Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
HackerOne

HackerOne Vendor Cyber Rating & Cyber Score

hackerone.com

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was


HackerOne A.I CyberSecurity Scoring

HackerOne
Company Information
Website:https://hackerone.com
Employees number:6,662
Number of followers:350,380
NAICS:541514
Industry Type:Computer and Network Security
Homepage:hackerone.com
HackerOne Risk Score (AI oriented)
Between 0 and 549
logo
HackerOneComputer and Network Security
Updated:
15/07/2026
504/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
HackerOne Global Score (TPRM)
xxxx
logo
HackerOneComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

HackerOneCritical
Current Score
504C (CRITICAL)
01000
6 incidents
-78 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
512Before Incident
AUGUST 2026
507Before Incident
JULY 2026
547Before Incident
JUNE 2026
603Before Incident
Breach
25 Jun 2026HackerOne
Klue: Klue Hit by Double Extortion as Second Hacker Group Emerges

Klue Faces Unprecedented Dual Extortion Attack After Data Breach

546After Incident
CRITICAL-57
KLU1782428022
Klue Faces Unprecedented Dual Extortion Attack After Data Breach Vancouver-based market intelligence platform Klue has disclosed a rare and escalating cybersecurity crisis, involving two criminal groups with conflicting extortion demands following a data breach. The incident, first reported by TechCrunch, marks an unusual case of competing threats targeting the same victim highlighting evolving tactics in cyber extortion. The breach initially involved a hacking group that stole sensitive customer data, including proprietary market research, competitive analysis, and strategic planning materials used by enterprise clients to track rivals. In a surprising turn, the original attackers later claimed they were deleting the stolen files, though Klue’s customers were warned not to assume the threat had passed. Before any relief could set in, a second criminal group emerged, demanding ransom for the same compromised data. The situation leaves Klue’s enterprise clients including sales and marketing teams at major corporations in limbo, uncertain whether their highly sensitive business intelligence has been destroyed, leaked, or is now in the hands of multiple threat actors. The competitive intelligence sector handles particularly valuable data, such as go-to-market strategies and product roadmaps, which could cause significant damage if exposed. Security researchers note that while secondary markets for stolen data are not new, the simultaneous, opposing claims from two criminal groups are highly unusual. The first group’s alleged data deletion could be a face-saving exit or genuine reversal, while the second group’s demands suggest they either independently accessed Klue’s systems or acquired the data from the original attackers. Klue has not disclosed technical details of the breach, the scope of compromised data, or the number of affected customers. The incident underscores the cascading risks of B2B SaaS breaches, where third-party vendors handling critical business intelligence become high-value targets. It also arrives amid growing enterprise concerns over vendor security postures, following high-profile breaches at platforms like Okta and LastPass.
INCIDENT DETAILS -
TYPE
data_breachransomwaredual_extortion
MOTIVATION
financial gaindata extortion
IMPACT
Data Compromised: proprietary market research, competitive analysis, strategic planning materials, go-to-market strategies, product roadmapsBrand Reputation Impact: high
DATA BREACH
proprietary market researchcompetitive analysisstrategic planning materialsgo-to-market strategiesproduct roadmapsSensitivity Of Data: high
MAY 2026
599Before Incident
APRIL 2026
596Before Incident
MARCH 2026
592Before Incident
FEBRUARY 2026
589Before Incident
JANUARY 2026
586Before Incident
DECEMBER 2025
700Before Incident
Breach
22 Dec 2025HackerOne
Navia Benefit Solutions Inc.: Navia Benefit Solutions Data Breach Exposes Sensitive Health Data

Navia Benefit Solutions Discloses Data Breach Exposing PII and PHI

581After Incident
CRITICAL-119
NAV1773671790
Navia Benefit Solutions Discloses Data Breach Exposing PII and PHI Navia Benefit Solutions Inc., a national benefits administrator based in Renton, Washington, recently reported a data breach that compromised sensitive personal and health information. The company detected suspicious activity within its systems on January 23, 2026, prompting an investigation that revealed unauthorized access between December 22, 2025, and January 15, 2026. The exposed data includes personally identifiable information (PII) such as names, dates of birth, Social Security numbers, phone numbers, and email addresses as well as protected health information (PHI), specifically health plan details. The total number of affected individuals remains undisclosed, and Navia has not specified how the breach occurred. Navia has begun notifying impacted individuals via mail and posted a notice on its website. While the company has not offered free credit monitoring or identity protection services, it established a dedicated assistance line (844-443-1645) for inquiries, available Monday through Friday from 9:00 a.m. to 6:30 p.m. Eastern Time. Affected individuals may also contact Navia by mail at 707 South Grady Way, Suite 350, Renton, WA 98057. The breach underscores the risks of medical and financial identity theft, particularly given the exposure of Social Security numbers and health plan data.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: PII and PHIIdentity Theft Risk: High (medical and financial identity theft risk)
DATA BREACH
Personally Identifiable Information (PII)Protected Health Information (PHI)Sensitivity Of Data: High (Social Security numbers, health plan details)NamesDates of birthSocial Security numbersPhone numbersEmail addresses
Breach
22 Dec 2025HackerOne
HackerOne and Navia Benefit Solutions Inc.: HackerOne Data Breach Exposes SSNs and Health Details

HackerOne Data Breach Traces Back to Third-Party Benefits Provider

581After Incident
CRITICAL-119
NAVHAC1774377242
HackerOne Data Breach Traces Back to Third-Party Benefits Provider HackerOne, a San Francisco-based cybersecurity firm specializing in bug bounty programs, disclosed a data breach affecting 287 U.S.-based employees and dependents. The incident originated from Navia Benefit Solutions Inc., a third-party benefits administrator based in Renton, Washington, rather than HackerOne’s own systems. The breach was discovered on January 23, 2026, after Navia detected suspicious activity between December 22, 2025, and January 15, 2026. An investigation revealed that a Broken Object Level Authorization (BOLA) vulnerability in Navia’s systems allowed an unauthorized actor to access and exfiltrate sensitive data. The exposed information included Social Security numbers, full names, addresses, dates of birth, email addresses, health plan details, and dependent data. Navia notified affected companies, including HackerOne, on February 20, 2026, after completing its review. HackerOne confirmed the breach’s legitimacy in a meeting with Navia on March 13, 2026, and began notifying impacted individuals via written notices on March 17, 2026. The breach was formally disclosed to the Maine Attorney General on March 23, 2026, with one Maine resident among those affected. HackerOne stated it is still awaiting further details from Navia regarding the vulnerability and is evaluating the provider’s security practices. While Navia has found no evidence of data misuse, HackerOne is treating the incident as a potential risk for identity theft, fraud, or financial loss. As a remedial measure, Navia is offering complimentary credit monitoring services through Kroll to affected individuals. Affected parties can direct inquiries to [email protected] or Navia’s dedicated assistance line, as outlined in individual notifications.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Social Security numbers, full names, addresses, dates of birth, email addresses, health plan details, and dependent dataSystems Affected: Navia Benefit Solutions Inc. systemsBrand Reputation Impact: Potential risk to HackerOne’s reputation due to third-party breachIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII), Health Plan DetailsNumber Of Records Exposed: 287Sensitivity Of Data: HighPersonally Identifiable Information: Social Security numbers, full names, addresses, dates of birth, email addresses
NOVEMBER 2025
697Before Incident
OCTOBER 2025
696Before Incident
SEPTEMBER 2025
751Before Incident
Breach
10 Sep 2025HackerOne
HackerOne

HackerOne Salesforce Environment Compromised via Drift Application Vulnerability

693After Incident
MEDIUM-58
HAC5462354091125
HackerOne, a vulnerability coordination platform, experienced a breach in its Salesforce environment due to an attack on the Drift application (provided by Salesloft). Unauthorized actors exploited a vulnerability in Drift’s Salesforce integration, gaining access to a subset of general Salesforce records, including contact information and standard account details. However, no customer vulnerability data, exploit details, or private security reports were exposed, as HackerOne’s strict data segmentation and access controls contained the incident.The breach was isolated to a limited set of records, and HackerOne promptly disabled the compromised integration while collaborating with Salesforce and Salesloft to mitigate risks. External forensic experts were engaged to verify the breach’s scope, and affected individuals were notified. While the incident did not compromise sensitive security data, it exposed non-critical business records, prompting precautionary measures like log reviews and integration updates to prevent future exploits.
INCIDENT DETAILS -
TYPE
third-party breachunauthorized access
IMPACT
general Salesforce recordscontact informationstandard account detailsHackerOne’s Salesforce instance (subset of data accessed via Drift integration)Operational Impact: Drift integration disabled; forensic investigation ongoingBrand Reputation Impact: Potential reputational risk due to breach transparency; proactive communication to mitigate impactIdentity Theft Risk: Low (no sensitive vulnerability data exposed)
DATA BREACH
contact informationstandard account detailsSensitivity Of Data: Low (no sensitive vulnerability data, exploit details, or PII exposed)Data Exfiltration: Unconfirmed (under investigation)Personally Identifiable Information: No
JUNE 2025
750Before Incident
Breach
12 Jun 2025HackerOne
LastPass, BeyondTrust, Klue, HackerOne, Jamf, Recorded Future, Snyk, Huntress and Tanium: Klue Data Breach 2026: 200 Firms Hit via Old Credential

Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential

693After Incident
CRITICAL-57
JAMHUNSNYRECHACLASTANKLUBEY1784126732
Klue Breach Exposes 200 Firms via Forgotten 4-Year-Old Credential In June 2025, a dormant credential issued by competitive-intelligence platform Klue in 2022 became the entry point for a breach affecting nearly 200 companies, including prominent cybersecurity vendors. The attack, claimed by the extortion group Icarus, exploited an unmonitored OAuth token to access Salesforce environments, underscoring the risks of neglected third-party integrations. ### What Happened? On June 12, 2025, attackers used a compromised legacy credential originally created for a "limited pilot" to infiltrate Klue’s systems. The credential, left active for four years, granted access to OAuth tokens that Klue used to pull data from connected Salesforce instances. Once inside, the threat actors automated data exfiltration from 195–200 companies, including LastPass, BeyondTrust, Jamf, HackerOne, Recorded Future, Snyk, Tanium, and Huntress. Klue publicly disclosed the breach on June 15, 2025, confirming data theft from an unspecified number of customers. By late June, affected firms began acknowledging the incident, with LastPass and BeyondTrust clarifying that only business contact and CRM data not core product systems were exposed. ### How the Attack Unfolded The breach required no zero-day exploits or sophisticated malware just an overlooked credential. The attackers leveraged Klue’s OAuth tokens to access Salesforce environments en masse, demonstrating the dangers of fourth-party risk: a vendor’s vendor (Klue) becoming the weak link in a supply chain. ### Key Victims & Impact While Klue serves sales and marketing teams, its customer base included security vendors, amplifying the breach’s irony. Confirmed victims span: - Password management (LastPass) - Privileged access (BeyondTrust) - Endpoint security (Tanium, Jamf) - Threat intelligence (Recorded Future) - Bug bounty coordination (HackerOne) - Application security (Snyk) Huntress reported receiving a ransom note from the attackers via a compromised Australian email address, highlighting the group’s reliance on reused infrastructure. ### Broader Context: A Year of Supply Chain Attacks The Klue breach coincided with a separate 2026 supply chain campaign targeting open-source security tools, including Trivy, Bitwarden, and Checkmarx. While unrelated, both incidents reflect a trend: attackers increasingly compromise trusted platforms to bypass direct defenses. ### Regulatory & Industry Reactions - Cyber insurers are tightening scrutiny of third-party integrations, particularly OAuth token hygiene. - Security vendors on the victim list face heightened procurement questions from enterprise buyers. - Regulators are paying closer attention to software supply chain risks, though the Klue breach limited to business data may not trigger major notifications. ### Lessons from the Breach The incident mirrors the 2025 Salesloft Drift breach, where stolen OAuth tokens compromised 700+ Salesforce environments. Both cases reveal a critical gap: point-in-time vendor assessments fail to catch dormant credentials. Mitigation requires: - Automated expiration for pilot credentials. - Minimum-scoped OAuth grants (avoiding broad CRM access). - Recurring token audits to identify stale integrations. As of June 2026, only ~15 of the estimated 200 affected firms have publicly confirmed exposure, with more expected to disclose as investigations continue. The breach serves as a stark reminder that identity and credential management not just perimeter defenses are central to modern cybersecurity.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: Business contact and CRM dataSystems Affected: Salesforce environmentsBrand Reputation Impact: Heightened procurement scrutiny for security vendors
DATA BREACH
Type Of Data Compromised: Business contact and CRM dataSensitivity Of Data: Low (non-core product data)
JULY 2022
775Before Incident
Breach
01 Jul 2022HackerOne
HackerOne

HackerOne Internal Data Breach by Former Employee

721After Incident
CRITICAL-54
HAC1486722
A former employee of HackerOne accessed internal data documents of the company for personal financial gain. He obtained information from security reports submitted to the bug bounty platform and attempted to disclose the same vulnerabilities outside of the platform. In under 24 hours, the company worked quickly to contain the incident by identifying the then-employee and cutting off his access to data after a suspicious customer received duplicated bug reports and raised complaints.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Personal Financial Gain
IMPACT
Security ReportsBug ReportsCustomer Complaints: Yes
DATA BREACH
Security ReportsBug Reports

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for HackerOne ?
?
What was HackerOne's A.I Rankiteo Cyber Score in August 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in July 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in June 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in May 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in April 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in March 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in February 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in January 2026 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in December 2025 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in November 2025 ?
?
What was HackerOne's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on HackerOne's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with HackerOne ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view HackerOne's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
HackerOne Cyber Scoring History | Rankiteo