Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
La Poste Groupe

La Poste Groupe Vendor Cyber Rating & Cyber Score

lapostegroupe.com

Premier réseau commercial de proximité en France, le groupe La Poste est organisé en 4 branches d’activité : Services-Courrier-Colis, Banque et Assurance, Distributeur physique et numérique, GeoPost/DPDGroup pour l'international. Présent dans plus de 63 pays, sur 5 continents, il a réalisé un chiffre d’affaires de 34,1 Mds€ en 2023. En 2021, le groupe La Poste est devenu la première entreprise publique à adopter la qualité de société à mission. 4 engagements sociétaux sont désormais inscrits dans ses statuts : • Contribuer au développement et à la cohésion des territoires • Favoriser l’inclusion sociale • Promouvoir un numérique éthique, inclusif et frugal • Œuvrer à l’accélération de la transition écologique pour tous Le groupe La


LPG A.I CyberSecurity Scoring

LPG
Company Information
Website:https://www.lapostegroupe.com/fr
Employees number:55,442
Number of followers:231,239
NAICS:47
Industry Type:Transportation, Logistics, Supply Chain and Storage
Homepage:lapostegroupe.com
LPG Risk Score (AI oriented)
Between 700 and 749
logo
LPGTransportation, Logistics, Supply Chain and Storage
Updated:
01/04/2026
746/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
LPG Global Score (TPRM)
xxxx
logo
LPGTransportation, Logistics, Supply Chain and Storage
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

LPG
LPGModerate
Current Score
746Ba (MODERATE)
01000
2 incidents
-15 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
748Before Incident
APRIL 2026
747Before Incident
MARCH 2026
745Before Incident
FEBRUARY 2026
745Before Incident
JANUARY 2026
744Before Incident
DECEMBER 2025
758Before Incident
Cyber Attack
29 Dec 2025LPG
La Poste and Baker University: 29th December – Threat Intelligence Report

Romanian Waters Ransomware Attack

743After Incident
CRITICAL-15
LA-BAK1767116583
Cybersecurity Roundup: Major Breaches, Ransomware, and Critical Vulnerabilities (Week of December 29) The past week saw a surge in cyberattacks targeting critical infrastructure, financial services, and high-profile organizations, alongside the disclosure of severe vulnerabilities in widely used software. Major Breaches and Attacks Romania’s national water management authority, Romanian Waters, fell victim to a ransomware attack encrypting nearly 1,000 systems across its national and regional offices. While operational technology controlling water infrastructure remained unaffected, the incident disrupted geographic information systems, databases, email, and web servers. No data leakage was reported. France’s postal service, La Poste, experienced a cyberattack disrupting online parcel tracking, mail distribution, and banking services for La Banque Postale customers. The pro-Russian hacktivist group NoName057(16) claimed responsibility, though no evidence of data compromise emerged. Insurance giant Aflac confirmed a June data breach exposing sensitive files—including insurance claims, health data, and Social Security numbers—of 22.7 million U.S. individuals. The attack was attributed to the Scattered Spider threat group. Nissan disclosed a breach affecting 21,000 customers after unauthorized access to Red Hat data servers exposed personal details (names, addresses, emails, and sales data). The Crimson Collective claimed the initial breach, with ShinyHunters later leaking samples of the stolen data. Trust Wallet, a non-custodial cryptocurrency wallet, reported a compromised Chrome extension update (version 2.68.0) that exfiltrated seed phrases to a malicious domain, resulting in at least $7 million in losses. Ubisoft’s Rainbow Six Siege suffered an attack where threat actors manipulated internal systems to distribute $13.33 million in in-game currency, unlock restricted cosmetics, and bypass bans. Baker University confirmed a breach exposing sensitive data—including Social Security numbers, financial details, and medical records—of 53,624 students, alumni, and staff. Critical Vulnerabilities A high-severity flaw (CVE-2025-14847, "MongoBleed") in MongoDB Server (versions 4.0–8.2.3) allows unauthenticated attackers to exploit a zlib implementation flaw, potentially accessing uninitialized heap memory and executing arbitrary code. A critical serialization injection vulnerability (CVE-2025-68664, CVSS 9.3) in LangChain Core enables attackers to extract secrets, inject prompts, or execute arbitrary code via unescaped user-controlled dictionaries. A buffer overflow vulnerability (CVE-2025-68615, CVSS 9.8) in Net-SNMP’s snmptrapd daemon permits remote code execution or service crashes via specially crafted packets. Patches are available in versions 5.9.5 and 5.10.pre2. Threat Intelligence A phishing campaign abused Google Cloud Application Integration to send 9,000 spoofed Google notification emails, redirecting victims to a Microsoft-themed credential-harvesting site. Targets included manufacturing, technology, and finance sectors across the U.S., Asia-Pacific, and Europe. Researchers uncovered a two-year Evasive Panda campaign using DNS poisoning to deliver MgBot malware via fake updaters. The attack employed multi-stage shellcode, hybrid encryption, and DLL sideloading, with persistence achieved through signed system processes and hardcoded C2 servers.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: None reportedSystems Affected: Nearly 1,000 computer systems (geographic information systems, databases, email, web servers, Windows workstations)Operational Impact: Key IT services disrupted across the organization
DATA BREACH
Data Exfiltration: NoData Encryption: Yes (ransomware)
NOVEMBER 2025
758Before Incident
OCTOBER 2025
757Before Incident
SEPTEMBER 2025
756Before Incident
AUGUST 2025
756Before Incident
JULY 2025
755Before Incident
JULY 2022
789Before Incident
Ransomware
01 Jul 2022LPG
La Poste Groupe

Ransomware Attack on La Poste

715After Incident
CRITICAL-74
LAP0711722
French mobile phone network La Poste suffered a ransomware attack that crippled its administrative and management services. LockBit ransomware took responsibility for the attack by adding its name to the list of victims. The attackers affected the website of the company and accessed the customer data from the employee account, however, the service was not much affected. .
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial Gain
IMPACT
Customer DataAdministrative ServicesManagement ServicesWebsiteOperational Impact: Minimal
DATA BREACH
Customer Data

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for LPG ?
?
What was LPG's A.I Rankiteo Cyber Score in May 2026 ?
?
What was LPG's A.I Rankiteo Cyber Score in April 2026 ?
?
What was LPG's A.I Rankiteo Cyber Score in March 2026 ?
?
What was LPG's A.I Rankiteo Cyber Score in February 2026 ?
?
What was LPG's A.I Rankiteo Cyber Score in January 2026 ?
?
What was LPG's A.I Rankiteo Cyber Score in December 2025 ?
?
What was LPG's A.I Rankiteo Cyber Score in November 2025 ?
?
What was LPG's A.I Rankiteo Cyber Score in October 2025 ?
?
What was LPG's A.I Rankiteo Cyber Score in September 2025 ?
?
What was LPG's A.I Rankiteo Cyber Score in August 2025 ?
?
What was LPG's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on LPG's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with LPG ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view LPG's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?