Company Details
paramount-plus
1,482
194,210
71
paramount.com
0
PAR_7608224
In-progress

Paramount+ Company CyberSecurity Posture
paramount.comParamount+, a direct-to-consumer digital subscription video on-demand and live streaming service from Paramount Global, combines live sports, breaking news, and a mountain of entertainment. The premium streaming service features an expansive library of original series, hit shows and popular movies across every genre from world-renowned brands and production studios, including BET, CBS, Comedy Central, MTV, Nickelodeon, Paramount Pictures and the Smithsonian Channel. The service is also the streaming home to unmatched sports programming, including every CBS Sports event, from golf to football to basketball and more, plus exclusive streaming rights for major sports properties, including some of the world’s biggest and most popular soccer leagues. Paramount+ also enables subscribers to stream local CBS stations live across the U.S. in addition to the ability to stream Paramount Streaming’s other live channels: CBSN for 24/7 news, CBS Sports HQ for sports news and analysis, and ET Live for entertainment coverage.
Company Details
paramount-plus
1,482
194,210
71
paramount.com
0
PAR_7608224
In-progress
Between 700 and 749

Paramount+ Global Score (TPRM)XXXX

Description: The movie theatre chain National Amusements, which is the corporate parent company of media behemoths Paramount and CBS, has acknowledged that it suffered a data breach from which hackers obtained tens of thousands of people's data. In a legally mandated filing with Maine's attorney general, the private media conglomerate stated that hackers had taken 82,128 people's data. The hackers stole Paramount customer names and dates of birth, as well as Social Security numbers or other government-issued identification numbers, according to the notice.
Description: Multinational mass media conglomerate Paramount Global suffered a data breach after an unauthorized party accessed files from certain of its systems. The compromised information included name, date of birth, Social Security number, or other government-issued identification number (such as driver’s license number or passport number) and information related to the relationship of the impacted individuals with Paramount. The company offered impacted individuals free identity protection and credit monitoring services for two years.


No incidents recorded for Paramount+ in 2025.
No incidents recorded for Paramount+ in 2025.
No incidents recorded for Paramount+ in 2025.
Paramount+ cyber incidents detection timeline including parent company and subsidiaries

Paramount+, a direct-to-consumer digital subscription video on-demand and live streaming service from Paramount Global, combines live sports, breaking news, and a mountain of entertainment. The premium streaming service features an expansive library of original series, hit shows and popular movies across every genre from world-renowned brands and production studios, including BET, CBS, Comedy Central, MTV, Nickelodeon, Paramount Pictures and the Smithsonian Channel. The service is also the streaming home to unmatched sports programming, including every CBS Sports event, from golf to football to basketball and more, plus exclusive streaming rights for major sports properties, including some of the world’s biggest and most popular soccer leagues. Paramount+ also enables subscribers to stream local CBS stations live across the U.S. in addition to the ability to stream Paramount Streaming’s other live channels: CBSN for 24/7 news, CBS Sports HQ for sports news and analysis, and ET Live for entertainment coverage.

Universal Music Group (UMG) is the world leader in music-based entertainment, with a broad array of businesses engaged in recorded music, music publishing, merchandising and audiovisual content in more than 60 countries. Featuring the most comprehensive catalog of recordings and songs across every m

Welcome to Entain. Our journey as Entain began when we evolved from GVC Holdings on 9th December 2020, but our brands have been paving the way and making history since the 1880s. Today, we’re one of the world’s largest sports betting and gaming entertainment groups – a FTSE 100 company that is h
Topgolf is the ultimate instigator of play. Thanks to our 100+ venues around the globe, which are powered by industry-leading Toptracer technology, we're leading the charge of modern golf. We offer a variety of tech-driven games, a top-tier food and drink menu, space to host large events, and a vibe

Paramount is a leading media and entertainment company that creates premium content and experiences for audiences worldwide. Driven by iconic studios, networks and streaming services, Paramount's portfolio of consumer brands includes CBS, Showtime Networks, Paramount Pictures, Skydance Animation, Sk

Electronic Arts creates next-level entertainment experiences that inspire players and fans around the world. Here, everyone is part of the story. Part of a community that connects across the globe. A team where creativity thrives, new perspectives are invited, and ideas matter. Regardless of your ro

Warner Bros. Discovery, a premier global media and entertainment company, offers audiences the world’s most differentiated and complete portfolio of content, brands and franchises across television, film, streaming and gaming. The new company combines WarnerMedia’s premium entertainment, sports and
Recognized three years in a row by Great Place to Work® and named one of People Magazine’s Top 50 Companies that Care, Live Nation Entertainment is the global leader in live events and ticketing. With business operations and corporate functions across major divisions including Ticketmaster, Concerts

Lucidity Agency Models, también conocida como Lucidity, es una agencia de modelos establecida en vancouver, Canada, en 2010 por el conglomerado The Ivan Group. Lucidity maneja en la actualidad a más de 800 modelos de los cinco continentes, convirtiéndola en la agencia de modelos más grande del mund

For years, we’ve been creating a legacy of unforgettable experiences for our Guests. Our Guests are immersed into the sights and sounds of some of the greatest movies and most legendary stories, and our Team Members are the ones who help make those incredible experiences come alive. Our Team Members
.png)
News Desk. DUBAI/MANAMA: Paramount, the leading cybersecurity solutions provider in the Middle East, recently signed a partnership agreement...
The agreement was signed during the Arab International Cybersecurity Conference and Exhibition (AICS), marking a major step in enhancing...
Paramount, the leading cybersecurity solutions provider in the Middle East, recently signed a partnership agreement with the National Cyber...
Since CEO David Ellison took over, several senior staff have been dismissed for opposing the genocide in Gaza, with sources saying the...
Paramount Skydance Corp. and its video streaming subsidiary Pluto Inc. unlawfully disclosed the personally identifiable information of...
Bhopal: The MP high court, while refusing the permission to order medical termination of pregnancy of a minor rape victim, said that making...
International Business News: Paramount Skydance Corporation is implementing a significant restructuring, announcing plans to eliminate...
John Pagliuca describes security as being at the 'centre of the growth algorithm' in the country.
Crypto Under Siege: Billions Lost in 2024-2025 Breaches as Cybersecurity Becomes Paramount ... The cryptocurrency ecosystem has been rocked by an...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Paramount+ is https://www.paramount.com/brand/paramount-plus.
According to Rankiteo, Paramount+’s AI-generated cybersecurity score is 721, reflecting their Moderate security posture.
According to Rankiteo, Paramount+ currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Paramount+ is not certified under SOC 2 Type 1.
According to Rankiteo, Paramount+ does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Paramount+ is not listed as GDPR compliant.
According to Rankiteo, Paramount+ does not currently maintain PCI DSS compliance.
According to Rankiteo, Paramount+ is not compliant with HIPAA regulations.
According to Rankiteo,Paramount+ is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Paramount+ operates primarily in the Entertainment Providers industry.
Paramount+ employs approximately 1,482 people worldwide.
Paramount+ presently has no subsidiaries across any sectors.
Paramount+’s official LinkedIn profile has approximately 194,210 followers.
Paramount+ is classified under the NAICS code 71, which corresponds to Arts, Entertainment, and Recreation.
No, Paramount+ does not have a profile on Crunchbase.
Yes, Paramount+ maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/paramount-plus.
As of November 27, 2025, Rankiteo reports that Paramount+ has experienced 2 cybersecurity incidents.
Paramount+ has an estimated 7,232 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with offered impacted individuals free identity protection and credit monitoring services for two years..
Title: Paramount Global Data Breach
Description: Multinational mass media conglomerate Paramount Global suffered a data breach after an unauthorized party accessed files from certain of its systems.
Type: Data Breach
Title: Data Breach at National Amusements
Description: National Amusements, the corporate parent company of Paramount and CBS, suffered a data breach affecting tens of thousands of people. Hackers obtained names, dates of birth, Social Security numbers, and other government-issued identification numbers of 82,128 individuals.
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Name, Date of birth, Social security number, Other government-issued identification number (such as driver’s license number or passport number), Information related to the relationship of the impacted individuals with paramount

Data Compromised: Names, Dates of birth, Social security numbers, Other government-issued identification numbers
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personally Identifiable Information (Pii), Relationship Information, , Names, Dates Of Birth, Social Security Numbers, Other Government-Issued Identification Numbers and .

Entity Name: Paramount Global
Entity Type: Corporation
Industry: Mass Media

Entity Name: National Amusements
Entity Type: Corporation
Industry: Media and Entertainment
Customers Affected: 82128

Communication Strategy: Offered impacted individuals free identity protection and credit monitoring services for two years

Type of Data Compromised: Personally identifiable information (pii), Relationship information
Sensitivity of Data: High
Personally Identifiable Information: namedate of birthSocial Security numberother government-issued identification number (such as driver’s license number or passport number)

Type of Data Compromised: Names, Dates of birth, Social security numbers, Other government-issued identification numbers
Number of Records Exposed: 82128
Sensitivity of Data: High
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Offered Impacted Individuals Free Identity Protection And Credit Monitoring Services For Two Years.
Most Significant Data Compromised: The most significant data compromised in an incident were name, date of birth, Social Security number, other government-issued identification number (such as driver’s license number or passport number), information related to the relationship of the impacted individuals with Paramount, , Names, Dates of Birth, Social Security Numbers, Other Government-issued Identification Numbers and .
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Social Security Numbers, information related to the relationship of the impacted individuals with Paramount, date of birth, name, Social Security number, Other Government-issued Identification Numbers, Dates of Birth, other government-issued identification number (such as driver’s license number or passport number) and Names.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 849.0.
.png)
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 structures that trigger unbounded recursive parsing. This leads to a Denial-of-Service (DoS) via stack exhaustion when parsing untrusted DER inputs. This issue has been patched in version 1.3.2.
Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overflow vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft ASN.1 structures containing OIDs with oversized arcs. These arcs may be decoded as smaller, trusted OIDs due to 32-bit bitwise truncation, enabling the bypass of downstream OID-based security decisions. This issue has been patched in version 1.3.2.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Prior to versions 7.0.13 and 8.0.2, working with large buffers in Lua scripts can lead to a stack overflow. Users of Lua rules and output scripts may be affected when working with large buffers. This includes a rule passing a large buffer to a Lua script. This issue has been patched in versions 7.0.13 and 8.0.2. A workaround for this issue involves disabling Lua rules and output scripts, or making sure limits, such as stream.depth.reassembly and HTTP response body limits (response-body-limit), are set to less than half the stack size.
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. In versions from 8.0.0 to before 8.0.2, a NULL dereference can occur when the entropy keyword is used in conjunction with base64_data. This issue has been patched in version 8.0.2. A workaround involves disabling rules that use entropy in conjunction with base64_data.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.