Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Moderna

Moderna Vendor Cyber Rating & Cyber Score

modernatx.com

Moderna is a leader in the creation of the field of mRNA medicine. Through the advancement of mRNA technology, Moderna is reimagining how medicines are made and transforming how we treat and prevent disease for everyone. By working at the intersection of science, technology and health for more than a decade, the company has developed medicines at unprecedented speed and efficiency, including one of the earliest and most effective COVID-19 vaccines. Moderna's mRNA platform has enabled the development of therapeutics and vaccines for infectious diseases, immuno-oncology, rare diseases and autoimmune diseases. With a unique culture and a global team driven by the Moderna values and mindsets to responsibly change the future of human health,


Moderna A.I CyberSecurity Scoring

Moderna
Company Information
Website:https://www.modernatx.com/?tc=soc_7y8qkt&cc=1004
Employees number:6,394
Number of followers:747,362
NAICS:541714
Industry Type:Biotechnology Research
Homepage:modernatx.com
Moderna Risk Score (AI oriented)
Between 700 and 749
logo
ModernaBiotechnology Research
Updated:
21/05/2026
748/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Moderna Global Score (TPRM)
xxxx
logo
ModernaBiotechnology Research
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Moderna
ModernaModerate
Current Score
748Ba (MODERATE)
01000
2 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
766Before Incident
Cyber Attack
15 May 2026Moderna
Moderna: Cyberattack on West Pharmaceutical halts manufacturing across multiple sites

West Pharmaceutical Services Hit by Ransomware Attack

748After Incident
CRITICAL-18
MOD1779345048
West Pharmaceutical Services Hit by Ransomware Attack, Disrupting Global Manufacturing and Supply Chain West Pharmaceutical Services, a key supplier of injectable drug packaging and delivery systems, disclosed a ransomware attack on 4 May that forced the company to shut down portions of its global infrastructure. The breach, which involved data exfiltration and system encryption, disrupted manufacturing, shipping, and receiving operations across multiple facilities. The company reported progress in restoring core enterprise systems, with critical processes resuming at some sites while others remain in recovery. Forensic investigations, led by Palo Alto Networks’ Unit 42 alongside external experts, found no evidence of persistent malicious activity, though the incident affected domain-joined devices within West’s network. All known indicators of compromise are being addressed, and accounts have been secured. Industry Impact and Supply Chain Risks The attack highlights the growing sophistication of ransomware operations, which now function as a professionalized industry with affiliate programs and revenue-sharing models. According to Jacob Krell of Suzu Labs, ransomware groups target high-value supply chain entities like pharmaceutical manufacturers because downtime cascades downstream, disrupting critical drug delivery systems. Damon Small of Xcape Inc. noted that the breach paralyzed approximately 70% of the world’s injectable drug supply chain, forcing a proactive global shutdown to prevent further damage. The absence of a public leak site suggests negotiations may be underway to protect proprietary packaging designs and shipping data, which could expose major pharmaceutical clients like Pfizer and Moderna to operational risks. Lessons in Resilience and Recovery Experts emphasize that perimeter defense alone is insufficient against modern ransomware threats. Organizations in critical supply chains must adopt blast radius reduction, validated recovery capabilities, and proactive threat hunting. Small advocates for strict OT-IT segmentation (using models like the Purdue Model) and immutable backups to prevent a single breach from crippling global operations. West Pharmaceutical Services continues to provide updates as the investigation progresses, with restoration efforts ongoing. The incident underscores the urgent need for robust cybersecurity measures in sectors where operational downtime directly impacts public health.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain, operational disruption
IMPACT
Data Compromised: Proprietary packaging designs, shipping dataSystems Affected: Domain-joined devices, global manufacturing and supply chain infrastructureDowntime: Global shutdown of manufacturing, shipping, and receiving operationsOperational Impact: Disrupted approximately 70% of the world’s injectable drug supply chainBrand Reputation Impact: Potential reputational damage to West Pharmaceutical Services and its clients (e.g., Pfizer, Moderna)
DATA BREACH
Type Of Data Compromised: Proprietary packaging designs, shipping dataSensitivity Of Data: High (proprietary and operational data)
APRIL 2026
765Before Incident
MARCH 2026
764Before Incident
FEBRUARY 2026
764Before Incident
JANUARY 2026
763Before Incident
DECEMBER 2025
783Before Incident
Cyber Attack
28 Dec 2025Moderna
Canva, Adyen, Atlassian, HubSpot, Epic Games, Moderna, GameStop, ZoomInfo, WeWork, Halliburton, Betterment, Sonos and Telstra: Over 100 Organizations Targeted in ShinyHunters Phishing Campaign

ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations

763After Incident
CRITICAL-20
CANADYATLHUBEPIMODGAMZOOWEWHALBETSONTEL1769527593
ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations A recent cybercrime campaign attributed to the ShinyHunters group has targeted at least 100 organizations across multiple sectors, including software, finance, healthcare, and energy, according to cybersecurity firm Silent Push. Over the past 30 days, threat actors registered fake domains impersonating high-profile companies such as Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos, and Telstra. The attackers employed voice phishing (vishing) tactics to compromise single sign-on (SSO) accounts, particularly those using Okta and other identity platforms. Using specialized phishing kits, they intercepted credentials and manipulated victims into bypassing multi-factor authentication (MFA) by convincing them to approve push notifications or submit one-time passcodes (OTPs). Okta described the attacks as involving real-time session orchestration, where threat actors guided victims through the authentication process via verbal instructions. While Silent Push identified the infrastructure used in the campaign, it remains unclear whether the attacks successfully breached any systems. However, ShinyHunters has claimed responsibility for data breaches at companies like Betterment, Crunchbase, and SoundCloud, all of which confirmed incidents. The group allegedly stole millions of records from these organizations as part of the Okta SSO vishing campaign. Silent Push attributes the campaign to Scattered LAPSUS$ Hunters, a collective formed last year by members of Lapsus$, Scattered Spider, and ShinyHunters, based on observed tactics, techniques, and procedures (TTPs). The incident follows recent warnings from Google and others about rising vishing and phishing attacks targeting identity platforms.
INCIDENT DETAILS -
TYPE
Phishing (Vishing), Data Breach, Credential Theft
MOTIVATION
Data Theft, Financial Gain, Credential Harvesting
IMPACT
Data Compromised: Millions of records allegedly stolenSystems Affected: SSO accounts (Okta and other identity platforms)Identity Theft Risk: High (PII and credentials compromised)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII), Credentials, Business DataNumber Of Records Exposed: Millions (alleged)Sensitivity Of Data: High (PII, credentials)Data Exfiltration: Alleged (data sold on dark web)Personally Identifiable Information: Yes
NOVEMBER 2025
783Before Incident
OCTOBER 2025
783Before Incident
SEPTEMBER 2025
783Before Incident
AUGUST 2025
783Before Incident
JULY 2025
783Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Moderna ?
?
What was Moderna's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Moderna's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Moderna's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Moderna's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Moderna's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Moderna's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Moderna's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Moderna's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Moderna's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Moderna's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Moderna's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Moderna's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Moderna ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Moderna's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?