Hurricane Electric A.I CyberSecurity Scoring
Hurricane Electric
Company Information
Website:http://he.net/
Employees number:137
Number of followers:9,490
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:he.net
Hurricane Electric Risk Score (AI oriented)
Between 700 and 749
Hurricane ElectricTechnology, Information and Internet
Updated:
10/03/2026
10/03/2026
735/1000
Moderate
Ba
Hurricane Electric Global Score (TPRM)
xxxx
Hurricane ElectricTechnology, Information and Internet
Score locked

Hurricane ElectricModerate
Current Score
735Ba (MODERATE)
01000
1 incidents
-32 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
737
MAY 2026
737
APRIL 2026
736
MARCH 2026
767
Cyber Attack
10 Mar 2026 • Hurricane Electric
Cloudflare and Hurricane Electric: Hacker abusing .arpa domain to evade phishing detection, says Infoblox
Hackers Exploit Trusted .arpa Domain to Bypass Phishing Detection
735
HIGH-32
HURCLO1773109431
Hackers Exploit Trusted .arpa Domain to Bypass Phishing Detection
Researchers at Infoblox have uncovered a novel phishing tactic that abuses the .arpa top-level domain (TLD) a trusted infrastructure component to evade security defenses. The attack leverages IPv6-to-IPv4 tunneling services, specifically from Hurricane Electric, to create malicious forward DNS records under the .arpa domain, which is typically reserved for reverse DNS lookups and is implicitly trusted by security tools.
### How the Attack Works
1. Abusing Free Tunneling Services – The attacker obtained IPv6 addresses from Hurricane Electric’s free tunneling service, which allows customers to designate DNS providers for their allocated space.
2. Manipulating DNS Records – Instead of creating legitimate PTR (pointer) records for reverse lookups, the attacker configured A (address) records on Cloudflare’s name servers, redirecting .arpa domains to malicious websites.
3. Bypassing Security Controls – Since .arpa is universally trusted, security tools like protective DNS and next-gen firewalls often overlook it, allowing phishing links to slip through undetected.
### Phishing Lures & Impact
The campaign primarily targets consumers with two types of scams:
- Fake brand surveys (e.g., department stores, supermarkets) offering "free gifts" for participation.
- Subscription renewal scams claiming the victim’s cloud storage or antivirus service has been interrupted, demanding payment to restore access.
When victims click embedded links in phishing emails, they are redirected through a series of malicious pages, ultimately tricked into entering credit card details under false pretenses.
### Why This Attack Is Dangerous
- .arpa domains are inherently trusted, making them invisible to reputation-based security filters.
- No registration details are required, eliminating typical red flags like newly registered domains.
- Sophisticated threat actors could adapt this technique for spear-phishing or targeted attacks.
- Not all providers are vulnerable some block unauthorized .arpa domain claims but many remain exposed.
### Mitigation Recommendations
Infoblox advises organizations to:
- Monitor DNS traffic for unusual .ip6.arpa queries.
- Block or alert on atypical .arpa hostnames (e.g., non-standard IP address formats).
- Audit IPv6 tunneling providers to prevent abuse of their services.
- Ensure email security tools flag .arpa-based phishing links.
The discovery highlights a critical gap in phishing defenses, proving that even trusted infrastructure components can be weaponized. While currently used for consumer scams, the technique could easily escalate to enterprise-targeted attacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
767
JANUARY 2026
767
DECEMBER 2025
767
NOVEMBER 2025
767
OCTOBER 2025
767
SEPTEMBER 2025
767
AUGUST 2025
767
JULY 2025
767
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Hurricane Electric ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in May 2026 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in April 2026 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in March 2026 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in February 2026 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in January 2026 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in December 2025 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in November 2025 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in October 2025 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in September 2025 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in August 2025 ??
What was Hurricane Electric's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Hurricane Electric's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Hurricane Electric ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Hurricane Electric's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?