MCFP A.I CyberSecurity Scoring
MCFP
Company Information
Website:https://www.mastercard.com/us/en/business/cybersecurity-fraud-prevention.html
Employees number:None
Number of followers:29,522
NAICS:52
Industry Type:Financial Services
Homepage:mastercard.com
MCFP Risk Score (AI oriented)
Between 700 and 749
MCFPFinancial Services
Updated:
25/03/2026
25/03/2026
734/1000
Moderate
Ba
MCFP Global Score (TPRM)
xxxx
MCFPFinancial Services
Score locked

MCFPModerate
Current Score
734Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
736
MAY 2026
735
APRIL 2026
735
MARCH 2026
734
FEBRUARY 2026
732
JANUARY 2026
732
DECEMBER 2025
731
NOVEMBER 2025
731
OCTOBER 2025
730
SEPTEMBER 2025
729
AUGUST 2025
728
JULY 2025
727
OCTOBER 2024
761
Cyber Attack
01 Oct 2024 • MCFP
MasterCard and Bradesco: Researchers Hijack Hacker Domain Using Name Server Delegation
Infoblox Researchers Hijack Malicious Push Notification Network via DNS Misconfiguration
715
HIGH-46
MASBRA1769236185
Infoblox Researchers Hijack Malicious Push Notification Network via DNS Misconfiguration
Security researchers at Infoblox disrupted a large-scale malicious push notification operation by exploiting a DNS misconfiguration flaw known as "lame nameserver delegation" a technique dubbed "Sitting Ducks." Without directly compromising systems, the team intercepted over 57 million logs in just two weeks, exposing a global scam network targeting victims across 60+ languages with deceptive ads, brand impersonation, and fraudulent content.
The operation leveraged abandoned domains misconfigured to use external nameservers lacking proper records allowing researchers to claim them without registration. Within hours, their servers were flooded with unencrypted traffic from victim devices, revealing detailed user metrics, device data, and ad delivery logs. The threat actor’s infrastructure sent duplicate notifications to victims, some of whom received 140+ alerts daily, with subscriptions lasting over a year.
Key Findings:
- Scale & Impact: The network delivered 52 million ads, yielding only 630 clicks (a 0.0012% click-through rate) and an estimated $350 daily revenue from monitored domains.
- Targets: 50% of traffic focused on South Asia, particularly Bangladesh, India, Indonesia, and Pakistan.
- Impersonation: Ads mimicked financial institutions like Bradesco, Sparkasse, MasterCard, Touch ‘n Go, and GCash, alongside fake security alerts and adult content.
- Technique: The "Sitting Ducks" flaw previously used by groups like Vacant Viper enabled domain hijacking via traffic distribution systems (e.g., 404TDS), turning dormant domains into malware distribution hubs.
The research underscores the risks of unmaintained DNS configurations, where abandoned domains become repeat targets for malicious campaigns. Organizations were urged to audit nameserver delegations to prevent similar exploits.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for MCFP ??
What was MCFP's A.I Rankiteo Cyber Score in May 2026 ??
What was MCFP's A.I Rankiteo Cyber Score in April 2026 ??
What was MCFP's A.I Rankiteo Cyber Score in March 2026 ??
What was MCFP's A.I Rankiteo Cyber Score in February 2026 ??
What was MCFP's A.I Rankiteo Cyber Score in January 2026 ??
What was MCFP's A.I Rankiteo Cyber Score in December 2025 ??
What was MCFP's A.I Rankiteo Cyber Score in November 2025 ??
What was MCFP's A.I Rankiteo Cyber Score in October 2025 ??
What was MCFP's A.I Rankiteo Cyber Score in September 2025 ??
What was MCFP's A.I Rankiteo Cyber Score in August 2025 ??
What was MCFP's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on MCFP's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with MCFP ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view MCFP's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?