Ofcom A.I CyberSecurity Scoring
Ofcom
Company Information
Website:http://www.ofcom.org.uk
Employees number:1,691
Number of followers:70,942
NAICS:517
Industry Type:Telecommunications
Homepage:ofcom.org.uk
Ofcom Risk Score (AI oriented)
Between 650 and 699
OfcomTelecommunications
Updated:
19/06/2026
19/06/2026
650/1000
Weak
B
Ofcom Global Score (TPRM)
xxxx
OfcomTelecommunications
Score locked

OfcomWeak
Current Score
650B (WEAK)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
654
JULY 2026
651
JUNE 2026
650
MAY 2026
648
APRIL 2026
645
MARCH 2026
643
FEBRUARY 2026
639
JANUARY 2026
637
DECEMBER 2025
633
NOVEMBER 2025
630
OCTOBER 2025
627
SEPTEMBER 2025
623
JULY 2023
652
Ransomware
07 Jul 2023 • Ofcom
K&L Gates, Ofcom, MOVEit, Kirkland & Ellis, Proskauer Rose, PwC, Aon and Shell: Kirkland, K&L Gates and Proskauer hit by ransomware attack
Clop Ransomware Group Exploits MOVEit Vulnerability, Targets Major Law Firms and Corporations
484
CRITICAL-168
OFCK&LAONPROKIRSHEPWCMOV1781843490
Clop Ransomware Group Exploits MOVEit Vulnerability, Targets Major Law Firms and Corporations
A ransomware attack linked to the Clop cybercrime group has compromised several high-profile organizations, including law firms Kirkland & Ellis, Proskauer Rose, and K&L Gates, as well as entities like Ofcom, EY, PwC, Shell, and Aon. The breach stemmed from a critical SQL injection vulnerability in MOVEit Transfer, a third-party file-transfer software exploited by a hacker operating under the alias "Lance Tempest" a suspected affiliate of Clop.
The attack began in late May, when Clop infiltrated MOVEit’s systems. Though the vendor released a patch shortly after, many organizations failed to apply it in time, leaving them exposed. Clop initially gave victims until June 14 to negotiate via a dark web portal, warning that non-compliance would result in public exposure of their identities. When the deadline passed, the group published the names of over 100 affected organizations, signaling their refusal or inability to engage.
Unlike typical ransomware operations, Clop does not disclose fixed ransom amounts upfront. Instead, victims are directed to contact the group via email before negotiations shift to an encrypted chat on its dark web site. If no agreement is reached within three days, Clop threatens to release stolen data within a week. Cybersecurity firm Cypfer reports that the group’s demands often start at $3 million.
Believed to be Russian-linked, Clop has drawn heightened scrutiny from authorities, with the U.S. government offering a $10 million bounty for information leading to the arrest of its leader. Meanwhile, the targeted law firms have not disclosed details about the compromised data, ransom demands, or their response strategies.
The incident underscores the persistent threat of supply-chain attacks, particularly against law firms frequent targets due to their handling of sensitive client information. Earlier this year, a separate case involving a junior solicitor highlighted internal security risks, as she sued a firm over alleged unauthorized access to her private WhatsApp messages.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2023
762
Ransomware
01 Jun 2023 • Ofcom
Ofcom
MOVEit File Transfer Zero-Day Vulnerability Exploited by Clop Ransomware
650
CRITICAL-112
OFC73619923
The MOVEit file transfer zero-day vulnerability was used by the Clop ransomware campaign to compromise the data of UK communications regulator Ofcom.
The ransomware group had access to private data that Ofcom had on the companies it monitors, a representative for the regulator told The Record.
According to the organization, they took immediate action to stop further usage of the MOVEit service and to put the suggested security measures into place.
A SQL injection vulnerability exists, and it might be used by an unauthenticated attacker to access the database of MOVEit Transfer without authorization.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Ofcom ??
What was Ofcom's A.I Rankiteo Cyber Score in July 2026 ??
What was Ofcom's A.I Rankiteo Cyber Score in June 2026 ??
What was Ofcom's A.I Rankiteo Cyber Score in May 2026 ??
What was Ofcom's A.I Rankiteo Cyber Score in April 2026 ??
What was Ofcom's A.I Rankiteo Cyber Score in March 2026 ??
What was Ofcom's A.I Rankiteo Cyber Score in February 2026 ??
What was Ofcom's A.I Rankiteo Cyber Score in January 2026 ??
What was Ofcom's A.I Rankiteo Cyber Score in December 2025 ??
What was Ofcom's A.I Rankiteo Cyber Score in November 2025 ??
What was Ofcom's A.I Rankiteo Cyber Score in October 2025 ??
What was Ofcom's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Ofcom's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Ofcom ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Ofcom's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?