Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Fortune

Fortune Vendor Cyber Rating & Cyber Score

fortune.com

FORTUNE is a global media organization dedicated to helping its readers, viewers, and attendees succeed big in business through unrivaled access and best-in-class storytelling. We drive the conversation about business. With a global perspective, the guiding wisdom of history, and an unflinching eye to the future, we report and reveal the stories that matter today—and that will matter even more tomorrow. With the trusted power to convene and challenge those who are shaping industry, commerce and society around the world, FORTUNE lights the path for global leaders—and gives them the tools to make business better.


Fortune A.I CyberSecurity Scoring

Fortune
Company Information
Website:http://www.fortune.com
Employees number:2,986
Number of followers:2,044,954
NAICS:511
Industry Type:Book and Periodical Publishing
Homepage:fortune.com
Fortune Risk Score (AI oriented)
Between 650 and 699
logo
FortuneBook and Periodical Publishing
Updated:
17/06/2026
691/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Fortune Global Score (TPRM)
xxxx
logo
FortuneBook and Periodical Publishing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Fortune
FortuneWeak
Current Score
691B (WEAK)
01000
3 incidents
-48.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
691Before Incident
MAY 2026
688Before Incident
APRIL 2026
688Before Incident
MARCH 2026
776Before Incident
Ransomware
01 Mar 2026Fortune
Fortune 100 company: Perimeter Defense Isn’t Enough. MSSPs Need a Data Resilience Strategy

Ransomware Recovery Takes Center Stage as AI-Powered Attacks Outpace Prevention

683After Incident
CRITICAL-93
FOR1779481690
Ransomware Recovery Takes Center Stage as AI-Powered Attacks Outpace Prevention Managed Security Service Providers (MSSPs) are being urged to shift their focus from perimeter defense to rapid recovery as ransomware attacks grow more sophisticated. A 2026 report from Veeam reveals that 72% of companies never fully recover their data after an attack, underscoring the limitations of traditional prevention-only strategies. The rise of AI has democratized cyber threats, enabling attackers to exploit unknown vulnerabilities in operating systems and browsers with minimal resources. Instead of brute-force breaches, adversaries now log in using stolen credentials and leverage an organization’s own admin tools to delete data before detection. With global cybercrime damages projected to reach $12.2 trillion by 2031 and the average time from intrusion to containment at 241 days, businesses face prolonged exposure to undetected threats. The real business risk lies in downtime hospitals canceling appointments, small businesses halting operations, and enterprises facing multimillion-dollar recovery costs. Sophos reports the 2025 average ransomware payment at $1.2 million, but the larger financial and operational impact stems from prolonged outages. A Fortune 100 company’s recent incident demonstrated this disparity: two sites hit by the same attack had vastly different outcomes one recovered in minutes, the other in days due to architectural differences like immutable snapshots and separate recovery credentials. MSSPs are now being pushed to adopt an assumed-breach model, designing defenses under the premise that attackers are already inside. The focus shifts from preventing entry to limiting access and accelerating recovery. Key factors include: - Immutable backups that cannot be altered or deleted. - Separate control planes for recovery credentials, isolated from compromised admin accounts. - Rapid-restore architectures that minimize downtime to minutes rather than days. As attackers leverage AI to move faster, the data layer becomes the critical line of defense. MSSPs that prioritize recovery time objectives (RTOs) and active data management will define the next phase of cybersecurity resilience.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Financial Loss: Global cybercrime damages projected to reach $12.2 trillion by 2031Data Compromised: 72% of companies never fully recover their data after an attackDowntime: Prolonged outages (e.g., hospitals canceling appointments, small businesses halting operations)Operational Impact: Multimillion-dollar recovery costs; one site recovered in minutes, another in days
FEBRUARY 2026
776Before Incident
JANUARY 2026
779Before Incident
Vulnerability
16 Jan 2026Fortune
Fortune 500 organizations and Salesforce: Salesforce Marketing Cloud Vulnerability Exposes Email Data Risk

Salesforce Marketing Cloud Patches Critical Vulnerabilities Exposing Subscriber Data

775After Incident
CRITICAL-4
SALFOR1778063116
Salesforce Marketing Cloud Patches Critical Vulnerabilities Exposing Subscriber Data Salesforce recently addressed a series of high-severity vulnerabilities in its Marketing Cloud (SFMC) platform that could have allowed attackers to access and exfiltrate marketing emails, subscriber records, and engagement data across multiple tenants including Fortune 500 organizations. The flaws stemmed from weaknesses in SFMC’s server-side templating and encryption mechanisms. AMPScript and SSJS, used for dynamic email personalization, included functions like TreatAsContent that enabled template injection. Attackers could exploit this by embedding malicious payloads in user-controlled fields (e.g., name fields), which would execute during template evaluation. Once injected, built-in functions like LookupRows allowed queries against internal data views, exposing subscriber lists, sent emails, and tracking data. A more severe issue involved SFMC’s "view email in browser" and CloudPages features, which relied on encrypted query strings (qs parameters) to authenticate users. Researchers at Searchlight Cyber discovered that the older "classic" qs format used unauthenticated CBC encryption with a padding oracle vulnerability, enabling decryption and re-encryption of parameters. Additionally, a legacy XOR-based encryption scheme with a static key allowed rapid decryption of sensitive identifiers like JobID and ListSubscriber. Since SFMC reused a single static encryption key across tenants, attackers could forge qs tokens to access emails and subscriber data from other organizations. The vulnerabilities, reported on 16 January 2026, were mitigated between 21–24 January 2026. Salesforce migrated to AES-GCM encryption, rotated keys, disabled double evaluation of email subject templates, and invalidated all legacy tracking and CloudPages links created before 21 January 2026 (23:00 UTC). No confirmed malicious exploitation was reported. The incident underscores risks in shared SaaS infrastructure, where template engines and cryptographic flaws can expose high-value marketing data at scale. Salesforce assigned multiple CVEs to address broken encryption, hard-coded keys, and argument injection in MicrositeURL and CloudPages workflows.
INCIDENT DETAILS -
TYPE
Data BreachVulnerability Exploitation
IMPACT
Marketing emailsSubscriber recordsEngagement dataSalesforce Marketing Cloud (SFMC)
DATA BREACH
Marketing emailsSubscriber recordsEngagement dataSensitivity Of Data: High (subscriber data, tracking data)Data Exfiltration: PossibleBroken (CBC encryption with padding oracle)Legacy XOR-based encryption with static keyPersonally Identifiable Information: Subscriber records
DECEMBER 2025
779Before Incident
NOVEMBER 2025
778Before Incident
OCTOBER 2025
778Before Incident
SEPTEMBER 2025
778Before Incident
AUGUST 2025
777Before Incident
JULY 2025
777Before Incident
JUNE 2025
790Before Incident
Cyber Attack
17 Jun 2025Fortune
Fortune 100 companies: SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies

AI and Phishing-as-a-Service Fuel Surge in Sophisticated Enterprise Attacks

776After Incident
CRITICAL-14
FOR1781706487
AI and Phishing-as-a-Service Fuel Surge in Sophisticated Enterprise Attacks, SpyCloud Report Reveals Austin, TX – June 17, 2026 – A new report from SpyCloud, a leader in identity threat protection, underscores the rapid escalation of phishing attacks targeting enterprises, driven by artificial intelligence (AI) and phishing-as-a-service (PhaaS) platforms. The 2026 Phishing Pulse Report reveals that 78% of organizations with over 1,000 employees experienced a rise in phishing volume over the past year, while 84% report that AI-generated attacks are becoming more prevalent or harder to detect. The analysis found that phishing exposed employee data at 86% of Fortune 100 companies in the last 12 months, with technology firms facing the highest exposure, followed by the airline and automotive sectors. Despite awareness of the threat, many organizations remain ill-equipped to respond effectively. Only 38% are highly confident in detecting and mitigating credential theft within 24 hours, while 58% struggle to identify exposed credentials or session tokens post-incident. Remediation challenges persist, with 42% unable to scale responses and 68% requiring four hours or more to address confirmed exposures. SpyCloud’s research also highlights a shift in attacker tactics, with PhaaS platforms now five times more likely to target enterprise identities than malware up from three times in late 2025. Nearly half of recaptured PhaaS-sourced records are tied to corporate accounts, and tools like Tycoon 2FA show 80% of stolen credentials belong to enterprise email addresses. Beyond traditional phishing, organizations face growing threats from business email compromise (BEC), vendor impersonation, and adversary-in-the-middle (AiTM) techniques, including device code phishing, which exploits OAuth workflows for persistent access. Trevor Hilligoss, SpyCloud’s Chief Intelligence Officer, noted that attackers are increasingly capturing session cookies and refresh tokens, enabling prolonged access even after password resets. The report emphasizes a critical visibility gap: without clear insight into exposed credentials or tokens, attackers gain time to establish persistence, escalate privileges, or launch follow-on attacks like ransomware or session hijacking. Only 30% of organizations have fully integrated phishing detection with identity response workflows, leaving many vulnerable to prolonged breaches. The findings are based on a survey of security professionals and SpyCloud’s analysis of active phishing campaigns, darknet data, and criminal infrastructure. The company’s recaptured data including credentials, session cookies, and tokens helps enterprises identify and remediate exposures before they lead to further compromise.
INCIDENT DETAILS -
TYPE
phishingbusiness email compromise (BEC)vendor impersonationadversary-in-the-middle (AiTM)device code phishing
MOTIVATION
credential theftpersistent accessprivilege escalationransomwaresession hijacking
IMPACT
Data Compromised: employee data, credentials, session cookies, refresh tokensOperational Impact: prolonged breaches, privilege escalation, follow-on attacksIdentity Theft Risk: high
DATA BREACH
credentialssession cookiesrefresh tokensemployee dataSensitivity Of Data: highPersonally Identifiable Information: employee data

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Fortune ?
?
What was Fortune's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Fortune's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Fortune's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Fortune's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Fortune's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Fortune's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Fortune's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Fortune's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Fortune's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Fortune's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Fortune's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Fortune's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Fortune ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Fortune's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?