Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Hikvision

Hikvision Vendor Cyber Rating & Cyber Score

hikvision.com

Founded in 2001, Hikvision focuses on integrated security and scenario-based digitalization. Propelled by the AI-powered Internet of Things (AIoT), the Company remains committed to serving various industries with its machine perception and artificial intelligence technologies. Guided by the core values of 'Professionalism, Reliability, and Integrity', Hikvision explores innovative ways to better perceive and understand the world. It empowers visionary decision-makers and practitioners to work together to enhance safety and advance sustainable development around the world. The Company's business grows through technologies that are deeply rooted in innovation and an increasingly diverse range of AIoT products and solutions. With an open


Hikvision A.I CyberSecurity Scoring

Hikvision
Company Information
Website:https://www.hikvision.com/en/
Employees number:9,449
Number of followers:396,739
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:hikvision.com
Hikvision Risk Score (AI oriented)
Between 700 and 749
logo
HikvisionIT Services and IT Consulting
Updated:
04/08/2026
720/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Hikvision Global Score (TPRM)
xxxx
logo
HikvisionIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Hikvision
HikvisionModerate
Current Score
720Ba (MODERATE)
01000
6 incidents
-20 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
720Before Incident
Vulnerability
04 Aug 2026Hikvision
SonicWall, Citrix, Sophos, Fortinet, vBulletin, Hikvision and SAP: Russian Hacker Breaches Companies, Sells Their Access and Spies on Ukrainian Military Sites

Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation

717After Incident
CRITICAL-3
SAPFORVBUCITSONSOPHIK1785846368
Russian-Speaking Hacker Linked to Global Cybercrime and Espionage Operation A Russian-speaking threat actor has been identified as the orchestrator of a large-scale cyber operation targeting organizations worldwide, acting as an initial access broker (IAB) for ransomware groups. The campaign, uncovered by CloudSEK researchers, exploited exposed security appliances and unpatched vulnerabilities to breach networks across education, healthcare, financial services, telecommunications, and government sectors in over a dozen countries. ### Attack Methodology The hacker conducted large-scale scans to identify vulnerable internet-facing systems, leveraging 12 known exploits in products from Fortinet, F5, SonicWall, Sophos, Citrix, SAP, Roundcube, vBulletin, and Hikvision. Most exploits relied on public proof-of-concept (PoC) code, though some were modified for the operation. Once inside a network, the attacker: - Deployed web shells and network tunnels to move laterally. - Harvested NTLM password hashes, credential stores, and browser secrets. - Compromised Active Directory (AD), extracting Kerberos ticket-granting keys to forge long-term authentication tokens. - In some cases, achieved full domain control, enabling ransomware groups to later encrypt systems. ### Shift to Espionage: Ukraine in the Crosshairs While the initial focus was financial cybercrime, the operation later pivoted to targeting Ukrainian defense and aerospace organizations. The hacker: - Deployed Sliver command-and-control (C2) tooling. - Accessed exposed source-code repositories. - Collected hundreds of images from internet-facing IP cameras and screenshots from remote desktop sessions, likely to monitor military logistics, border crossings, and critical infrastructure. CloudSEK assessed with moderate-to-high confidence that this phase served Russian state-linked intelligence needs, though it remains unclear whether the actor was directly tasked or sold the data to a state customer. ### Shared Infrastructure and Defensive Recommendations The same VPS servers, tunnels, and tooling were used for both criminal and espionage activities, highlighting the blurred lines between cybercrime and state-sponsored operations. Organizations are advised to: - Remove administrative interfaces from direct internet exposure. - Patch vulnerable appliances immediately. - Rotate credentials and review unauthorized logins, SSH keys, and device settings. - Isolate IP cameras from public networks and replace default passwords. ### Indicators of Compromise (IoCs) CloudSEK provided key IoCs, including: - IPv4 addresses linked to operator VPS, jumpboxes, and C2 infrastructure. - SHA-256 hashes for Sliver Linux implants and malicious drivers used in credential theft. The case underscores the dual threat posed by initial access brokers facilitating both ransomware attacks and state-aligned espionage while reinforcing the risks of unpatched edge devices and exposed credentials.
INCIDENT DETAILS -
TYPE
CybercrimeEspionage
MOTIVATION
Financial gainState-aligned intelligence collection
IMPACT
Data Compromised: NTLM password hashes, credential stores, browser secrets, Kerberos ticket-granting keys, source-code repositories, images from IP cameras, remote desktop screenshotsSystems Affected: Networks across education, healthcare, financial services, telecommunications, government, defense, and aerospace sectorsOperational Impact: Full domain control achieved in some cases, enabling ransomware deploymentIdentity Theft Risk: High (due to credential harvesting)
DATA BREACH
NTLM password hashesCredential storesBrowser secretsKerberos ticket-granting keysSource-code repositoriesImages from IP camerasRemote desktop screenshotsSensitivity Of Data: High (personally identifiable information, authentication tokens, military logistics data)Data Exfiltration: Yes (data sold on dark web in some cases)ImagesSource codeScreenshotsPersonally Identifiable Information: Yes (credentials, authentication tokens)
JULY 2026
720Before Incident
JUNE 2026
718Before Incident
MAY 2026
719Before Incident
APRIL 2026
712Before Incident
MARCH 2026
791Before Incident
Ransomware
21 Mar 2026Hikvision
Hikvision and French manufacturing firm: Exclusive: Ransomware newcomer claims breach of security camera firm Hikvision

Hikvision Hit by ALP-001 Ransomware Group in Massive Data Breach

711After Incident
CRITICAL-80
NOVHIK1774427439
Hikvision Hit by ALP-001 Ransomware Group in Massive Data Breach A newly identified ransomware group, ALP-001, has claimed responsibility for a 19.9-terabyte data breach targeting Hikvision, the Chinese-headquartered security camera manufacturer. The group listed the company as a victim on its darknet leak site on March 21, threatening to release the stolen data in 200-gigabyte increments within five days. A sample data link provided by the hackers was reportedly broken, and no ransom demand has been disclosed. Hikvision, a partly state-owned firm known for its surveillance equipment, has not responded to requests for comment. The company has faced prior scrutiny over cybersecurity vulnerabilities in its products, as well as sanctions and bans due to its alleged involvement in mass surveillance, including in China’s Uyghur internment camps. While Hikvision’s cameras remain commercially available, they were removed from government buildings in early 2023. ALP-001 emerged on the same day as its first victim listing, but cybersecurity firm ReliaQuest traced its origins to an Initial Access Broker (IAB) active on underground forums earlier this year. The group’s Tox and Session IDs matched those used by a known threat actor previously operating under aliases like "Alpha Group" and "DGJT Group." ReliaQuest identified a direct link between a French manufacturing firm ($543M revenue) listed on ALP-001’s leak site and a January 2026 access sale by the same user, suggesting the group has transitioned from selling breached access to running a full-fledged extortion operation. Despite its claims of being a "discreet collective of cybersecurity professionals," ALP-001’s actual data exfiltration capabilities remain unverified. The group positions itself as a pragmatic enterprise, offering victims a choice between a private financial settlement or public data disclosure. With Hikvision’s global presence including offices in Australia the breach raises concerns over the potential exposure of sensitive surveillance data.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Extortion
IMPACT
Data Compromised: 19.9 terabytesBrand Reputation Impact: Potential reputational damage due to prior scrutiny and sanctions
DATA BREACH
Type Of Data Compromised: Surveillance dataSensitivity Of Data: High (potential sensitive surveillance data)
MARCH 2026
794Before Incident
Vulnerability
05 Mar 2026Hikvision
Hikvision: Hikvision Multiple Product Vulnerability Could Let Attackers Escalate Privileges

CISA Adds Critical Hikvision Vulnerability to Exploited Flaws Catalog After Active Attacks

791After Incident
CRITICAL-3
HIK1773044701
CISA Adds Critical Hikvision Vulnerability to Exploited Flaws Catalog After Active Attacks On March 5, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2017-7921, a severe authentication bypass flaw in Hikvision surveillance products, to its Known Exploited Vulnerabilities (KEV) catalog. The move follows confirmation that threat actors are actively exploiting the vulnerability in real-world attacks. The flaw, classified as CWE-287 (Improper Authentication), affects Hikvision cameras and network video recorders, allowing attackers to bypass login requirements entirely. Once exploited, hackers gain full administrative control, enabling them to access live and recorded video feeds, extract sensitive operational data, and use compromised devices as a foothold to infiltrate broader corporate networks. While the vulnerability was initially discovered years ago, its inclusion in the KEV catalog signals a resurgence in active exploitation. Security analysts have not confirmed whether ransomware groups are leveraging the flaw, but its severity has prompted urgent action. Under Binding Operational Directive (BOD 22-01), federal agencies must remediate the issue by March 26, 2026. CISA has also urged private-sector organizations to prioritize patching, recommending immediate firmware updates, network isolation of surveillance systems, and if patching is impossible permanent disconnection of vulnerable devices. The flaw’s exploitation underscores the risks posed by unpatched edge devices, particularly in critical infrastructure and enterprise environments.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Live and recorded video feeds, sensitive operational dataSystems Affected: Hikvision cameras and network video recordersOperational Impact: Full administrative control of devices, potential network infiltration
DATA BREACH
Type Of Data Compromised: Video feeds, operational dataSensitivity Of Data: High (surveillance data, potential corporate network access)
FEBRUARY 2026
807Before Incident
JANUARY 2026
797Before Incident
Vulnerability
30 Jan 2026Hikvision
Hikvision: Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution

High-Severity Command Execution Flaw Disclosed in Hikvision Wireless Access Points

794After Incident
CRITICAL-3
HIK1770108920
High-Severity Command Execution Flaw Disclosed in Hikvision Wireless Access Points A critical authenticated command execution vulnerability, tracked as CVE-2026-0709, has been identified in multiple Hikvision Wireless Access Point (WAP) models. The flaw, rated 7.2 (High) on the CVSS v3.1 scale, stems from insufficient input validation in device firmware, allowing attackers with valid credentials to execute arbitrary commands on affected systems. The vulnerability enables threat actors to bypass security controls by sending maliciously crafted packets to the WAP after authentication. While exploitation requires valid credentials, the risk is heightened in environments where compromised accounts, stolen credentials, or insider threats exist. Successful exploitation could lead to full system compromise, granting attackers device-level privileges. ### Affected Models & Remediation The following Hikvision WAP models running firmware versions V1.1.6303 build250812 or earlier are vulnerable: - DS-3WAP521-SI - DS-3WAP522-SI - DS-3WAP621E-SI - DS-3WAP622E-SI - DS-3WAP623E-SI - DS-3WAP622G-SI Hikvision has released patched firmware (V1.1.6601 build 251223) to address the flaw. The vulnerability was reported on January 30, 2026, by independent researcher exzettabyte. ### Mitigation & Impact Organizations deploying affected models should immediately update to the latest firmware to prevent exploitation. For those unable to patch immediately, network segmentation, strict access controls, and credential rotation are recommended as interim measures. Monitoring authentication logs for suspicious activity can also help detect potential breaches. Hikvision’s Hardware Security Response Center (HSRC) continues to monitor threats and encourages vulnerability disclosures via [email protected]. Official support channels are available for further inquiries.
INCIDENT DETAILS -
TYPE
Command Execution Vulnerability
IMPACT
Systems Affected: Full system compromise possibleOperational Impact: Potential device-level privilege escalation
DECEMBER 2025
798Before Incident
NOVEMBER 2025
807Before Incident
Cyber Attack
01 Nov 2025Hikvision
OpenClaw, Notepad++, Hikvision, Apache Syncope, Foxit, TP-Link, Cisco, Google Chrome and Arista NG Firewall: ⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More

Cybersecurity Roundup: Trust Abuse, AI Risks, and Supply Chain Attacks Dominate Threat Landscape

796After Incident
CRITICAL-11
TP-HIKFOXGOOREVARITHEOPECIS1770645410
Cybersecurity Roundup: Trust Abuse, AI Risks, and Supply Chain Attacks Dominate Threat Landscape This week’s cybersecurity developments highlight a growing trend: attackers are increasingly exploiting trusted systems AI platforms, software updates, messaging apps, and open-source ecosystems to bypass security controls. Below are the key incidents and trends shaping the threat landscape. ### AI and Open-Source Ecosystems Under Siege OpenClaw, an open-source AI agent framework, has partnered with Google’s VirusTotal to scan uploaded "skills" (AI extensions) for malware, following discoveries of malicious components in its ClawHub marketplace. Researchers warn that AI agents’ broad permissions, persistent memory, and user-controlled configurations create risks like prompt injection, data exfiltration, and supply chain attacks. Trend Micro reported threat actors on Exploit.in discussing OpenClaw for botnet operations, while Veracode noted a surge in typosquatted "claw" packages on npm and PyPI from zero in early 2026 to over 1,000 by February. Meanwhile, MoltBook, an AI-driven social platform built on OpenClaw, faces scrutiny after Simula Research Laboratory identified 506 prompt injection attacks, social engineering exploits, and unregulated cryptocurrency activity comprising 19.3% of its content. The platform’s autonomous AI agents, which interact without human oversight, raise concerns about data privacy and manipulation risks. Security firm Pillar Security detected active scanning of exposed OpenClaw gateways (port 18789), with attackers bypassing AI layers to target the WebSocket API directly for authentication bypasses and command execution. Censys identified 21,639 exposed OpenClaw instances as of January 2026, underscoring the framework’s outdated trust model lacking encryption-at-rest and containerization. ### Supply Chain Attacks: Trusted Updates as Malware Vectors A sophisticated supply chain attack targeted Notepad++ between June and December 2025, where threat actors redirected its WinGUp updater to malicious servers. Despite losing access to a compromised hosting provider in September, attackers reused stolen credentials to maintain control until December. The campaign, attributed to Lotus Blossom, exploited weak update verification in older Notepad++ versions, demonstrating how legitimate domains can become malware distribution hubs. Similarly, Docker’s AI assistant (Ask Gordon) was found vulnerable to remote code execution (RCE) via DockerDash, a flaw in its Model Context Protocol (MCP) Gateway. Attackers could embed malicious instructions in Docker image metadata, which the AI assistant executed without validation. Docker patched the issue in version 4.50.0 (November 2025). ### State-Sponsored Threats and High-Profile Targets Germany’s BfV and BSI issued a joint advisory warning of state-sponsored phishing attacks via Signal, exploiting the app’s PIN and device-linking features to hijack accounts. Targets included high-ranking officials, military personnel, diplomats, and journalists across Germany and Europe. In Ukraine, the government implemented a Starlink terminal verification system after confirming Russian forces were using the technology on attack drones. Only registered devices are now permitted to operate in the country. ### DDoS, Botnets, and Emerging Attack Techniques The AISURU/Kimwolf botnet set a record with a 31.4 Tbps DDoS attack in November 2025, lasting just 35 seconds. Cloudflare mitigated the attack, which was part of a broader campaign ("The Night Before Christmas") starting in December. Overall, DDoS attacks surged 121% in 2025, averaging 5,376 mitigated attacks per hour. Researchers also uncovered 54 malicious npm packages using EtherHiding, a technique leveraging Ethereum smart contracts to fetch C2 servers, complicating takedown efforts. The malware targets Windows systems with 5+ CPUs, employing sandbox evasion, COM hijacking, and system profiling. ### Linux Threats and Post-Exploitation Frameworks Cyble discovered ShadowHS, a fileless Linux post-exploitation framework that runs entirely in memory, prioritizing stealth and long-term control. The framework includes modules for credential access, lateral movement, privilege escalation, and data exfiltration, with aggressive defensive tooling enumeration to avoid detection. ### Ransomware, Dark Markets, and Legal Actions - INC Ransomware suffered a setback after Cyber Centaurs breached its backup server, helping 12 victims recover data. The group, active since 2023, had listed over 100 victims on its leak site. - Rui-Siang Lin, administrator of the Incognito Market darknet drug marketplace, was sentenced to 30 years in prison for facilitating $105 million in narcotics sales to over 400,000 users. - Xinbi, a Telegram-based illicit marketplace, processed $17.9 billion in transactions, outlasting competitors like Haowang and Tudou Guarantee, which saw declines of 100% and 74%, respectively. ### Critical Vulnerabilities and Exploits Notable CVEs disclosed this week include: - CVE-2026-25049 (n8n) - CVE-2026-0709 (Hikvision Wireless Access Point) - CVE-2026-23795 (Apache Syncope) - CVE-2026-1591/1592 (Foxit PDF Editor Cloud) - CVE-2026-24512 (ingress-nginx) - Multiple CVEs in Django, Google Chrome, Cisco, TP-Link, F5 BIG-IP, and Arista NG Firewall Additionally, XBOW uncovered two Insecure Direct Object Reference (IDOR) flaws in Spree (CVE-2026-22588/22589), allowing unauthorized access to user address data. ### Microsoft’s AI Backdoor Scanner Microsoft developed a scanner to detect hidden backdoors in open-weight AI models, addressing risks for enterprises relying on third-party large language models (LLMs). The tool identifies three key indicators: 1. Attention shifts when a hidden trigger is present. 2. Leakage of poisoned training data. 3. Partial triggers still activating malicious responses. The scanner extracts memorized content from models and ranks suspicious substrings as potential triggers. ### Conclusion This week’s incidents underscore a shift in attacker tactics exploiting trust in ecosystems, AI workflows, and supply chains rather than relying on traditional malware. As threats evolve, organizations must monitor integrations, verify updates, and secure AI deployments to mitigate risks from both state-sponsored actors and cybercriminals.
INCIDENT DETAILS -
TYPE
Supply Chain AttackAI ExploitationDDoSRansomwarePhishingMalwarePost-Exploitation Framework
MOTIVATION
Financial GainEspionageData ExfiltrationBotnet OperationsRansomwareDrug TraffickingState-Sponsored Surveillance
IMPACT
AI Agent ConfigurationsUser Data on MoltBookCredentialsSystem ProfilesPersonally Identifiable Information (PII)Payment InformationOpenClaw AI FrameworkNotepad++Docker AI AssistantSignal Messaging AppStarlink TerminalsLinux Systems (ShadowHS)Spree E-Commerce PlatformUnauthorized Command ExecutionData ExfiltrationBotnet OperationsAI Agent ManipulationDDoS DisruptionsMoltBook (AI-Driven Social Platform)Notepad++DockerOpenClawRegulatory Violations (GDPR, etc.)Fines for Data BreachesIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
AI Agent ConfigurationsUser DataCredentialsPIIPayment InformationDrug Trafficking RecordsSensitivity Of Data: HighYes (OpenClaw, ShadowHS, INC Ransomware)Yes (Ransomware)No (OpenClaw, ShadowHS)Personally Identifiable Information: Yes
OCTOBER 2025
807Before Incident
SEPTEMBER 2025
807Before Incident
JANUARY 2024
809Before Incident
Cyber Attack
01 Jan 2024Hikvision
Linksys, Hikvision, Cisco, Ubiquiti, Draytek, Fortinet, Araknis and Mimosa Networks: China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation

China-Linked JDY Botnet Expands, Targeting U.S. Critical Infrastructure

799After Incident
CRITICAL-10
DOMCISLINDRAFORMIMHIKUBI1781173672
China-Linked JDY Botnet Expands, Targeting U.S. Critical Infrastructure A resurgent botnet tied to China-backed threat actors has grown into one of the most sophisticated reconnaissance tools in operation. Dubbed JDY, the network now controls over 1,500 compromised small office/home office (SOHO) routers and IoT devices across the U.S., Europe, and Asia, doubling in size since January 2024. Originally part of the KV-botnet operation linked to Volt Typhoon JDY was first detected in late 2023 as a covert scanning network used to gather intelligence on U.S. critical infrastructure. After U.S. authorities dismantled its companion KV cluster, JDY quietly rebuilt, expanding its reach and capabilities. Researchers at Lumen’s Black Lotus Labs found that the botnet now targets devices from manufacturers including Cisco, Ubiquiti, Hikvision, Draytek, Linksys, Araknis, and Mimosa Networks. Its operators act with remarkable speed shifting scans to exploit newly disclosed vulnerabilities within hours of public disclosure. A recent example involved CVE-2026-35616, a Fortinet flaw, which JDY began probing almost immediately. The botnet’s primary focus is U.S.-based networks, particularly those tied to military entities. By leveraging ordinary home and small business routers, JDY blends malicious traffic with legitimate activity, evading detection. Infected devices receive scanning tasks via Tor-hidden command-and-control (C2) servers, making attribution difficult. Scans span TCP, UDP, SSL, and ICMP protocols, with results compressed, encrypted, and sent back to a central server. JDY’s malware, designed for MIPS and MIPSEL architectures, uses a lightweight bash dropper to infect devices, download payloads, and erase traces. Some devices are managed via Platypus, an open-source remote shell tool, with a known payload server at 149.248.3[.]38 (port 13339). The botnet’s distributed nature spreading scans across thousands of IPs helps it bypass traditional defenses like blocklists and geofencing. Despite disruption efforts, JDY has proven resilient, adapting and expanding even after partial takedowns. Its rapid response to new vulnerabilities underscores the persistent threat posed by China-linked cyber espionage operations.
INCIDENT DETAILS -
TYPE
Botnet, Cyber Espionage
MOTIVATION
Cyber espionage, intelligence gathering on U.S. critical infrastructure
IMPACT
Data Compromised: Reconnaissance data, network intelligenceSystems Affected: 1,500+ SOHO routers and IoT devicesOperational Impact: Potential disruption of critical infrastructure networks
DATA BREACH
Type Of Data Compromised: Network intelligence, reconnaissance dataSensitivity Of Data: High (military and critical infrastructure-related)Data Exfiltration: Yes (compressed and encrypted data sent to C2 servers)Data Encryption: Yes (payloads encrypted)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Hikvision ?
?
What was Hikvision's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Hikvision's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Hikvision's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Hikvision ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Hikvision's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Hikvision Cyber Scoring History | Rankiteo