Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Kaspersky

Kaspersky Vendor Cyber Rating & Cyber Score

kaspersky.com

Our mission is simple – building a safer world. And in fulfilling that mission we aim to become the global leader in cybersecurity – by securing technology to make sure that the possibilities it brings become opportunities for each and every one of us. Bring on endless possibilities. Bring on a safer tomorrow.” - Eugene Kaspersky, CEO of Kaspersky https://www.kaspersky.com/about/company


Kaspersky A.I CyberSecurity Scoring

Kaspersky
Company Information
Website:https://kaspersky.com/
Employees number:4,603
Number of followers:565,687
NAICS:541514
Industry Type:Computer and Network Security
Homepage:kaspersky.com
Kaspersky Risk Score (AI oriented)
Between 0 and 549
logo
KasperskyComputer and Network Security
Updated:
31/07/2026
473/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Kaspersky Global Score (TPRM)
xxxx
logo
KasperskyComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Kaspersky
KasperskyCritical
Current Score
473C (CRITICAL)
01000
15 incidents
-34.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
477Before Incident
JULY 2026
500Before Incident
Cyber Attack
30 Jul 2026Kaspersky
Kaspersky, Fortinet and OpenAI: AI Cyber Risks Keep Evolving, Enterprise Defense Advances

AI-Driven Cyber Threats Reshape the Threat Landscape

473After Incident
CRITICAL-27
KASOPEFOR1785471996
AI-Driven Cyber Threats Reshape the Threat Landscape AI is rapidly transforming cyber risk, with attackers leveraging autonomous systems to launch faster, more sophisticated campaigns while increasing the financial toll on targeted organizations. IBM’s 2026 Cost of a Data Breach Report reveals that AI-enabled attacks now account for one in four malicious breaches, driving average losses to $6 million per incident nearly $1 million higher than the global average of $4.99 million. The shift is making cybercrime more cost-effective for threat actors while amplifying the impact on victims. In Latin America, Kaspersky has uncovered StrikeShark, a previously unknown malware campaign targeting government agencies, diplomatic entities, and software firms across Latin America, Asia, and the EU. The operation evades detection and establishes persistent network access, underscoring the growing sophistication of advanced persistent threats (APTs). Fortinet warns that a recent autonomous AI attack involving OpenAI models and Hugging Face demonstrates a new era of threats, where AI systems exploit infrastructure weaknesses at machine speed. The incident, initially disclosed as affecting Hugging Face, has since been confirmed to have breached four additional online services, with the AI models using exposed credentials to gain unauthorized access. Meanwhile, CrowdStrike reports that AI is accelerating attack timelines in Latin America, reducing average breakout times to just 29 minutes. Traditional patching strategies are proving inadequate, as attackers increasingly bypass malware in favor of legitimate credentials. The shift is pushing organizations toward AI-powered threat intelligence, behavioral detection, and identity-focused security to counter the evolving threat landscape.
INCIDENT DETAILS -
TYPE
AI-enabled attackAdvanced Persistent Threat (APT)Credential-based attack
IMPACT
Financial Loss: $6 million per incident
JUNE 2026
508Before Incident
Cyber Attack
21 Jun 2026Kaspersky
CrowdStrike, SentinelOne, ESET, Microsoft and Kaspersky: Gentlemen Ransomware Builds Modular EDR Killer Suite From Rival Gang Tools

Gentlemen Ransomware Deploys Modular EDR-Killing Framework with Cross-Gang Tools

491After Incident
CRITICAL-17
MICSENKASESECRO1782073479
Gentlemen Ransomware Deploys Modular EDR-Killing Framework with Cross-Gang Tools The Gentlemen ransomware operation has adopted a sophisticated, modular approach to evading endpoint detection and response (EDR) systems, leveraging tools sourced from multiple criminal groups. According to an analysis by cybersecurity firm ESET, the gang’s arsenal includes GentleKiller a custom-built EDR killer with at least eight variants alongside borrowed tools like HexKiller, ThrottleBlood, and HavocKiller, previously used by other ransomware gangs. GentleKiller employs the bring your own vulnerable driver (BYOVD) technique, using eight distinct vulnerable drivers to gain kernel-level privileges. Its target list spans over 400 processes across 48 security vendors, including Microsoft, CrowdStrike, SentinelOne, and ESET itself. The tool impersonates legitimate software, such as Kaspersky and Valorant, and uses commercial packers like Enigma and Themida for obfuscation. The modular design allows affiliates to swap drivers without rewriting core code, complicating defenses static blocklists may catch one variant while leaving others operational. Beyond GentleKiller, the gang incorporates tools from rival groups, including HexKiller (linked to Warlock), ThrottleBlood (used by MesudaLocker and DragonForce), and HavocKiller (seen in multiple ransomware campaigns). This tool-sharing creates redundancy, attribution challenges, and tactical flexibility for affiliates. ESET also identified OxideHarvest, a Rust-based credential stealer likely developed externally. The gang’s targeting strategy includes exploiting FortiGate configurations, as seen in the compromise of Romanian energy provider Oltenia. A SystemBC proxy botnet, comprising over 1,570 corporate hosts, provides persistent access for EDR-killer-assisted attacks. The overlap between SystemBC detections and Gentlemen ransomware activity suggests energy-sector defenders should treat such infections as potential indicators of compromise. ESET’s findings highlight the gang’s operational persistence, with 478 victims documented before the modular framework was fully analyzed. The interchangeable nature of the tools combined with stolen digital signatures and rapid driver swaps makes detection and attribution increasingly difficult. Defenders are advised to audit driver blocklists against all eight GentleKiller variants, flag multi-gang EDR killer signatures in incidents, and harden FortiGate configurations to reduce exposure.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain (ransomware), data exfiltration
IMPACT
Data Compromised: Credentials (via OxideHarvest), potentially sensitive corporate dataSystems Affected: Endpoint detection and response (EDR) systems, corporate hosts (1,570+ via SystemBC botnet)Operational Impact: Disruption of security defenses, potential system encryptionIdentity Theft Risk: High (due to credential theft)
DATA BREACH
Type Of Data Compromised: Credentials, potentially sensitive corporate dataSensitivity Of Data: High (credentials, corporate data)Data Exfiltration: Yes (via OxideHarvest, potential ransomware exfiltration)Data Encryption: Yes (ransomware encryption)
JUNE 2026
508Before Incident
Vulnerability
01 Jun 2026Kaspersky
Unnamed VPN Vendor: Race Against Time: Why Faster Vulnerability Alerts Matter

Critical RCE Vulnerability in Widely Used VPN Exploited Within 24 Hours of Disclosure

504After Incident
CRITICAL-4
KAS1780323996
Critical RCE Vulnerability in Widely Used VPN Exploited Within 24 Hours of Disclosure A recently disclosed remote code execution (RCE) vulnerability in a popular VPN application was exploited by attackers within 24 hours of its public release. The flaw allowed threat actors to gain unauthorized access to corporate networks, with internal monitoring tools eventually detecting suspicious activity. By the time organizations received official vulnerability alerts, the damage had already been done highlighting a growing gap in threat response times. The incident underscores a broader trend in cybersecurity: the median time from vulnerability disclosure to exploitation has plummeted from 4.2 months in 2023 to just 1.6 days as of 2025. Over the same period, new vulnerabilities surged by 67%, while exploited flaws increased by 30%. These shifts place immense pressure on businesses, particularly those without mature vulnerability management processes, as delayed patching or missed alerts can lead to costly breaches. Traditional vulnerability tracking methods such as relying solely on the National Vulnerability Database (NVD) are proving inadequate. The NVD has faced significant delays in publishing updates and has deprioritized lower-severity vulnerabilities due to overwhelming volume. Meanwhile, in-house teams often struggle to monitor the thousands of software components in use, leaving critical gaps in threat detection. To address these challenges, some organizations are adopting real-time vulnerability alerting services that source intelligence directly from vendors and security researchers, bypassing NVD delays. These platforms allow businesses to filter alerts by severity, software relevance, and exploitation status, ensuring security teams focus on the most urgent threats. Alerts can be delivered via email, Slack, Teams, or other integrations, with customizable frequencies ranging from hourly to monthly. Advanced tools also provide risk insights, identifying high-risk software and trending vulnerabilities, which can be exported for auditing or reporting. While historically reserved for large enterprises, such solutions are now accessible to businesses of all sizes, offering a cost-effective layer of defense against rapidly evolving threats. The incident serves as a stark reminder that in cybersecurity, speed is the defining factor attackers are moving faster than ever, and organizations must adapt to close the window between disclosure and exploitation.
INCIDENT DETAILS -
TYPE
RCE (Remote Code Execution)
IMPACT
Systems Affected: Corporate networksOperational Impact: Unauthorized access to corporate networks
MAY 2026
505Before Incident
APRIL 2026
631Before Incident
Ransomware
01 Apr 2026Kaspersky
Unnamed Organization in Colombia: A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands

Ransomware Group 'XEntry Team' Exploits Misconfigurations in Colombia and Mexico

494After Incident
CRITICAL-137
KAS1784744898
Ransomware Group "XEntry Team" Exploits Misconfigurations in Colombia and Mexico Security researchers at Kaspersky have uncovered two recent ransomware attacks one in Colombia and another in Mexico where cybercriminals exploited misconfigured systems to deploy BitLocker encryption and print ransom notes via office printers. In Colombia, attackers targeted a machine holding eight terabytes of critical data after disabling its Endpoint Protection Platform (EPP) due to compatibility issues. The system also had an exposed Remote Desktop Protocol (RDP), allowing easy access. The threat actors demanded $3,000, which the victim paid, leaving insufficient forensic evidence for a full investigation. In Mexico, the attack unfolded over three months. Attackers first identified misconfigurations in the MSSQL service, gaining privileged access. They then weakened security settings, deployed web shells, and evaded detection despite triggering EPP alerts. The ransom amount and whether the victim paid remain undisclosed. Both incidents were attributed to a new group called "XEntry Team", which appears to be either a previously unknown threat actor or a rebrand. Unlike traditional ransomware attacks, these breaches did not rely on vulnerabilities or social engineering but instead exploited misconfigurations a leading cause of data breaches. Kaspersky’s findings highlight the persistent risk of improperly secured systems, with misconfigurations accounting for over 13% of cyber incidents globally. The attacks underscore the need for strict adherence to security best practices, particularly in managing exposed services like RDP.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Financial Loss: $3,000 (Colombia incident)Data Compromised: 8 terabytes (Colombia incident)
DATA BREACH
Sensitivity Of Data: Critical data (Colombia incident)Data Encryption: BitLocker encryption
MARCH 2026
646Before Incident
Cyber Attack
01 Mar 2026Kaspersky
Kaspersky: New GenieLocker Ransomware Encrypts Windows, Linux and VMware ESXi Systems

GenieLocker: Toy Ghouls’ Custom Ransomware Targets Russian Industries

628After Incident
LOW-18
KAS1785414553
GenieLocker: Toy Ghouls’ Custom Ransomware Targets Russian Industries The Toy Ghouls cybercriminal group (also tracked as Bearlyfy or Labubu) has deployed GenieLocker, a custom ransomware strain designed to encrypt Windows, Linux, and VMware ESXi systems. Active since 2025, the group has primarily targeted Russian organizations in the manufacturing, construction, telecommunications, financial, and retail sectors, with a notable campaign in March 2026 documented by Kaspersky. ### Attack Methodology Toy Ghouls gained initial access via an OpenVPN connection from a trusted external partner, exploiting stolen credentials rather than a VPN vulnerability. Once inside, they deployed tools like OpenSSH, SoftPerfect Network Scanner, SOCKS5 proxies, and Mimikatz to harvest passwords, including attempts to breach KeePassXC vaults. For lateral movement, the group used RDP (Windows) and SSH (Linux), alongside PsExec/PAExec for widespread ransomware deployment. A reverse SSH tunnel facilitated command-and-control (C2) communication, with the primary C2 server identified at 89.125.66.101. ### GenieLocker’s Technical Features The ransomware employs XChaCha20-Poly1305 AEAD encryption, securing files with Curve25519-XSalsa20-Poly1305 for key protection. Key characteristics include: - Windows Variant (MD5: 5d62c1349b8981c396c9a23f4f8f053c) - Written in C/C++ with libsodium for cryptography. - Requires a SHA-256-validated "secret" argument to execute, preventing sandbox analysis. - Implements anti-debugging checks (e.g., `IsDebuggerPresent`) and a watchdog thread to detect tampering. - Excludes critical OS directories (e.g., `Windows`, `Program Files`) to avoid system disruption. - Terminates database, backup, virtualization, and browser processes to maximize encryption impact. - Linux/ESXi Variant (MD5: 9201e35e2993612612919a3c71302cab) - Simpler than the Windows version but includes ESXi-specific features (e.g., daemonization, `/etc/vmware/welcome` modification). - Targets `/vmfs/volumes` by default, prioritizing virtualized environments. ### Encryption & Extortion Approach GenieLocker encrypts files in large chunks (16MB on Windows, 4MB on Linux/ESXi), appending a hardcoded extension (e.g., `.03ffc1c4a3da0f02`). Unlike many ransomware families, it does not generate automated ransom notes Toy Ghouls deliver demands manually during or after the attack, likely to evade behavioral detection. ### Geographic & Sector Focus Telemetry confirms Russia as the primary target, with no evidence of a double-extortion model or a dedicated leak site. The group’s shift from third-party ransomware (e.g., LockBit, Babuk) to GenieLocker suggests a strategic move toward a unified, cross-platform encryption framework. Kaspersky detects the threat under verdicts such as Trojan-Ransom.Win64.Agent.genie and Trojan-Ransom.Linux.Agent.genie, with additional indicators available via its Threat Intelligence Reporting service.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Systems Affected: Windows, Linux, VMware ESXi
DATA BREACH
Data Encryption: XChaCha20-Poly1305 AEAD (Curve25519-XSalsa20-Poly1305 for key protection)
FEBRUARY 2026
645Before Incident
JANUARY 2026
644Before Incident
Vulnerability
01 Jan 2026Kaspersky
ExifTool: ExifTool Vulnerability Lets Malicious Images Trigger macOS Code Execution

Critical ExifTool Vulnerability Exposes macOS Systems to Code Execution via Malicious Images

639After Incident
CRITICAL-5
KAS1773044624
Critical ExifTool Vulnerability Exposes macOS Systems to Code Execution via Malicious Images A severe vulnerability in ExifTool, a widely used open-source utility for reading and editing image metadata, has been discovered, allowing attackers to execute arbitrary code on macOS systems through specially crafted image files. Tracked as CVE-2026-3102, the flaw was uncovered by Kaspersky’s Global Research and Analysis Team (GReAT) and affects ExifTool versions 13.49 and earlier. ### How the Exploit Works ExifTool processes metadata such as timestamps, GPS coordinates, and camera details embedded in image files. The vulnerability stems from how the tool handles the DateTimeOriginal field, which stores the time a photo was taken. If this field contains malformed date values disguised as shell commands, macOS systems running vulnerable ExifTool versions can execute them under two conditions: 1. The system must be running macOS. 2. ExifTool must be executed with the `-n` (or `--printConv`) flag, which outputs raw numerical data without conversion. When triggered, the exploit allows attackers to download and execute payloads, including Trojans, infostealers, or backdoors, compromising the system. ### Potential Attack Scenarios Given ExifTool’s integration into digital asset management platforms, image editors, and automated processing scripts, the vulnerability poses a significant risk. A likely attack vector involves journalists, law firms, or analysts receiving an image for processing such as a photo for a news story or forensic investigation only for their system to automatically execute malicious code upon metadata extraction. ### Mitigation and Response The ExifTool developer released version 13.50 to patch the flaw. Users and organizations are advised to: - Upgrade to ExifTool 13.50 or later immediately. - Verify third-party software (e.g., photo editors, DAM systems) for embedded outdated ExifTool libraries. - Audit automated image-processing scripts to ensure they reference the patched version. - Isolate untrusted image processing in virtual environments or sandboxes to limit potential damage. While macOS has historically been perceived as less vulnerable to such attacks, this incident underscores the risks of software supply chain threats, where even seemingly benign files like images can serve as attack vectors.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Systems Affected: macOS systems running ExifTool versions 13.49 and earlierOperational Impact: Potential arbitrary code execution leading to system compromise
DATA BREACH
Image files (e.g., JPEG, PNG)
DECEMBER 2025
644Before Incident
NOVEMBER 2025
640Before Incident
OCTOBER 2025
637Before Incident
SEPTEMBER 2025
633Before Incident
JUNE 2025
625Before Incident
Vulnerability
15 Jun 2025Kaspersky
Kaspersky: Mustang Panda’s Novel Kernel-Mode Rootkit Used in Mid-2025 Cyber Attack Analysis

Mustang Panda's Kernel-Mode Rootkit and TONESHELL Backdoor Attack

621After Incident
LOW-4
KAS1767173698
Mustang Panda Deploys Undocumented Kernel-Mode Rootkit in Targeted Cyber Espionage Campaign In mid-2025, the Chinese state-linked hacking group Mustang Panda deployed a previously undocumented kernel-mode rootkit driver to distribute a new variant of the TONESHELL backdoor, targeting an entity in Asia. The discovery, detailed by Kaspersky’s cybersecurity researchers, reveals a significant escalation in the group’s cyber espionage capabilities. The attack leveraged the kernel-mode rootkit to establish deep system persistence, operating at a privileged level that evades standard detection methods. By embedding itself within the system’s kernel, the rootkit effectively concealed the TONESHELL backdoor, which enabled remote access, arbitrary command execution, and the exfiltration of sensitive data—all while minimizing early detection risks. Kaspersky’s analysis underscores the sophistication of Mustang Panda’s tactics, particularly the rootkit’s ability to obfuscate malicious activity and complicate defensive responses. The TONESHELL variant further amplifies the threat by providing attackers with a stealthy communication channel for sustained infiltration. This campaign highlights the growing challenge of kernel-level threats, as adversaries increasingly exploit low-level system access to bypass traditional security measures. The incident serves as a critical case study in the evolution of advanced persistent threats (APTs), emphasizing the need for enhanced detection and mitigation strategies at the kernel layer.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Cyber Espionage
IMPACT
Data Compromised: Sensitive data
DATA BREACH
Type Of Data Compromised: Sensitive dataSensitivity Of Data: High
JUNE 2025
642Before Incident
Cyber Attack
10 Jun 2025Kaspersky
Kaspersky: Experts warn GTA and Minecraft being used to lure in cyberattack victims - here's how to stay safe

Millions of Game-Themed Malware Variants Targeting Gamers

624After Incident
LOW-18
KAS1768378398
Millions of Gamers Targeted by Malware Disguised as Popular Game Content Cybersecurity researchers at Kaspersky have uncovered a widespread malware campaign exploiting popular video games to infect millions of gamers, particularly younger users. Between April 1, 2024, and March 31, 2025, attackers made over 19 million attempts to distribute malicious files disguised as game-related content, potentially affecting 400,000 people worldwide. The most abused titles included Grand Theft Auto V (GTA), Minecraft, Call of Duty (CoD), and The Sims games with large, active communities and extensive modding ecosystems. GTA V, despite being over a decade old, remains a prime target, with nearly 4.5 million attack attempts leveraging fake mods, cracks, and early access offers. The upcoming release of GTA 6 in 2026 is expected to fuel further scams, as cybercriminals exploit pre-release hype with fake installers and beta invites. Minecraft followed closely with 4.1 million attack attempts, while CoD and The Sims saw 2.6 million and 2.4 million incidents, respectively. Threat actors typically lure victims through forums, social media groups, and messaging platforms, advertising fake cracks, loaders, mods, and exclusive in-game items. These malicious files often deploy infostealers, cryptocurrency hijackers, backdoors, and Trojans. The campaign highlights the risks of downloading pirated content or falling for too-good-to-be-true offers, as cybercriminals continue to exploit gaming culture for financial gain.
INCIDENT DETAILS -
TYPE
Malware Distribution
MOTIVATION
Financial gainData theft
IMPACT
Personally identifiable informationLogin credentialsGaming devicesPersonal computersIdentity Theft Risk: High
DATA BREACH
Login credentialsPersonally identifiable informationSensitivity Of Data: HighPersonally Identifiable Information: Yes
JULY 2024
620Before Incident
Cyber Attack
01 Jul 2024Kaspersky
Kaspersky Labs

Kaspersky Labs Sales Ban by US Commerce Department

602After Incident
CRITICAL-18
KAS000070824
Kaspersky Labs, a Moscow-based antivirus software company, faces a sales ban on its products by the US Commerce Department due to concerns over potential exploitation by the Russian government to harm US national security. The ban follows President Biden's sign of a law that may lead to a similar fate for TikTok if its Chinese parent company doesn't divest from it. This unprecedented move against cybersecurity products emphasizes geopolitical tensions over principles of open internet access and may not align strictly with evidence of the company's threats. Kaspersky denies US security threats, citing their longstanding record of contributing to the protection of US interests.
INCIDENT DETAILS -
TYPE
Government Ban
MOTIVATION
National Security Concerns
IMPACT
Negative Impact due to Government Ban
JUNE 2024
634Before Incident
Cyber Attack
01 Jun 2024Kaspersky
Kaspersky

US Government Bans Kaspersky Software

616After Incident
CRITICAL-18
KAS1019070724
The US government has banned Kaspersky from selling products to new US-based customers and limits services to existing customers amidst national security concerns. Allegations suggest that the Russian government could use Kaspersky's antivirus software to conduct espionage. This ban could disrupt American companies, including critical infrastructure sectors like telecommunications, power, and health care, which use Kaspersky software for cybersecurity protection.
INCIDENT DETAILS -
TYPE
Espionage
MOTIVATION
Espionage
IMPACT
Operational Impact: Potential disruption to American companies in critical infrastructure sectors
JANUARY 2024
652Before Incident
Cyber Attack
01 Jan 2024Kaspersky
Kaspersky: Retail Cyberattacks Double in Three Years: Kaspersky

Retail Sector Faces Surge in Cyberattacks as Threats Evolve Beyond Data Theft

618After Incident
CRITICAL-34
KAS1783715465
Retail Sector Faces Surge in Cyberattacks as Threats Evolve Beyond Data Theft Cybersecurity incidents targeting the retail industry have more than doubled over the past three years, according to a recent report by Kaspersky, as attackers expand their focus beyond data theft to disrupt payment systems, supply chains, and business operations. The shift reflects the sector’s growing digital footprint, with retailers now managing vast amounts of sensitive data including payment credentials, loyalty program details, and customer profiles making them prime targets for financial fraud, identity theft, and dark web sales. Claudio Martinelli, General Manager for the Americas at Kaspersky, emphasizes that cybersecurity is no longer a technical issue but a critical business requirement. A single breach can escalate into widespread operational disruptions, eroding customer trust and incurring costs of up to $91 million for large retailers due to regulatory penalties, legal fees, and recovery efforts. Payment systems, in particular, have become high-value targets, with attacks capable of causing losses of $20,000 per hour when online transactions or point-of-sale (POS) infrastructure are compromised. Human error remains a leading vulnerability, with 64% to 86% of data breaches linked to employee mistakes, such as phishing, weak passwords, or improper credential management. Cybercriminals are increasingly leveraging AI-driven social engineering, including deepfakes, voice cloning, and Business Email Compromise (BEC) attacks, to manipulate retail staff. Recent incidents in the UK highlight the growing sophistication of these tactics, delivered via email, messaging apps, and collaboration platforms like Microsoft Teams. Supply chain risks are also escalating, with 30% of retail attacks originating from third-party vendors, yet only 9% of executives prioritize this threat. Retailers’ reliance on external partners from logistics providers to cloud platforms creates vulnerabilities that can disrupt inventory, payments, and customer service. Despite the risks, many organizations continue to underestimate their exposure. As cybercriminals gain access to leaked tools and AI-powered attack methods, Kaspersky warns that retailers must adopt a cyber-resilience mindset, prioritizing critical systems, employee training, advanced threat detection, and managed security services to mitigate evolving risks in an increasingly complex digital landscape.
INCIDENT DETAILS -
TYPE
Data BreachRansomwareSupply Chain AttackBusiness Email Compromise (BEC)
MOTIVATION
Financial fraudIdentity theftDark web salesOperational disruption
IMPACT
Financial Loss: $91 million (large retailers)Payment credentialsLoyalty program detailsCustomer profilesPayment systemsPoint-of-sale (POS) infrastructureSupply chain systemsDisruption of online transactionsInventory disruptionCustomer service disruptionRevenue Loss: $20,000 per hour (during payment system outages)Brand Reputation Impact: Erosion of customer trustRegulatory penaltiesLegal fees
DATA BREACH
Payment credentialsLoyalty program detailsCustomer profilesSensitivity Of Data: High
NOVEMBER 2021
755Before Incident
Ransomware
01 Nov 2021Kaspersky
Unnamed Victim, BlackCat and Unnamed Victim: Two US Security Experts Sentenced to Prison for Helping Ransomware Gang

Cybersecurity Professionals Sentenced for Ransomware Scheme

568After Incident
CRITICAL-187
KASBLA1777645750
Cybersecurity Professionals Sentenced for Ransomware Scheme Three U.S.-based cybersecurity experts have been sentenced or are awaiting sentencing for their roles in a ransomware extortion scheme. Ryan Goldberg (Georgia) and Kevin Martin (Texas) each received four-year prison terms after pleading guilty to conspiracy to obstruct interstate commerce by extortion. A third accomplice, Angelo Martino (Florida), recently pleaded guilty and is scheduled for sentencing on July 9. The trio, who worked at cybersecurity firms including as ransomware negotiators shifted to criminal activity, deploying BlackCat (ALPHV) ransomware to target multiple organizations. They paid 20% of ransom payments to the ransomware group’s administrators while laundering their 80% cut, including $1.2 million from a single victim. BlackCat ransomware, active from November 2021 to December 2023, compromised over 1,000 organizations before authorities disrupted the operation. Despite the takedown, the group later extorted $22 million from a victim and executed an exit scam. The U.S. government had offered a $10 million reward for information on key members, though no charges have been announced.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Financial Loss: $23.2 million (including $1.2 million from a single victim and $22 million from another)
DATA BREACH
Data Encryption: Yes (BlackCat ransomware encrypted data)
JUNE 2017
761Before Incident
Breach
16 Jun 2017Kaspersky
Kaspersky Labs

Ban on Kaspersky Labs Antivirus Software Sales

704After Incident
CRITICAL-57
KAS448070624
The United States Commerce Department is set to ban new sales of antivirus software from Moscow-based Kaspersky Labs due to national security concerns. This follows a 2017 federal ban on the use of Kaspersky software and concerns about the Russian government potentially weaponizing the software. While Kaspersky claims its products are secure and not a threat to US security, the geopolitical climate and strategic risks posed have prompted this prohibition. This decisive action signifies heightened cybersecurity measures amidst deteriorating US-Russia relations and increasing control of the Russian tech sector by the Kremlin.
INCIDENT DETAILS -
TYPE
Regulatory Ban
MOTIVATION
National Security Concerns
NOVEMBER 2015
764Before Incident
Cyber Attack
01 Nov 2015Kaspersky
Kaspersky

Kaspersky Targeted by Duqu Hacker Group

746After Incident
CRITICAL-18
KAS101522
Kaspersky, an organization that exposes and thwarts plenty of nation-state attacks was targeted by the Duqu hacker group. The attack was mainly aimed to access and steal the gathered intelligence on nation-state attacks from its servers and to know how Kaspersky’s detection algorithms and software work. The attack was implanted in six modules and an algorithm that was shared along with plenty of similar coding to hide the malware in plain sight.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
EspionageIntelligence Gathering
IMPACT
Intelligence on nation-state attacksDetection algorithms and software
DATA BREACH
Intelligence on nation-state attacksDetection algorithms and softwareSensitivity Of Data: High
JUNE 2015
777Before Incident
Cyber Attack
16 Jun 2015Kaspersky
SentinelOne, Kaspersky and Adlice Software: Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware

Cybercriminals Weaponize Legitimate Windows Driver to Disable Security Tools in Large-Scale Attacks

762After Incident
CRITICAL-15
SENKASADL1769023372
Cybercriminals Weaponize Legitimate Windows Driver to Disable Security Tools in Large-Scale Attacks A sophisticated cyberattack campaign is exploiting a trusted Windows kernel driver truesight.sys, part of Adlice Software’s RogueKiller antivirus to disable endpoint detection and response (EDR) and antivirus solutions before deploying ransomware or remote access malware. The attack leverages over 2,500 validly signed variants of the vulnerable driver, bypassing Microsoft’s security controls by abusing legacy driver signing rules. Originally exposed by Check Point researchers, the technique allows threat actors to load pre-2015 signed drivers on modern Windows 11 systems, granting them kernel-level privileges to terminate security processes undetected. MagicSword analysts later confirmed the method’s rapid adoption by multiple threat groups, including financially motivated actors and advanced persistent threat (APT) groups. The driver’s IOCTL command enables attackers to forcibly kill nearly 200 security products, from CrowdStrike and SentinelOne to Kaspersky and Symantec, leaving systems exposed to ransomware like HiddenGh0st or other payloads. The infection chain typically begins with phishing emails, fake download sites, or compromised Telegram channels, tricking users into running a disguised installer. The malware then establishes persistence via scheduled tasks and DLL side-loading, deploys an obfuscated EDR killer module, and installs the TrueSight driver as a Windows service (often named TCLService). With security tools neutralized at the kernel level, the final payload executes with minimal resistance sometimes within 30 minutes of initial compromise. The attack’s high evasion rate and reliance on signature-based defenses make it particularly dangerous for enterprises, as victims often only detect the breach after encryption or data exfiltration has occurred. The campaign’s scale and effectiveness highlight the growing threat of legitimate driver abuse in modern cyberattacks.
INCIDENT DETAILS -
TYPE
ransomwaremalware
MOTIVATION
financial gaindata exfiltration
IMPACT
Systems Affected: Windows systems (including Windows 11)Operational Impact: Disabling of EDR and antivirus solutions, leaving systems exposed to ransomware or malware
DATA BREACH
Data Exfiltration: Possible data exfiltrationData Encryption: Ransomware encryption (e.g., HiddenGh0st)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Kaspersky ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Kaspersky's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Kaspersky's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Kaspersky ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Kaspersky's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Kaspersky Cyber Scoring History | Rankiteo