Company Details
intrepid-museum
244
5,964
712
intrepidmuseum.org
0
INT_1959646
In-progress

Intrepid Museum Company CyberSecurity Posture
intrepidmuseum.orgThe Intrepid Museum, a private non-profit, holds a special place in New York City’s cultural landscape. Founded in 1982 with the acquisition of the storied WWII aircraft carrier Intrepid—a National Historic Landmark and the centerpiece of its collection—the Museum welcomes over one million visitors annually from all around the world. Its mission is to promote the awareness and understanding of history, science and service through bold and immersive collections, exhibitions and programming in order to honor our heroes, educate the public and inspire future generations. The Intrepid Museum’s dynamic exhibitions exemplify the intersection of history and innovation. Immersive fun, STEM and history are showcased through technological marvels such as Enterprise, the world’s first space shuttle, and Growler, the only nuclear-weapons-carrying submarine open to the public. The Museum’s one-of-a-kind experience also features dozens of military aircraft including fighter jets, a supersonic spy plane, and the Concorde, the world’s fastest commercial airliner, displayed in and around the legendary aircraft carrier, Intrepid, an awe-inspiring setting for an unforgettable adventure. But the true power of the Intrepid Museum extends beyond the mechanical marvels on display to all those whose stories of sacrifice, service and heroism bring history to life. Guided by its core values of integrity, innovation, and inclusivity, the Intrepid Museum’s exhibits and programs are designed to provide a meaningful visitor experience for all. The Museum delivers nationally-recognized accessible programming to its audience with an emphasis on underserved communities, individuals with physical, cognitive, and sensory disabilities, including autism and dementia, and our veterans. Through its after-school, professional development, and STEM programs, the Museum educates and impacts more than 55,000 students each year.
Company Details
intrepid-museum
244
5,964
712
intrepidmuseum.org
0
INT_1959646
In-progress
Between 700 and 749

Intrepid Museum Global Score (TPRM)XXXX

Description: The Vermont Office of the Attorney General reported a data breach affecting the Intrepid Museum Foundation on June 10, 2024. The breach occurred on December 2, 2023, when an unauthorized third party gained access to the museum's network, potentially compromising personal information including names of affected individuals. The total number of individuals affected is 8 residents from Rhode Island.


No incidents recorded for Intrepid Museum in 2025.
No incidents recorded for Intrepid Museum in 2025.
No incidents recorded for Intrepid Museum in 2025.
Intrepid Museum cyber incidents detection timeline including parent company and subsidiaries

The Intrepid Museum, a private non-profit, holds a special place in New York City’s cultural landscape. Founded in 1982 with the acquisition of the storied WWII aircraft carrier Intrepid—a National Historic Landmark and the centerpiece of its collection—the Museum welcomes over one million visitors annually from all around the world. Its mission is to promote the awareness and understanding of history, science and service through bold and immersive collections, exhibitions and programming in order to honor our heroes, educate the public and inspire future generations. The Intrepid Museum’s dynamic exhibitions exemplify the intersection of history and innovation. Immersive fun, STEM and history are showcased through technological marvels such as Enterprise, the world’s first space shuttle, and Growler, the only nuclear-weapons-carrying submarine open to the public. The Museum’s one-of-a-kind experience also features dozens of military aircraft including fighter jets, a supersonic spy plane, and the Concorde, the world’s fastest commercial airliner, displayed in and around the legendary aircraft carrier, Intrepid, an awe-inspiring setting for an unforgettable adventure. But the true power of the Intrepid Museum extends beyond the mechanical marvels on display to all those whose stories of sacrifice, service and heroism bring history to life. Guided by its core values of integrity, innovation, and inclusivity, the Intrepid Museum’s exhibits and programs are designed to provide a meaningful visitor experience for all. The Museum delivers nationally-recognized accessible programming to its audience with an emphasis on underserved communities, individuals with physical, cognitive, and sensory disabilities, including autism and dementia, and our veterans. Through its after-school, professional development, and STEM programs, the Museum educates and impacts more than 55,000 students each year.


LancasterHistory engages and educates the public about the people, places, and events that shaped Lancaster County within the broader context of the history of the Commonwealth of Pennsylvania and the United States of America. As custodians of a complex past, we collect, preserve, exhibit, and make

Cleveland’s Museum of Contemporary Art (moCa) plays an urgent and exciting role in the city's cultural landscape. As a non-collecting institution and the region’s only contemporary art museum, moCa is ever-changing, introducing new exhibitions three times a year and creating fresh experiences for vi

Our vision is to celebrate America’s love affair with the automobile and to ensure that the love affair continues for generations to come. When LeMay – America’s Car Museum opened, our goal was to genuinely serve the car collector and enthusiast communities. Beyond showcasing the LeMay collection,

The Hood Museum of Art at Dartmouth enables and cultivates transformative encounters with works of artistic and cultural significance to advance critical thinking and enrich people’s lives. Dartmouth’s collections are among the oldest and largest of any college or university in the country, but it

Pacific Bonsai Museum connects people to nature through the living art of bonsai. Fifty to 60 of the Museum's 150 bonsai are displayed at any given time in an outdoor fine art museum setting in the open air of a large forest in Federal Way, Washington. Pacific Bonsai Museum is one of only a handful

The Grace Museum is a 501(c)(3) nonprofit museum in Abilene, Texas. In 1937, the culturally minded Art Unit of Women’s Forum in Abilene established the Abilene Fine Arts Museum in a small facility in Rose City Park. In 1987, a campaign was initiated to save the majestic Hotel Grace, an abandoned 55,
.png)
A recent audit of the Denver Zoo's information technology systems found that security risks are “low,” according to a report released by the Denver Auditor's...
Defense Secretary Leon E. Panetta spelled out in detail the Defense Department's responsibility in cybersecurity during a speech to the Business Executives.
Defense Secretary Leon E. Panetta warned that the United States was facing the possibility of a “cyber-Pearl Harbor” and was increasingly...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Intrepid Museum is http://intrepidmuseum.org.
According to Rankiteo, Intrepid Museum’s AI-generated cybersecurity score is 717, reflecting their Moderate security posture.
According to Rankiteo, Intrepid Museum currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Intrepid Museum is not certified under SOC 2 Type 1.
According to Rankiteo, Intrepid Museum does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Intrepid Museum is not listed as GDPR compliant.
According to Rankiteo, Intrepid Museum does not currently maintain PCI DSS compliance.
According to Rankiteo, Intrepid Museum is not compliant with HIPAA regulations.
According to Rankiteo,Intrepid Museum is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Intrepid Museum operates primarily in the Museums, Historical Sites, and Zoos industry.
Intrepid Museum employs approximately 244 people worldwide.
Intrepid Museum presently has no subsidiaries across any sectors.
Intrepid Museum’s official LinkedIn profile has approximately 5,964 followers.
Intrepid Museum is classified under the NAICS code 712, which corresponds to Museums, Historical Sites, and Similar Institutions.
No, Intrepid Museum does not have a profile on Crunchbase.
Yes, Intrepid Museum maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/intrepid-museum.
As of December 03, 2025, Rankiteo reports that Intrepid Museum has experienced 1 cybersecurity incidents.
Intrepid Museum has an estimated 2,133 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Title: Data Breach at Intrepid Museum Foundation
Description: The Vermont Office of the Attorney General reported a data breach affecting the Intrepid Museum Foundation on June 10, 2024. The breach occurred on December 2, 2023, when an unauthorized third party gained access to the museum's network, potentially compromising personal information including names of affected individuals. The total number of individuals affected is 8 residents from Rhode Island.
Date Detected: 2023-12-02
Date Publicly Disclosed: 2024-06-10
Type: Data Breach
Attack Vector: Unauthorized Access
Threat Actor: Unauthorized Third Party
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Names of affected individuals
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information and .

Entity Name: Intrepid Museum Foundation
Entity Type: Non-profit Organization
Industry: Museum
Customers Affected: 8

Type of Data Compromised: Personal information
Number of Records Exposed: 8
Personally Identifiable Information: Names

Source: Vermont Office of the Attorney General
Date Accessed: 2024-06-10
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Vermont Office of the Attorney GeneralDate Accessed: 2024-06-10.
Last Attacking Group: The attacking group in the last incident was an Unauthorized Third Party.
Most Recent Incident Detected: The most recent incident detected was on 2023-12-02.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-06-10.
Most Significant Data Compromised: The most significant data compromised in an incident were Names of affected individuals and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was Names of affected individuals.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 8.0.
Most Recent Source: The most recent source of information about an incident is Vermont Office of the Attorney General.
.png)
vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.11.1, vllm has a critical remote code execution vector in a config class named Nemotron_Nano_VL_Config. When vllm loads a model config that contains an auto_map entry, the config class resolves that mapping with get_class_from_dynamic_module(...) and immediately instantiates the returned class. This fetches and executes Python from the remote repository referenced in the auto_map string. Crucially, this happens even when the caller explicitly sets trust_remote_code=False in vllm.transformers_utils.config.get_config. In practice, an attacker can publish a benign-looking frontend repo whose config.json points via auto_map to a separate malicious backend repo; loading the frontend will silently run the backend’s code on the victim host. This vulnerability is fixed in 0.11.1.
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. Prior to 12.5.0, by crafting a malicious URL, an attacker could access routes that are not allowed, even though the reply.from is defined for specific routes in @fastify/reply-from. This vulnerability is fixed in 12.5.0.
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 21.0.2, 20.3.15, and 19.2.17, A Stored Cross-Site Scripting (XSS) vulnerability has been identified in the Angular Template Compiler. It occurs because the compiler's internal security schema is incomplete, allowing attackers to bypass Angular's built-in security sanitization. Specifically, the schema fails to classify certain URL-holding attributes (e.g., those that could contain javascript: URLs) as requiring strict URL security, enabling the injection of malicious scripts. This vulnerability is fixed in 21.0.2, 20.3.15, and 19.2.17.
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.
Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an external fetch. This can be maliciously used by users for SSRF attacks. This vulnerability is fixed in 1.14.0.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.