Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
The George Washington University

The George Washington University Vendor Cyber Rating & Cyber Score

gwu.edu

The George Washington University, an independent academic institution chartered by the Congress of the United States in 1821, dedicates itself to furthering human well-being. The University values a dynamic, student-focused community stimulated by cultural and intellectual diversity and built upon a foundation of integrity, creativity, and openness to the exploration of new ideas. The George Washington University, centered in the national and international crossroads of Washington, D.C., commits itself to excellence in the creation, dissemination, and application of knowledge. To promote the process of lifelong learning from both global and integrative perspectives, the University provides a stimulating intellectual environment for


GWU A.I CyberSecurity Scoring

GWU
Company Information
Website:http://www.gwu.edu
Employees number:11,815
Number of followers:350,917
NAICS:6113
Industry Type:Higher Education
Homepage:gwu.edu
GWU Risk Score (AI oriented)
Between 750 and 799
logo
GWUHigher Education
Updated:
02/04/2026
799/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
GWU Global Score (TPRM)
xxxx
logo
GWUHigher Education
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

GWUFair
Current Score
799Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
799Before Incident
AUGUST 2026
799Before Incident
JULY 2026
799Before Incident
JUNE 2026
799Before Incident
MAY 2026
799Before Incident
APRIL 2026
799Before Incident
MARCH 2026
799Before Incident
FEBRUARY 2026
799Before Incident
JANUARY 2026
799Before Incident
DECEMBER 2025
799Before Incident
NOVEMBER 2025
799Before Incident
OCTOBER 2025
799Before Incident
FEBRUARY 2020
799Before Incident
Vulnerability
01 Feb 2020GWU
Microsoft: Chinese State-Sponsored Contract Hacker Extradited to U.S. Over COVID-19 Research Cyberattacks – HSToday

Chinese National Extradited to U.S. for Cyber Intrusions Linked to HAFNIUM and COVID-19 Research Theft

780After Incident
CRITICAL-19
MIC1777372097
Chinese National Extradited to U.S. for Cyber Intrusions Linked to HAFNIUM and COVID-19 Research Theft A 34-year-old Chinese national, Xu Zewei (徐泽伟), was extradited to the U.S. over the weekend and appeared in federal court in Houston on a nine-count indictment for his role in state-sponsored cyber intrusions between February 2020 and June 2021. Xu, along with co-conspirator Zhang Yu (张宇), 44, is accused of participating in the HAFNIUM campaign a large-scale hacking operation that compromised thousands of systems worldwide, including U.S. organizations and targeting COVID-19 research during the pandemic. According to court documents, Xu’s activities were directed by officers of the PRC’s Ministry of State Security (MSS) Shanghai State Security Bureau (SSSB), China’s primary intelligence agency. At the time of the intrusions, Xu worked for Shanghai Powerock Network Co. Ltd., one of many Chinese "enabling" companies used by the PRC government to conduct cyber operations while obscuring its direct involvement. The indictment alleges that in early 2020, Xu and his co-conspirators hacked U.S. universities, immunologists, and virologists working on COVID-19 vaccines, treatments, and testing. On February 19, 2020, Xu confirmed to an SSSB officer that he had breached a Texas-based research university’s network. Days later, the officer instructed him to target specific email accounts belonging to researchers, which Xu later accessed and exfiltrated. From late 2020 into 2021, Xu and Zhang exploited vulnerabilities in Microsoft Exchange Server, a widely used email platform, as part of the HAFNIUM campaign. Microsoft publicly disclosed the state-sponsored attacks in March 2021, prompting the release of patches and detection tools. Despite mitigation efforts, hundreds of U.S. systems remained compromised. In April 2021, the U.S. Justice Department conducted a court-authorized operation to remove web shells installed by the hackers. By July 2021, the U.S. and its allies formally attributed the HAFNIUM campaign to the PRC’s MSS. Among the victims were a second Texas university and a global law firm, where Xu and Zhang installed web shells to maintain access and search for sensitive information. Their searches included terms like "Chinese sources," "MSS," and "HongKong," suggesting an interest in U.S. policy and intelligence-related data. The indictment highlights the PRC’s use of private contractors to conduct cyber espionage, allowing the government to distance itself from the operations. Xu faces charges including conspiracy to commit wire fraud, unauthorized access to protected computers, intentional damage to computer systems, and aggravated identity theft, with potential penalties totaling decades in prison. Zhang remains at large. The case is being investigated by the FBI’s Houston Field Office and prosecuted by the U.S. Attorney’s Office for the Southern District of Texas and the DOJ’s National Security Cyber Section. Xu’s extradition from Italy was secured with assistance from Italian law enforcement, including the Polizia Postale.
INCIDENT DETAILS -
TYPE
Cyber EspionageState-Sponsored Hacking
MOTIVATION
Intelligence gatheringTheft of COVID-19 researchPolicy and intelligence-related data
IMPACT
Data Compromised: Sensitive research data, email accounts, policy-related informationU.S. universitiesGlobal law firmResearch institutionsOperational Impact: Unauthorized access and data exfiltration from critical research and legal entitiesIdentity Theft Risk: Aggravated identity theft (charges included)
DATA BREACH
Research dataEmail accountsPolicy-related informationSensitivity Of Data: High (COVID-19 research, intelligence-related data)Personally Identifiable Information: Email accounts of researchers (potential PII)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for GWU ?
?
What was GWU's A.I Rankiteo Cyber Score in August 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in July 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in June 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in May 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in April 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in March 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in February 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in January 2026 ?
?
What was GWU's A.I Rankiteo Cyber Score in December 2025 ?
?
What was GWU's A.I Rankiteo Cyber Score in November 2025 ?
?
What was GWU's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on GWU's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with GWU ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view GWU's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
The George Washington University Cyber Scoring History | Rankiteo