ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

We are a grassroots people-to-people solidarity movement composed of campaigns and initiatives from different parts of the world, working together to end the illegal Israeli blockade of Gaza.

Freedom Flotilla Coalition (FFC) A.I CyberSecurity Scoring

FFC

Company Details

Linkedin ID:

freedom-flotilla-coalition-ffc

Employees number:

1

Number of followers:

1,320

NAICS:

8135

Industry Type:

Non-profit Organizations

Homepage:

freedomflotilla.org

IP Addresses:

0

Company ID:

FRE_1667355

Scan Status:

In-progress

AI scoreFFC Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/freedom-flotilla-coalition-ffc.jpeg
FFC Non-profit Organizations
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreFFC Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/freedom-flotilla-coalition-ffc.jpeg
FFC Non-profit Organizations
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

FFC Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Freedom Flotilla CoalitionCyber Attack2515/2025
Rankiteo Explanation :
Attack without any consequences

Description: In the early hours off Malta, a drone strike significantly damaged one of Freedom Flotilla Coalition’s humanitarian vessels. The attack, carried out in international waters, punctured the hull, allowing water to flood multiple compartments. Simultaneously, incendiary fragments ignited a fire near the bow, which the crew battled until local authorities dispatched a tug and an Armed Forces of Malta patrol vessel. Within an hour, firefighters brought the blaze under control, and all personnel were confirmed safe. Although there were no injuries or fatalities, the ship’s water ingress and structural damage forced the suspension of its Gaza-bound relief mission. Essential food, medicine, and dozens of activists on board were delayed, and the vessel now awaits inspection and repairs before it can resume operations. The incident has highlighted vulnerabilities in maritime humanitarian logistics and underscores the acute risks faced by nonviolent aid missions in contested waters. The Freedom Flotilla Coalition continues to call for international support to safeguard future journeys and ensure uninterrupted delivery of critical supplies to Gaza.

Freedom Flotilla Coalition
Cyber Attack
Severity: 25
Impact: 1
Seen: 5/2025
Blog:
Rankiteo Explanation
Attack without any consequences

Description: In the early hours off Malta, a drone strike significantly damaged one of Freedom Flotilla Coalition’s humanitarian vessels. The attack, carried out in international waters, punctured the hull, allowing water to flood multiple compartments. Simultaneously, incendiary fragments ignited a fire near the bow, which the crew battled until local authorities dispatched a tug and an Armed Forces of Malta patrol vessel. Within an hour, firefighters brought the blaze under control, and all personnel were confirmed safe. Although there were no injuries or fatalities, the ship’s water ingress and structural damage forced the suspension of its Gaza-bound relief mission. Essential food, medicine, and dozens of activists on board were delayed, and the vessel now awaits inspection and repairs before it can resume operations. The incident has highlighted vulnerabilities in maritime humanitarian logistics and underscores the acute risks faced by nonviolent aid missions in contested waters. The Freedom Flotilla Coalition continues to call for international support to safeguard future journeys and ensure uninterrupted delivery of critical supplies to Gaza.

Ailogo

FFC Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for FFC

Incidents vs Non-profit Organizations Industry Average (This Year)

Freedom Flotilla Coalition (FFC) has 40.85% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Freedom Flotilla Coalition (FFC) has 56.25% more incidents than the average of all companies with at least one recorded incident.

Incident Types FFC vs Non-profit Organizations Industry Avg (This Year)

Freedom Flotilla Coalition (FFC) reported 1 incidents this year: 1 cyber attacks, 0 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — FFC (X = Date, Y = Severity)

FFC cyber incidents detection timeline including parent company and subsidiaries

FFC Company Subsidiaries

SubsidiaryImage

We are a grassroots people-to-people solidarity movement composed of campaigns and initiatives from different parts of the world, working together to end the illegal Israeli blockade of Gaza.

Loading...
similarCompanies

FFC Similar Companies

American Red Cross

The American Red Cross prevents and alleviates human suffering in the face of emergencies by mobilizing the power of volunteers and the generosity of donors. Each day, thousands of people – people just like you – provide compassionate care to those in need. Our network of generous donors, voluntee

Save the Children International

Save the Children Save the Children is the world's leading independent organisation for children. We work in around 120 countries. Our vision is to live in a world in which every child attains the right to survival, protection, development and participation. Last year Save the Children's prog

AIESEC

AIESEC develops leadership among youth aged 18 to 30 and contributes to strengthening the global employability market by providing an end-to-end international talent recruitment solution for Enterprises, NGOs, and Start-ups. AIESEC is the world's largest youth-run organization developing the leader

IEEE is the world’s largest technical professional organization and is a public charity dedicated to advancing technological innovation and excellence for the benefit of humanity. IEEE and its members inspire a global community through its highly cited publications, conferences, technology standards

CASA DE LA FAMILIA

Casa de la Familia (CDLF) is a 501(c)(3) non-profit organization founded in 1996 by Clinical Psychologist Dr. Ana Nogales whose vision was to create an organization dedicated to ensuring long-lasting mental health success of children, youth, and families in response to psychological trauma. We prov

The Salvation Army

The Salvation Army is the nation's largest direct provider of social services. Annually, we help millions overcome poverty, addiction, and spiritual and economic hardships by preaching the gospel of Jesus Christ and meeting human needs in His name without discrimination in nearly every zip code.

Colsubsidio

Colsubsidio es una organización privada sin ánimo de lucro, que pertenece al Sistema de Protección y Seguridad Social, su evolución ha estado marcada tanto por el reconocimiento de las personas como seres integrales con necesidades dinámicas, múltiples e interdependientes, como por las transformacio

We support peace and prosperity by building connections, understanding and trust between people in the UK and countries worldwide. We uniquely combine the UK’s deep expertise in arts and culture, education and the English language, our global presence and relationships in over 100 countries, our un

World Vision

World Vision is the largest child-focused private charity in the world. Our 33,000+ staff members working in nearly 100 countries have united with our incredible supporters to impact the lives of over 200 million vulnerable children by tackling the root causes of poverty. Through World Vision every

newsone

FFC CyberSecurity News

October 08, 2025 07:00 AM
Gaza aid flotilla says Israeli forces intercepted its boats

Oct 8 (Reuters) - A group of vessels attempting to deliver aid to the war-ravaged Gaza Strip was intercepted by Israeli forces in...

October 07, 2025 07:00 AM
Israel intercepts Freedom Flotilla Coalition vessels en route to Gaza

The Freedom Flotilla Coalition (FFC) says the Israeli military attacked its convoy of boats and intercepted several vessels as they were...

October 05, 2025 07:00 AM
‘Our mission is to defy the illegal blockade’

Photographer-activist Shahidul Alam, the only Bangladeshi aboard the Gaza-bound Freedom Flotilla, said their mission is not to risk lives...

October 02, 2025 07:00 AM
Another international flotilla determined to reach Gaza despite risk of sabotage by Israel

KUALA LUMPUR: The joint humanitarian mission of the Freedom Flotilla Coalition and Thousand Madleens to Gaza (FFC x TMTG) which is currently...

July 29, 2025 07:00 AM
Handala aid ship activist abused upon arrival to Israeli prison: Freedom Flotilla Coalition

'When he reached the Israeli prison, U.S. human rights defender Chris Smalls was physically assaulted by seven uniformed individuals,' says...

June 09, 2025 07:00 AM
Israeli forces seize Gaza aid boat carrying Greta Thunberg

Israeli naval forces boarded and seized a charity vessel carrying Swedish activist Greta Thunberg, which had tried to break the naval blockade of the Gaza...

June 08, 2025 07:00 AM
Seized Gaza aid ship docks in Israel with Greta Thunberg aboard

(CNN) — The detained crew of the Gaza-bound aid ship that was intercepted by Israel on Monday morning docked in the Israeli port of Ashdod...

June 03, 2025 07:00 AM
Who’s on board the Madleen Gaza flotilla, and where has it reached so far?

The Madleen ship, launched by the Freedom Flotilla Coalition (FFC), is en route to Gaza, carrying humanitarian aid and human rights activists.

June 01, 2025 07:00 AM
Nonprofit ship sets sail for Gaza after drone attack setback

International nonprofit organisation Freedom Flotilla Coalition (FFC) said one of its vessels left the Italian port of Catania on Sunday,...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

FFC CyberSecurity History Information

Official Website of Freedom Flotilla Coalition (FFC)

The official website of Freedom Flotilla Coalition (FFC) is https://freedomflotilla.org/.

Freedom Flotilla Coalition (FFC)’s AI-Generated Cybersecurity Score

According to Rankiteo, Freedom Flotilla Coalition (FFC)’s AI-generated cybersecurity score is 735, reflecting their Moderate security posture.

How many security badges does Freedom Flotilla Coalition (FFC)’ have ?

According to Rankiteo, Freedom Flotilla Coalition (FFC) currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Freedom Flotilla Coalition (FFC) have SOC 2 Type 1 certification ?

According to Rankiteo, Freedom Flotilla Coalition (FFC) is not certified under SOC 2 Type 1.

Does Freedom Flotilla Coalition (FFC) have SOC 2 Type 2 certification ?

According to Rankiteo, Freedom Flotilla Coalition (FFC) does not hold a SOC 2 Type 2 certification.

Does Freedom Flotilla Coalition (FFC) comply with GDPR ?

According to Rankiteo, Freedom Flotilla Coalition (FFC) is not listed as GDPR compliant.

Does Freedom Flotilla Coalition (FFC) have PCI DSS certification ?

According to Rankiteo, Freedom Flotilla Coalition (FFC) does not currently maintain PCI DSS compliance.

Does Freedom Flotilla Coalition (FFC) comply with HIPAA ?

According to Rankiteo, Freedom Flotilla Coalition (FFC) is not compliant with HIPAA regulations.

Does Freedom Flotilla Coalition (FFC) have ISO 27001 certification ?

According to Rankiteo,Freedom Flotilla Coalition (FFC) is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Freedom Flotilla Coalition (FFC)

Freedom Flotilla Coalition (FFC) operates primarily in the Non-profit Organizations industry.

Number of Employees at Freedom Flotilla Coalition (FFC)

Freedom Flotilla Coalition (FFC) employs approximately 1 people worldwide.

Subsidiaries Owned by Freedom Flotilla Coalition (FFC)

Freedom Flotilla Coalition (FFC) presently has no subsidiaries across any sectors.

Freedom Flotilla Coalition (FFC)’s LinkedIn Followers

Freedom Flotilla Coalition (FFC)’s official LinkedIn profile has approximately 1,320 followers.

NAICS Classification of Freedom Flotilla Coalition (FFC)

Freedom Flotilla Coalition (FFC) is classified under the NAICS code 8135, which corresponds to Others.

Freedom Flotilla Coalition (FFC)’s Presence on Crunchbase

No, Freedom Flotilla Coalition (FFC) does not have a profile on Crunchbase.

Freedom Flotilla Coalition (FFC)’s Presence on LinkedIn

Yes, Freedom Flotilla Coalition (FFC) maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/freedom-flotilla-coalition-ffc.

Cybersecurity Incidents Involving Freedom Flotilla Coalition (FFC)

As of November 30, 2025, Rankiteo reports that Freedom Flotilla Coalition (FFC) has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

Freedom Flotilla Coalition (FFC) has an estimated 20,295 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Freedom Flotilla Coalition (FFC) ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.

How does Freedom Flotilla Coalition (FFC) detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with local authorities, third party assistance with armed forces of malta patrol vessel, and containment measures with firefighters brought the blaze under control, and remediation measures with vessel awaits inspection and repairs..

Incident Details

Can you provide details on each incident ?

Incident : Drone Strike

Title: Drone Strike on Humanitarian Vessel

Description: A drone strike significantly damaged one of Freedom Flotilla Coalition’s humanitarian vessels in international waters off Malta, causing structural damage and a fire.

Type: Drone Strike

Attack Vector: Drone

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : Drone Strike FRE300050225

Downtime: ['Suspension of Gaza-bound relief mission']

Operational Impact: Delay in delivery of essential food, medicine, and dozens of activists

Which entities were affected by each incident ?

Incident : Drone Strike FRE300050225

Entity Name: Freedom Flotilla Coalition

Entity Type: Non-profit Organization

Industry: Humanitarian Aid

Location: International Waters off Malta

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Drone Strike FRE300050225

Third Party Assistance: Local Authorities, Armed Forces Of Malta Patrol Vessel.

Containment Measures: Firefighters brought the blaze under control

Remediation Measures: Vessel awaits inspection and repairs

How does the company involve third-party assistance in incident response ?

Third-Party Assistance: The company involves third-party assistance in incident response through Local authorities, Armed Forces of Malta patrol vessel, .

Data Breach Information

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Vessel awaits inspection and repairs, .

How does the company handle incidents involving personally identifiable information (PII) ?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by firefighters brought the blaze under control and .

Lessons Learned and Recommendations

What lessons were learned from each incident ?

Incident : Drone Strike FRE300050225

Lessons Learned: Vulnerabilities in maritime humanitarian logistics, Acute risks faced by nonviolent aid missions in contested waters

What recommendations were made to prevent future incidents ?

Incident : Drone Strike FRE300050225

Recommendations: International support to safeguard future journeys, Ensure uninterrupted delivery of critical supplies to GazaInternational support to safeguard future journeys, Ensure uninterrupted delivery of critical supplies to Gaza

What are the key lessons learned from past incidents ?

Key Lessons Learned: The key lessons learned from past incidents are Vulnerabilities in maritime humanitarian logistics,Acute risks faced by nonviolent aid missions in contested waters.

Post-Incident Analysis

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Local Authorities, Armed Forces Of Malta Patrol Vessel, .

Additional Questions

Response to the Incidents

What third-party assistance was involved in the most recent incident ?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was local authorities, armed forces of malta patrol vessel, .

What containment measures were taken in the most recent incident ?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident was Firefighters brought the blaze under control.

Lessons Learned and Recommendations

What was the most significant lesson learned from past incidents ?

Most Significant Lesson Learned: The most significant lesson learned from past incidents was Acute risks faced by nonviolent aid missions in contested waters.

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was International support to safeguard future journeys and Ensure uninterrupted delivery of critical supplies to Gaza.

cve

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can lead to use of hard-coded cryptographic key . The physical device can be targeted for the attack. A high complexity level is associated with this attack. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 1.2
Severity: HIGH
AV:L/AC:H/Au:N/C:P/I:N/A:N
cvss3
Base: 2.0
Severity: HIGH
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
cvss4
Base: 1.0
Severity: HIGH
CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, without verifying whether the requester has permission to access the associated interview record. Because the server does not perform any recruitment-level authorization checks, an ESS-level user with no access to recruitment workflows can directly request interview attachment URLs and receive the corresponding files. This exposes confidential interview documents—including candidate CVs, evaluations, and supporting files—to unauthorized users. The issue arises from relying on predictable object identifiers and session presence rather than validating the user’s association with the relevant recruitment process. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. Even users restricted to ESS-level access, who have no permission to view the Recruitment module, can directly access candidate attachment URLs. When an authenticated request is made to the attachment endpoint, the system validates the session but does not confirm that the requesting user has the necessary recruitment permissions. As a result, any authenticated user can download CVs and other uploaded documents for arbitrary candidates by issuing direct requests to the attachment endpoint, leading to unauthorized exposure of sensitive applicant data. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a result, a disabled user, or an attacker using a compromised account, can continue to access protected pages and perform operations as long as a prior session remains active. Because the server performs no session revocation or session-store cleanup during these critical state changes, disabling an account or updating credentials has no effect on already-established sessions. This makes administrative disable actions ineffective and allows unauthorized users to retain full access even after an account is closed or a password is reset, exposing the system to prolonged unauthorized use and significantly increasing the impact of account takeover scenarios. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After obtaining a valid reset link for any account they can receive email for, an attacker can alter the username parameter in the final reset request to target a different user. Because the system accepts the supplied username without verification, the attacker can set a new password for any chosen account, including privileged accounts, resulting in full account takeover. This issue has been patched in version 5.8.

Risk Information
cvss4
Base: 8.7
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=freedom-flotilla-coalition-ffc' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge