Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Mastercard Cybersecurity & Fraud Prevention

Mastercard Cybersecurity & Fraud Prevention Vendor Cyber Rating & Cyber Score

mastercard.com

Mastercard Cybersecurity and fraud prevention combines data, AI, and technology solutions and expertise to combat fraud and protect your digital ecosystem.


MCFP A.I CyberSecurity Scoring

MCFP
Company Information
Website:https://www.mastercard.com/us/en/business/cybersecurity-fraud-prevention.html
Employees number:None
Number of followers:29,522
NAICS:52
Industry Type:Financial Services
Homepage:mastercard.com
MCFP Risk Score (AI oriented)
Between 700 and 749
logo
MCFPFinancial Services
Updated:
25/03/2026
734/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MCFP Global Score (TPRM)
xxxx
logo
MCFPFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MCFP
MCFPModerate
Current Score
734Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
736Before Incident
MAY 2026
735Before Incident
APRIL 2026
735Before Incident
MARCH 2026
734Before Incident
FEBRUARY 2026
732Before Incident
JANUARY 2026
732Before Incident
DECEMBER 2025
731Before Incident
NOVEMBER 2025
731Before Incident
OCTOBER 2025
730Before Incident
SEPTEMBER 2025
729Before Incident
AUGUST 2025
728Before Incident
JULY 2025
727Before Incident
OCTOBER 2024
761Before Incident
Cyber Attack
01 Oct 2024MCFP
MasterCard and Bradesco: Researchers Hijack Hacker Domain Using Name Server Delegation

Infoblox Researchers Hijack Malicious Push Notification Network via DNS Misconfiguration

715After Incident
HIGH-46
MASBRA1769236185
Infoblox Researchers Hijack Malicious Push Notification Network via DNS Misconfiguration Security researchers at Infoblox disrupted a large-scale malicious push notification operation by exploiting a DNS misconfiguration flaw known as "lame nameserver delegation" a technique dubbed "Sitting Ducks." Without directly compromising systems, the team intercepted over 57 million logs in just two weeks, exposing a global scam network targeting victims across 60+ languages with deceptive ads, brand impersonation, and fraudulent content. The operation leveraged abandoned domains misconfigured to use external nameservers lacking proper records allowing researchers to claim them without registration. Within hours, their servers were flooded with unencrypted traffic from victim devices, revealing detailed user metrics, device data, and ad delivery logs. The threat actor’s infrastructure sent duplicate notifications to victims, some of whom received 140+ alerts daily, with subscriptions lasting over a year. Key Findings: - Scale & Impact: The network delivered 52 million ads, yielding only 630 clicks (a 0.0012% click-through rate) and an estimated $350 daily revenue from monitored domains. - Targets: 50% of traffic focused on South Asia, particularly Bangladesh, India, Indonesia, and Pakistan. - Impersonation: Ads mimicked financial institutions like Bradesco, Sparkasse, MasterCard, Touch ‘n Go, and GCash, alongside fake security alerts and adult content. - Technique: The "Sitting Ducks" flaw previously used by groups like Vacant Viper enabled domain hijacking via traffic distribution systems (e.g., 404TDS), turning dormant domains into malware distribution hubs. The research underscores the risks of unmaintained DNS configurations, where abandoned domains become repeat targets for malicious campaigns. Organizations were urged to audit nameserver delegations to prevent similar exploits.
INCIDENT DETAILS -
TYPE
DNS Misconfiguration Exploitation
MOTIVATION
Financial gain (ad fraud, brand impersonation)
IMPACT
Financial Loss: $350 daily revenue (estimated from monitored domains)Data Compromised: User metrics, device data, ad delivery logs (unencrypted)Systems Affected: Victim devices receiving malicious push notificationsOperational Impact: Disruption of malicious push notification network by researchersConversion Rate Impact: 0.0012% click-through rate (630 clicks from 52 million ads)Brand Reputation Impact: Brand impersonation (Bradesco, Sparkasse, MasterCard, Touch ‘n Go, GCash)
DATA BREACH
Type Of Data Compromised: User metrics, device data, ad delivery logsNumber Of Records Exposed: 57 million+ logsSensitivity Of Data: Low to medium (no PII explicitly mentioned)Data Encryption: Unencrypted traffic intercepted

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MCFP ?
?
What was MCFP's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MCFP's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MCFP's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MCFP's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MCFP's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MCFP's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MCFP's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MCFP's A.I Rankiteo Cyber Score in October 2025 ?
?
What was MCFP's A.I Rankiteo Cyber Score in September 2025 ?
?
What was MCFP's A.I Rankiteo Cyber Score in August 2025 ?
?
What was MCFP's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on MCFP's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MCFP ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MCFP's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?