Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OneLogin by One Identity

OneLogin by One Identity Vendor Cyber Rating & Cyber Score

onelogin.com

OneLogin by One Identity, a wholly owned subsidiary of Quest Software, leads the market in Identity and Access Management. OneLogin by One Identity, a wholly owned subsidiary of Quest Software, leads the market in Identity and Access Management and support more than 5,000 customers worldwide. Our platform provides everything you need to secure your workforce, customers and partners.


OOI A.I CyberSecurity Scoring

OOI
Company Information
Website:http://onelogin.com?utm_source=orgsocial&utm_medium=linkedin
Employees number:55
Number of followers:20,821
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:onelogin.com
OOI Risk Score (AI oriented)
Between 700 and 749
logo
OOIIT Services and IT Consulting
Updated:
02/04/2026
734/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
OOI Global Score (TPRM)
xxxx
logo
OOIIT Services and IT Consulting
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OOI
OOIModerate
Current Score
734Ba (MODERATE)
01000
3 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
737Before Incident
AUGUST 2026
736Before Incident
JULY 2026
736Before Incident
JUNE 2026
736Before Incident
MAY 2026
735Before Incident
APRIL 2026
735Before Incident
MARCH 2026
734Before Incident
FEBRUARY 2026
734Before Incident
JANUARY 2026
734Before Incident
DECEMBER 2025
733Before Incident
NOVEMBER 2025
733Before Incident
OCTOBER 2025
732Before Incident
JUNE 2025
735Before Incident
Vulnerability
12 Jun 2025OOI
OneLogin

OneLogin AD Connector Service Vulnerabilities

730After Incident
CRITICAL-5
ONE438061225
A comprehensive security investigation revealed critical vulnerabilities in OneLogin’s Active Directory (AD) Connector service, exposing authentication credentials and enabling attackers to impersonate legitimate users across enterprise environments. The vulnerabilities allowed threat actors to generate valid JSON Web Tokens (JWT) and gain unauthorized access to customer systems. The exposed credentials included cleartext AWS credentials, API keys, and cryptographic signing keys, leading to widespread unauthorized access across an organization's federated applications. This demonstrated a complete compromise scenario, highlighting systemic issues in OneLogin’s infrastructure management.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Unauthorized Access
IMPACT
Authentication credentialsJSON Web Tokens (JWT)OneLogin’s AD Connector serviceEnterprise environments
DATA BREACH
Authentication credentialsJWT tokensSensitivity Of Data: HighData Encryption: NoneConfiguration dataLDAP properties
JUNE 2017
698Before Incident
Breach
01 Jun 2017OOI
OneLogin by One Identity

Unauthorized Access to OneLogin Systems

632After Incident
CRITICAL-66
ONE102261123
The OneLogin firm declared that it had found evidence of unauthorised access to its US-based systems. After a review by the organisation, it was determined that a threat actor had access to a set of AWS keys and had utilised them to access the AWS API through an intermediary host that was hosted by a different, smaller US service provider. Regarding the weaknesses that hackers used to gain access to the organisation, nothing is known. OneLogin attested to the encryption of the data, but it also noted that threat actors may still be able to decrypt it.
INCIDENT DETAILS -
TYPE
Unauthorized Access
IMPACT
AWS API
DATA BREACH
Data Encryption: Encrypted
SEPTEMBER 2016
750Before Incident
Breach
01 Sep 2016OOI
OneLogin by One Identity

OneLogin Data Breach

688After Incident
HIGH-62
ONE1539622
OneLogin, a cloud-based single sign-on and identity management service provider with over 1400 enterprise customers in 44 countries, suffered from a data breach incident. An unauthorized user gained access to the system by compromising a OneLogin employee’s password for the system. A bug that encrypted the data after that notes visible in the logging system and stored in the hackers database.
INCIDENT DETAILS -
TYPE
Data Breach

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OOI ?
?
What was OOI's A.I Rankiteo Cyber Score in August 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OOI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OOI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was OOI's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on OOI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OOI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OOI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?