Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Michelin

Michelin Vendor Cyber Rating & Cyber Score

michelin.com

Michelin is a world-leading manufacturer of life-changing composites and experiences. Pioneering materials science over more than 130 years, Michelin is uniquely positioned to make decisive contributions to human progress and a more sustainable world. Drawing on technological leadership in polymer composites, Michelin is constantly innovating to manufacture high-quality tires and components for critical applications in demanding fields as varied as mobility, construction, aeronautics, low-carbon energies, and healthcare. The care we put into our products and our intimate knowledge of consumer habits enable Michelin to offer its customers exceptional experiences, whether in terms of connected solutions and artificial intelligence for


Michelin A.I CyberSecurity Scoring

Michelin
Company Information
Website:http://www.michelin.com
Employees number:52,207
Number of followers:1,035,719
NAICS:3361
Industry Type:Motor Vehicle Manufacturing
Homepage:michelin.com
Michelin Risk Score (AI oriented)
Between 550 and 599
logo
MichelinMotor Vehicle Manufacturing
Updated:
04/04/2026
577/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Michelin Global Score (TPRM)
xxxx
logo
MichelinMotor Vehicle Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Michelin
MichelinVery Poor
Current Score
577Ca (VERY POOR)
01000
3 incidents
-73.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
591Before Incident
MAY 2026
586Before Incident
APRIL 2026
586Before Incident
MARCH 2026
681Before Incident
Breach
13 Mar 2026Michelin
Shoppers Drug Mart, President’s Choice, Loblaw, No Frills and PC Optimum: “Threat Actor” on the dark web claims Loblaw’s “low-level” data breach is a much larger threat

Alleged Massive Data Breach at Loblaw

579After Incident
CRITICAL-102
NO-SHOPRELOB1773534483
Loblaw Faces Alleged Massive Data Breach as Threat Actor Demands Response A threat actor operating under the handle "igotafeeling" on the DarkWeb Informer forum has claimed to have breached Loblaw, Canada’s largest food and pharmacy retailer, which owns brands like President’s Choice, No Frills, Shoppers Drug Mart, Real Canadian Superstore, and the PC Optimum loyalty program. The actor alleges possession of over 1.8 billion records, including: - 75.1 million Salesforce customer records (names, emails, phone numbers, addresses, loyalty IDs, and health card numbers) - 724.9 million Shoppers Drug Mart records (passwords, tokens, loyalty IDs, payment details, and full credit card numbers with expiry dates) - 129.9 million pharmacy fill requests (prescription numbers and patient IDs) - 120.4 million e-commerce fraud-feed records (payment card BINs, last-four digits, and expiry dates) - 20.2 million Delivery Ops Portal records (orders, deliveries, and postal codes) - 3,014 GitLab projects containing Loblaw’s full source code - 19.3 million Oracle identity records (MFA device details and credentials) - 55.3 million marketing and email records across 673 tables The threat actor has given Loblaw until March 19 to respond, accusing the company of "ghosting" them and dismissing customer and investor concerns. They have also invited media organizations to verify the data’s authenticity. In response, Loblaw issued a March 12 press release, labeling the incident a "low-level data breach" and stating that only "basic customer information" (names, phone numbers, and emails) may have been accessed. The company explicitly denied evidence of financial or credit card data compromise directly contradicting the threat actor’s claims. While the breach remains unverified, the scale of the alleged exposure if confirmed would rank among the largest in Canadian history. The situation mirrors past high-profile breaches (e.g., T-Mobile, Equifax, Capital One), where initial corporate statements downplayed impact before later revelations proved otherwise. Loblaw customers with PC Optimum accounts, Shoppers Drug Mart loyalty cards, or prescription histories may be affected if the claims hold true. The deadline for Loblaw’s response is six days away.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion (response demanded by March 19)
IMPACT
Data Compromised: Over 1.8 billion records allegedly exposedSalesforceShoppers Drug Mart systemsGitLab projectsOracle identity systemsE-commerce platformsBrand Reputation Impact: Potential significant impact if claims are verifiedIdentity Theft Risk: High (health card numbers, prescription IDs, PII)Payment Information Risk: High (full credit card numbers with expiry dates)
DATA BREACH
Customer records (names, emails, phone numbers, addresses, loyalty IDs)Health card numbersPharmacy fill requests (prescription numbers, patient IDs)Payment details (full credit card numbers with expiry dates, BINs, last-four digits)Source code (GitLab projects)MFA device details and credentials (Oracle identity records)Marketing and email recordsNumber Of Records Exposed: 1.8 billion (alleged)Sensitivity Of Data: High (PII, financial data, health information, source code)Data Exfiltration: Alleged (data sold on dark web if claims are true)Personally Identifiable Information: Yes (names, emails, phone numbers, addresses, health card numbers, prescription IDs)
FEBRUARY 2026
752Before Incident
JANUARY 2026
792Before Incident
Breach
01 Jan 2026Michelin
Michelin, Oracle, Korean Air and Madison Square Garden: Michelin Confirms Data Breach Linked to Oracle EBS Attack

Michelin Data Breach in Cl0p’s Oracle EBS Cyberattack Campaign

752After Incident
CRITICAL-40
MADMICKORORA1773232260
Michelin Confirms Data Breach in Cl0p’s Oracle EBS Cyberattack Campaign Tire manufacturer Michelin has confirmed a data breach linked to the ongoing cybercrime campaign targeting organizations using Oracle’s E-Business Suite (EBS). The Cl0p ransomware and extortion group, believed to be operated by the FIN11 threat actor cluster, exploited zero-day vulnerabilities in Oracle EBS to access sensitive data from over 100 organizations, including Michelin. Michelin acknowledged the incident, stating that while its systems were protected by robust security measures, attackers leveraged an Oracle EBS zero-day flaw to infiltrate its network. The company reported that only a "small, localized volume of data" was compromised, with no sensitive or technical IT information affected. No ransomware was deployed, and global operations remained unaffected. Despite Michelin’s assurance that the breach was contained, Cl0p published over 315GB of allegedly stolen files on its leak site. Metadata analysis suggests the data originated from an Oracle EBS environment. Michelin emphasized its swift response, confirming that corrective actions were taken and the vulnerability has since been patched. This attack follows similar breaches at Madison Square Garden, auto parts supplier LKQ, the University of Phoenix, and Korean Air, all tied to the same Oracle EBS campaign. The incidents highlight the growing threat posed by sophisticated extortion groups exploiting enterprise software vulnerabilities.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: 315GB of filesSystems Affected: Oracle EBS environmentOperational Impact: None (global operations unaffected)
DATA BREACH
Type Of Data Compromised: Files (unspecified)Sensitivity Of Data: Non-sensitive, non-technical IT dataData Exfiltration: Yes (315GB published on leak site)
DECEMBER 2025
792Before Incident
NOVEMBER 2025
792Before Incident
OCTOBER 2025
792Before Incident
SEPTEMBER 2025
792Before Incident
AUGUST 2025
792Before Incident
JULY 2025
792Before Incident
JUNE 2025
794Before Incident
Ransomware
16 Jun 2025Michelin
Broadcom

Cl0p Exploits Zero-Day Vulnerabilities in Oracle E-Business Suite Leading to Massive Data Breaches

715After Incident
CRITICAL-79
BRO3105131112625
Broadcom, a global technology leader valued at hundreds of billions, was among the high-profile victims of Cl0p’s ransomware attack exploiting a zero-day vulnerability in Oracle’s E-Business Suite (CVE-2025-61882 and CVE-2025-21884). The cybercriminal group exfiltrated sensitive corporate and customer data, threatening to leak or sell it unless a ransom was paid. The breach compromised critical systems, risking financial records, proprietary business data, and third-party customer information. Cl0p’s extortion tactics included warnings of public disclosure on their blog, torrent leaks, or sales to malicious actors, amplifying reputational and operational risks. Given Broadcom’s role in semiconductor and infrastructure technology, the attack posed supply chain cascading risks, potentially disrupting clients reliant on its products. Oracle issued emergency patches, but the damage—including data theft, potential regulatory fines, and erosion of stakeholder trust—had already occurred. The incident underscores vulnerabilities in enterprise software dependencies, with Broadcom facing long-term financial and strategic repercussions if the stolen data is weaponized.
INCIDENT DETAILS -
TYPE
RansomwareData BreachZero-Day Exploit
MOTIVATION
Financial Gain (Ransomware Extortion)
IMPACT
Oracle E-Business Suite (EBS) versions 12.2.3–12.2.14Operational Impact: Significant (data exfiltration, potential system compromise)Brand Reputation Impact: High (public disclosure of breaches, ransom demands)Identity Theft Risk: High (PII and sensitive corporate data exfiltrated)
DATA BREACH
Corporate DataCustomer DataSensitive Business InformationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Michelin ?
?
What was Michelin's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Michelin's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Michelin's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Michelin's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Michelin's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Michelin's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Michelin's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Michelin's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Michelin's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Michelin's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Michelin's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Michelin's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Michelin ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Michelin's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?