised: Patient records, appointment dataSensitivity Of Data: High (personally identifiable information, medical data)Data Encryption: Yes (files encrypted by ransomware)Personally Identifiable Information: Yes (patient data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for FedEx ?
?
What was FedEx's A.I Rankiteo Cyber Score in July 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in June 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in May 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in April 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in March 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in February 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in January 2026 ?
?
What was FedEx's A.I Rankiteo Cyber Score in December 2025 ?
?
What was FedEx's A.I Rankiteo Cyber Score in November 2025 ?
?
What was FedEx's A.I Rankiteo Cyber Score in October 2025 ?
?
What was FedEx's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on FedEx's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with FedEx ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view FedEx's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?