ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Habib Bank AG Zurich was established in Switzerland in 1967, and has grown into a global institution with a presence in 11 countries spanning across four continents. Over the past six decades, we have expanded internationally, combining modern technology with timeless values. Habib Bank AG Zurich has a head office in Zurich, and operates with branches in Kenya and the United Arab Emirates. It has subsidiaries in Canada, Hong Kong, Pakistan, South Africa, and the United Kingdom, and representative offices in Bangladesh, China, Hong Kong, Pakistan, and Türkiye. Our Core Business: * Commercial & Corporate Banking * Personal Banking Our Key Business Lines: * Trade Finance * Islamic Banking * Wealth Management

Habib Bank AG Zurich A.I CyberSecurity Scoring

HBAZ

Company Details

Linkedin ID:

habib-bank-ag-zurich

Employees number:

1,630

Number of followers:

41,794

NAICS:

52211

Industry Type:

Banking

Homepage:

http://www.habibbank.com

IP Addresses:

0

Company ID:

HAB_1045029

Scan Status:

In-progress

AI scoreHBAZ Risk Score (AI oriented)

Between 0 and 549

https://images.rankiteo.com/companyimages/habib-bank-ag-zurich.jpeg
HBAZ Banking
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreHBAZ Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/habib-bank-ag-zurich.jpeg
HBAZ Banking
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

HBAZ Company CyberSecurity News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Habib Bank AG ZurichRansomware10056/2025
Rankiteo Explanation :
Attack threatening the organization's existence

Description: Habib Bank AG Zurich, a prominent financial institution based in Switzerland, suffered a severe **ransomware attack** orchestrated by the cybercriminal group **Qilin** on **November 5, 2025**. The breach was detected within minutes of its execution, highlighting the bank’s exposure to advanced persistent threats. While the exact extent of data compromise remains undisclosed, ransomware attacks typically involve encryption of critical systems and exfiltration of sensitive financial, customer, or employee data for extortion purposes.Given the bank’s sector (**financial services**), the incident likely disrupted operations, risked exposure of confidential client information (e.g., account details, transaction records, or personal identifiers), and posed significant reputational and regulatory repercussions. Ransomware groups like Qilin are known for double-extortion tactics—demanding payment not only for decryption keys but also to prevent public leakage of stolen data. The attack underscores systemic vulnerabilities in the bank’s cybersecurity defenses, potentially eroding trust among customers, investors, and regulatory bodies.The financial sector’s high-value targets make such breaches particularly damaging, with potential cascading effects on market stability, compliance penalties (e.g., GDPR or Swiss FADP violations), and long-term operational costs for recovery and remediation. The incident serves as a stark reminder of the escalating sophistication of cyber threats in 2025, necessitating robust proactive measures like phishing simulations, real-time breach monitoring, and employee training to mitigate future risks.

Habib Bank AG ZurichRansomware100511/2025
Rankiteo Explanation :
Attack threatening the organization’s existence

Description: Habib Bank AG Zurich confirmed unauthorized external access to its corporate network by the **Qilin ransomware gang**, which claimed to have stolen **2.56 TB of data** and listed the bank on its leak site on **November 5, 2025**. While the bank stated that **banking services remained operational** and no persistent access was detected, the extent of data exposure is still under investigation. Qilin, a Russia-based **ransomware-as-a-service (RaaS)** group, typically infiltrates victims via **phishing emails** and has a history of targeting financial institutions. The bank has not verified Qilin’s theft claims, nor disclosed whether a ransom was paid. With **8,000 employees** and **500+ global offices**, the breach poses significant risks, including potential **financial fraud, reputational damage, and regulatory scrutiny**. The incident aligns with Qilin’s 2025 rampage, which included **31 confirmed attacks on financial firms**, some stemming from a supply-chain breach via a South Korean IT provider. The bank is conducting a forensic investigation with cybersecurity experts to assess the impact and mitigate further risks.

Habib Bank AG Zurich
Ransomware
Severity: 100
Impact: 5
Seen: 6/2025
Blog:
Rankiteo Explanation
Attack threatening the organization's existence

Description: Habib Bank AG Zurich, a prominent financial institution based in Switzerland, suffered a severe **ransomware attack** orchestrated by the cybercriminal group **Qilin** on **November 5, 2025**. The breach was detected within minutes of its execution, highlighting the bank’s exposure to advanced persistent threats. While the exact extent of data compromise remains undisclosed, ransomware attacks typically involve encryption of critical systems and exfiltration of sensitive financial, customer, or employee data for extortion purposes.Given the bank’s sector (**financial services**), the incident likely disrupted operations, risked exposure of confidential client information (e.g., account details, transaction records, or personal identifiers), and posed significant reputational and regulatory repercussions. Ransomware groups like Qilin are known for double-extortion tactics—demanding payment not only for decryption keys but also to prevent public leakage of stolen data. The attack underscores systemic vulnerabilities in the bank’s cybersecurity defenses, potentially eroding trust among customers, investors, and regulatory bodies.The financial sector’s high-value targets make such breaches particularly damaging, with potential cascading effects on market stability, compliance penalties (e.g., GDPR or Swiss FADP violations), and long-term operational costs for recovery and remediation. The incident serves as a stark reminder of the escalating sophistication of cyber threats in 2025, necessitating robust proactive measures like phishing simulations, real-time breach monitoring, and employee training to mitigate future risks.

Habib Bank AG Zurich
Ransomware
Severity: 100
Impact: 5
Seen: 11/2025
Blog:
Rankiteo Explanation
Attack threatening the organization’s existence

Description: Habib Bank AG Zurich confirmed unauthorized external access to its corporate network by the **Qilin ransomware gang**, which claimed to have stolen **2.56 TB of data** and listed the bank on its leak site on **November 5, 2025**. While the bank stated that **banking services remained operational** and no persistent access was detected, the extent of data exposure is still under investigation. Qilin, a Russia-based **ransomware-as-a-service (RaaS)** group, typically infiltrates victims via **phishing emails** and has a history of targeting financial institutions. The bank has not verified Qilin’s theft claims, nor disclosed whether a ransom was paid. With **8,000 employees** and **500+ global offices**, the breach poses significant risks, including potential **financial fraud, reputational damage, and regulatory scrutiny**. The incident aligns with Qilin’s 2025 rampage, which included **31 confirmed attacks on financial firms**, some stemming from a supply-chain breach via a South Korean IT provider. The bank is conducting a forensic investigation with cybersecurity experts to assess the impact and mitigate further risks.

Ailogo

HBAZ Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for HBAZ

Incidents vs Banking Industry Average (This Year)

Habib Bank AG Zurich has 124.72% more incidents than the average of same-industry companies with at least one recorded incident.

Incidents vs All-Companies Average (This Year)

Habib Bank AG Zurich has 212.5% more incidents than the average of all companies with at least one recorded incident.

Incident Types HBAZ vs Banking Industry Avg (This Year)

Habib Bank AG Zurich reported 2 incidents this year: 0 cyber attacks, 2 ransomware, 0 vulnerabilities, 0 data breaches, compared to industry peers with at least 1 incident.

Incident History — HBAZ (X = Date, Y = Severity)

HBAZ cyber incidents detection timeline including parent company and subsidiaries

HBAZ Company Subsidiaries

SubsidiaryImage

Habib Bank AG Zurich was established in Switzerland in 1967, and has grown into a global institution with a presence in 11 countries spanning across four continents. Over the past six decades, we have expanded internationally, combining modern technology with timeless values. Habib Bank AG Zurich has a head office in Zurich, and operates with branches in Kenya and the United Arab Emirates. It has subsidiaries in Canada, Hong Kong, Pakistan, South Africa, and the United Kingdom, and representative offices in Bangladesh, China, Hong Kong, Pakistan, and Türkiye. Our Core Business: * Commercial & Corporate Banking * Personal Banking Our Key Business Lines: * Trade Finance * Islamic Banking * Wealth Management

Loading...
similarCompanies

HBAZ Similar Companies

Kotak Mahindra Bank

About Kotak Mahindra Group: Established in 1985, the Kotak Mahindra Group is one of India’s leading financial services conglomerates. In February 2003, Kotak Mahindra Finance Ltd. (KMFL), the Group’s flagship company, received a banking license from the Reserve Bank of India (RBI). With this, KMF

Crédit Agricole CIB

Crédit Agricole CIB is the corporate and investment banking arm of Crédit Agricole Group, 9th largest banking group worldwide in terms of balance sheet size in 2023 (The Banker, July 2024). Nearly 8,600 employees across Europe, the Americas, Asia-Pacific, the Middle East and North Africa support Cr

DenizBank

In 1997, DenizBank was acquired by the Zorlu Holding in the form of a banking license from the Privatization Administration. Undergoing three shareholder changes and done public offering in its short history, the Bank was acquired in October 2006 by Dexia, one of the leading financial groups of Euro

Standard Chartered

We are a leading international banking group, with a presence in 54 of the world’s most dynamic markets. Our purpose is to drive commerce and prosperity through our unique diversity, and our heritage and values are expressed in our brand promise, here for good. If you’re interested joining Standar

Banco de Crédito BCP

Somos el banco peruano que desde hace más de 130 años viene liderando el sistema financiero a nivel nacional. A lo largo de todo este tiempo hemos contribuido con el desarrollo económico de nuestro país, transformando planes en realidad. Todo esto es posible gracias al equipo de profesionales de p

Crédit Agricole Personal Finance & Mobility

A major consumer credit provider in Europe, Crédit Agricole Consumer Finance operates in 19 countries. Its 9,900 employees support customers by providing the financing they need to undertake their projects. Reflecting the essential social and economic role of consumer credit, Crédit Agricole Consu

Nordea

We are a universal bank with a 200-year history of supporting and growing the Nordic economies – enabling dreams and aspirations for a greater good. Every day, we work to support our customers’ financial development, delivering best-in-class omnichannel customer experiences and driving sustainable c

We’re here to do Right By You. At UOB, we aspire to build a better future for the people and businesses in the region. Through our extensive network and suite of capabilities, we offer financial solutions to the people and businesses within, and connecting with ASEAN. We create solutions tail

Royal Bank of Canada is a global financial institution with a purpose-driven, principles-led approach to delivering leading performance. Our success comes from the 94,000+ employees who leverage their imaginations and insights to bring our vision, values and strategy to life so we can help our clien

newsone

HBAZ CyberSecurity News

November 08, 2025 08:00 AM
Russian hackers attack Swiss bank

A Russian hacker group has attacked Habib Bank AG in Zurich and stolen sensitive customer data. The bank is working intensively to clarify...

November 06, 2025 03:52 PM
Qilin Ransomware gang steals 2.5TB data from Swiss Bank

Qilin Ransomware group, a highly organized and increasingly notorious hacking collective, has reportedly compromised the servers of Habib Bank AG Zurich,...

November 05, 2025 08:00 AM
Russian hackers say they robbed a Swiss bank, stealing 2.5TB of data

Russian hackers claim to have breached Swiss bank Habib Bank AG Zurich, stealing 2.5TB of data, including customer records and internal...

August 15, 2025 07:00 AM
News - WestJet Confirms Customer Data Breach Exposing Sensitive Personal Information

Canadian airline WestJet said the data security incident it suffered earlier this year compromised the sensitive personal data of its...

July 03, 2025 07:00 AM
News - Qantas confirms data breach exposing personal details of 6 million people

Australian airlines Qantas said that a data breach at one of its service providers has compromised the personal information of over 6...

June 29, 2025 07:00 AM
News - Hawaiian Airlines investigates data security breach impacting essential IT systems

Hawaiian Airlines said it is investigating a recent data security incident that has affected the airline's essential IT systems, critical for its daily...

June 26, 2025 07:00 AM
News - Cyberattack on Arkansas health center compromises data of over 100,000

Last year's data security incident at Arkansas-based Mainline Health Center compromised the sensitive personal information belonging to more...

June 20, 2025 07:00 AM
News - Kettering Health back online following cyber security crisis

Nearly a month after suffering a significant cyber attack, Kettering Health has finally restored its affected systems and resumed normal...

April 28, 2025 07:00 AM
News - Spanish water utility Aigües de Mataró confirms a major customer data breach

Spanish water supplier Aigües de Mataró said it suffered a significant data security incident that compromised the sensitive personal information of its...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

HBAZ CyberSecurity History Information

Official Website of Habib Bank AG Zurich

The official website of Habib Bank AG Zurich is http://www.habibbank.com.

Habib Bank AG Zurich’s AI-Generated Cybersecurity Score

According to Rankiteo, Habib Bank AG Zurich’s AI-generated cybersecurity score is 488, reflecting their Critical security posture.

How many security badges does Habib Bank AG Zurich’ have ?

According to Rankiteo, Habib Bank AG Zurich currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Habib Bank AG Zurich have SOC 2 Type 1 certification ?

According to Rankiteo, Habib Bank AG Zurich is not certified under SOC 2 Type 1.

Does Habib Bank AG Zurich have SOC 2 Type 2 certification ?

According to Rankiteo, Habib Bank AG Zurich does not hold a SOC 2 Type 2 certification.

Does Habib Bank AG Zurich comply with GDPR ?

According to Rankiteo, Habib Bank AG Zurich is not listed as GDPR compliant.

Does Habib Bank AG Zurich have PCI DSS certification ?

According to Rankiteo, Habib Bank AG Zurich does not currently maintain PCI DSS compliance.

Does Habib Bank AG Zurich comply with HIPAA ?

According to Rankiteo, Habib Bank AG Zurich is not compliant with HIPAA regulations.

Does Habib Bank AG Zurich have ISO 27001 certification ?

According to Rankiteo,Habib Bank AG Zurich is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Habib Bank AG Zurich

Habib Bank AG Zurich operates primarily in the Banking industry.

Number of Employees at Habib Bank AG Zurich

Habib Bank AG Zurich employs approximately 1,630 people worldwide.

Subsidiaries Owned by Habib Bank AG Zurich

Habib Bank AG Zurich presently has no subsidiaries across any sectors.

Habib Bank AG Zurich’s LinkedIn Followers

Habib Bank AG Zurich’s official LinkedIn profile has approximately 41,794 followers.

NAICS Classification of Habib Bank AG Zurich

Habib Bank AG Zurich is classified under the NAICS code 52211, which corresponds to Commercial Banking.

Habib Bank AG Zurich’s Presence on Crunchbase

No, Habib Bank AG Zurich does not have a profile on Crunchbase.

Habib Bank AG Zurich’s Presence on LinkedIn

Yes, Habib Bank AG Zurich maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/habib-bank-ag-zurich.

Cybersecurity Incidents Involving Habib Bank AG Zurich

As of December 04, 2025, Rankiteo reports that Habib Bank AG Zurich has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Habib Bank AG Zurich has an estimated 6,799 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Habib Bank AG Zurich ?

Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.

How does Habib Bank AG Zurich detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with cybersecurity experts, third party assistance with forensic experts, and remediation measures with ongoing investigation to assess and mitigate impact, and communication strategy with public notice posted on the bank’s website..

Incident Details

Can you provide details on each incident ?

Incident : ransomware

Title: Ransomware Attack on Habib Bank AG Zurich by Qilin Group

Description: Habib Bank AG Zurich, a financial services company operating in Switzerland (CH), fell victim to a ransomware attack conducted by the Qilin group. The breach was discovered on 2025-11-05 at 10:20:35.645004 UTC. The incident highlights the growing threat of ransomware in the financial sector and the critical need for proactive cybersecurity defenses.

Date Detected: 2025-11-05T10:20:35.645004

Type: ransomware

Threat Actor: qilin

Incident : Unauthorized Access

Title: Unauthorized Access and Ransomware Attack on Habib Bank AG Zurich

Description: Habib Bank AG Zurich disclosed unauthorized external access to its corporate network on November 5, 2025. The Qilin ransomware gang claimed responsibility, stating it stole 2.56 TB of data and listed the bank on its data leak site. The bank confirmed no persistent access was identified, and banking services remained operational. The investigation is ongoing to assess the extent of data exposure, with support from cybersecurity and forensic experts. The bank has not verified Qilin’s claim regarding the stolen data or ransom demands.

Date Publicly Disclosed: 2025-11-05

Type: Unauthorized Access

Attack Vector: Phishing Emails (likely, based on Qilin's typical methods)

Threat Actor: Qilin Ransomware Gang

Motivation: Financial GainData Theft

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Ransomware.

Impact of the Incidents

What was the impact of each incident ?

Incident : Unauthorized Access HAB5402254111225

Data Compromised: 2.56 TB (claimed by Qilin, unverified by the bank)

Downtime: None (banking services remained fully operational)

Operational Impact: Ongoing investigation; cybersecurity and forensic experts engaged

Brand Reputation Impact: Potential reputational damage due to public disclosure of unauthorized access and ransomware claim

Identity Theft Risk: Potential (if data was exfiltrated as claimed)

Which entities were affected by each incident ?

Incident : ransomware HAB3220532110725

Entity Name: Habib Bank AG Zurich

Entity Type: private

Industry: Financial Services

Location: Switzerland (CH)

Incident : Unauthorized Access HAB5402254111225

Entity Name: Habib Bank AG Zurich

Entity Type: Private Bank

Industry: Financial Services

Location: Zurich, Switzerland

Size: ~8,000 employees, 500+ offices worldwide

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Unauthorized Access HAB5402254111225

Incident Response Plan Activated: True

Third Party Assistance: Cybersecurity Experts, Forensic Experts.

Remediation Measures: Ongoing investigation to assess and mitigate impact

Communication Strategy: Public notice posted on the bank’s website

How does the company involve third-party assistance in incident response ?

Third-Party Assistance: The company involves third-party assistance in incident response through Cybersecurity Experts, Forensic Experts, .

Data Breach Information

What type of data was compromised in each breach ?

Incident : Unauthorized Access HAB5402254111225

Data Exfiltration: 2.56 TB (claimed by Qilin, unverified)

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Ongoing investigation to assess and mitigate impact.

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : ransomware HAB3220532110725

Ransomware Strain: qilin

Incident : Unauthorized Access HAB5402254111225

Ransomware Strain: Qilin

Data Exfiltration: 2.56 TB (claimed)

Lessons Learned and Recommendations

What recommendations were made to prevent future incidents ?

Incident : ransomware HAB3220532110725

Recommendations: Implement phishing simulations to test and improve employee readiness., Provide cybersecurity awareness training to educate teams on recognizing and responding to attack tactics., Deploy data breach monitoring for real-time alerts on exposed organizational data., Adopt phishing detection and response solutions to neutralize threats proactively.Implement phishing simulations to test and improve employee readiness., Provide cybersecurity awareness training to educate teams on recognizing and responding to attack tactics., Deploy data breach monitoring for real-time alerts on exposed organizational data., Adopt phishing detection and response solutions to neutralize threats proactively.Implement phishing simulations to test and improve employee readiness., Provide cybersecurity awareness training to educate teams on recognizing and responding to attack tactics., Deploy data breach monitoring for real-time alerts on exposed organizational data., Adopt phishing detection and response solutions to neutralize threats proactively.Implement phishing simulations to test and improve employee readiness., Provide cybersecurity awareness training to educate teams on recognizing and responding to attack tactics., Deploy data breach monitoring for real-time alerts on exposed organizational data., Adopt phishing detection and response solutions to neutralize threats proactively.

References

Where can I find more information about each incident ?

Incident : ransomware HAB3220532110725

Source: HookPhish Threat Intelligence Feed

Incident : Unauthorized Access HAB5402254111225

Source: Comparitech

Incident : Unauthorized Access HAB5402254111225

Source: Habib Bank AG Zurich Public Notice

Date Accessed: 2025-11-05

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: HookPhish Threat Intelligence Feed, and Source: Comparitech, and Source: Habib Bank AG Zurich Public NoticeDate Accessed: 2025-11-05.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : ransomware HAB3220532110725

Investigation Status: ongoing

Incident : Unauthorized Access HAB5402254111225

Investigation Status: Ongoing (supported by cybersecurity and forensic experts)

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public notice posted on the bank’s website.

Stakeholder and Customer Advisories

Were there any advisories issued to stakeholders or customers for each incident ?

Incident : Unauthorized Access HAB5402254111225

Stakeholder Advisories: Public notice posted on the bank’s website

Customer Advisories: Banking services remain unaffected and fully operational

What advisories does the company provide to stakeholders and customers following an incident ?

Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Public notice posted on the bank’s website and Banking services remain unaffected and fully operational.

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Unauthorized Access HAB5402254111225

Backdoors Established: None identified (as per bank’s statement)

Post-Incident Analysis

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Cybersecurity Experts, Forensic Experts, .

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident were an qilin and Qilin Ransomware Gang.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on 2025-11-05T10:20:35.645004.

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-11-05.

Impact of the Incidents

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were 2.56 TB (claimed by Qilin and unverified by the bank).

Response to the Incidents

What third-party assistance was involved in the most recent incident ?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was cybersecurity experts, forensic experts, .

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were 2.56 TB (claimed by Qilin and unverified by the bank).

Lessons Learned and Recommendations

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Deploy data breach monitoring for real-time alerts on exposed organizational data., Adopt phishing detection and response solutions to neutralize threats proactively., Provide cybersecurity awareness training to educate teams on recognizing and responding to attack tactics. and Implement phishing simulations to test and improve employee readiness..

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident are Comparitech, Habib Bank AG Zurich Public Notice and HookPhish Threat Intelligence Feed.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is ongoing.

Stakeholder and Customer Advisories

What was the most recent stakeholder advisory issued ?

Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Public notice posted on the bank’s website, .

What was the most recent customer advisory issued ?

Most Recent Customer Advisory: The most recent customer advisory issued was an Banking services remain unaffected and fully operational.

cve

Latest Global CVEs (Not Company-Specific)

Description

MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is a security issue exists in the exec_in_pod tool of the mcp-server-kubernetes MCP Server. The tool accepts user-provided commands in both array and string formats. When a string format is provided, it is passed directly to shell interpretation (sh -c) without input validation, allowing shell metacharacters to be interpreted. This vulnerability can be exploited through direct command injection or indirect prompt injection attacks, where AI agents may execute commands without explicit user intent. This vulnerability is fixed in 2.9.8.

Risk Information
cvss3
Base: 6.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Description

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

Description

An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access administrative functions of the device (e.g. file upload, firmware update, reboot...) via a crafted authentication bypass.

Description

Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker to bypass password verification when a TOTP code is provided, potentially gaining unauthorized access to user accounts. This issue exists due to problematic conditional logic in the authentication flow. This vulnerability is fixed in 5.9.8.

Risk Information
cvss4
Base: 9.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, when an application passed an attacker controlled float poing number into the toFixed() function, it might lead to high CPU consumption and a potential Denial of Service. Small numbers go through this call stack: NativeNumber.numTo > DToA.JS_dtostr > DToA.JS_dtoa > DToA.pow5mult where pow5mult attempts to raise 5 to a ridiculous power. This vulnerability is fixed in 1.8.1, 1.7.15.1, and 1.7.14.1.

Risk Information
cvss4
Base: 5.5
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=habib-bank-ag-zurich' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge