Proofpoint A.I CyberSecurity Scoring
Proofpoint
Company Information
Website:https://www.proofpoint.com
Employees number:4,976
Number of followers:182,427
NAICS:541514
Industry Type:Computer and Network Security
Homepage:proofpoint.com
Proofpoint Risk Score (AI oriented)
Between 650 and 699
ProofpointComputer and Network Security
Updated:
08/06/2026
08/06/2026
690/1000
Weak
B
Proofpoint Global Score (TPRM)
xxxx
ProofpointComputer and Network Security
Score locked

ProofpointWeak
Current Score
690B (WEAK)
01000
3 incidents
-31 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
690
MAY 2026
707
APRIL 2026
704
Cyber Attack
01 Apr 2026 • Proofpoint
GitLab, Proofpoint, Google, GitHub, Phantom and Firefox: North Korean Hackers Use Fake Coding Tasks to Steal Crypto
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign
685
LOW-19
MOZPHAGITPROGOOGIT1780935989
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign
A likely North Korean threat actor has conducted a sophisticated phishing campaign, targeting nearly 100 organizations primarily in the U.S. with fake job offers and code-review requests to steal cryptocurrency and credentials. The operation, tracked by Proofpoint as UNK_DeadDrop, sent over 250 malicious emails in April and May 2026, focusing on employees in technology, education, finance, and cryptocurrency firms.
### How the Attack Worked
The campaign used shifting pretexts including fake full-stack developer roles, AI payment agent projects, and ERC-4626 smart-contract testing to lure victims into cloning malicious GitHub or GitLab repositories. Once opened in VS Code or Cursor, a hidden tasks.json file executed automatically, exploiting a legitimate editor feature.
- VS Code displayed a trust prompt, but Cursor ran the payload silently without user interaction.
- The malware installed a fake Google-themed VS Code extension, ensuring persistence by relaunching on macOS and Linux whenever the editor reopened.
- Linux/macOS systems received a Go-based remote access trojan (RAT) from the open-source Overlord framework, while Windows ran JavaScript directly in the editor, leaving no disk footprint.
### Data Theft & Wallet Drainage
The malware targeted cryptocurrency wallets and browser credentials, including:
- Browser extensions: MetaMask, Phantom, Keplr
- Desktop wallets: Exodus, Electrum, Ledger Live
- Saved passwords & cookies from Chrome, Brave, Edge, and Firefox
To bypass security:
- macOS/Linux displayed a fake password prompt, using the input to escalate privileges and dump keychains.
- Windows bypassed Chrome’s app-bound encryption to extract data.
After exfiltration, the malware deleted itself to evade detection.
### Attribution & Distinct Tactics
While resembling Contagious Interview a long-running North Korean operation Proofpoint tracks UNK_DeadDrop separately due to its email-led delivery, large-scale repository creation, and self-contained payloads that persist even after infrastructure takedowns. Though attribution remains unconfirmed, the campaign aligns with North Korea’s history of targeting developers since 2022.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
704
FEBRUARY 2026
703
JANUARY 2026
701
DECEMBER 2025
700
NOVEMBER 2025
698
OCTOBER 2025
755
Breach
21 Oct 2025 • Proofpoint
Salesloft
Salesloft-Drift OAuth Token Breach
696
CRITICAL-59
DRI1593115102125
The Salesloft-Drift OAuth incident involved attackers stealing OAuth tokens from Salesloft’s development platform, exploiting them to access customer data across integrated applications like Salesforce and Google Workspace. The breach, executed by the threat group UNC6395, leveraged voice phishing (vishing) to trick administrators into authorizing malicious apps, bypassing multi-factor authentication (MFA). Over 700 organizations were impacted as the compromised tokens enabled attackers to exfiltrate sensitive customer information, leading to widespread revocation of Drift integrations. The incident exposed systemic risks in SaaS supply chains, where trusted third-party integrations became attack vectors, enabling potential data theft, cloud credential abuse, outages, or ransomware. Beyond immediate data exposure, the breach triggered forensic investigations, regulatory fines, lawsuits, reputational damage, and operational disruptions, highlighting the cascading risks of N-th degree vendor dependencies in modern cybersecurity ecosystems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
755
AUGUST 2025
769
Cyber Attack
01 Aug 2025 • Proofpoint
Unidentified Trucking Carriers, Proofpoint and Unidentified Freight Brokers: Cybercriminals Hit Freight and Trucking Companies In Cargo Theft Scheme
Cybercriminals Hijack Freight Shipments in Sophisticated Supply Chain Attacks
754
CRITICAL-15
PRONOVVTS1776407277
Cybercriminals Hijack Freight Shipments in Sophisticated Supply Chain Attacks
A financially motivated cybercrime group is targeting the surface transportation industry, using advanced tactics to steal physical cargo by compromising freight brokers and trucking carriers. Since August 2025, cybersecurity firm Proofpoint has tracked nearly two dozen campaigns involving thousands of malicious messages, resulting in the theft of high-value shipments including electronics and energy drinks which are later resold online or shipped overseas.
The attackers exploit digital load boards, marketplaces where brokers and carriers arrange freight shipments, through three primary methods:
- Compromised Load Boards: Using stolen credentials, they post fraudulent freight listings and send malicious links to responding carriers.
- Email Thread Hijacking: They infiltrate legitimate email chains between supply chain partners, inserting malicious URLs into trusted conversations.
- Direct Email Targeting: Broad phishing campaigns target logistics firms to identify and later steal high-value cargo.
Once a victim clicks a malicious link, it downloads an executable or MSI file that installs legitimate but abused Remote Monitoring and Management (RMM) tools such as ScreenConnect, PDQ Connect, or LogMeIn Resolve enabling attackers to maintain control over compromised systems.
While the threat actors remain unidentified, they demonstrate deep knowledge of trucking industry software and dispatch operations. To mitigate risks, Proofpoint recommends restricting unauthorized RMM tool installations, deploying network monitoring for suspicious activity, blocking executable email attachments, and training staff to recognize phishing attempts.
As digital infrastructure becomes increasingly integral to supply chains, these attacks highlight the growing intersection of cyber threats and physical cargo theft, posing significant financial and operational risks to transportation companies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JULY 2025
769
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Proofpoint ??
What was Proofpoint's A.I Rankiteo Cyber Score in May 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in April 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in March 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in February 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in January 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in December 2025 ??
What was Proofpoint's A.I Rankiteo Cyber Score in November 2025 ??
What was Proofpoint's A.I Rankiteo Cyber Score in October 2025 ??
What was Proofpoint's A.I Rankiteo Cyber Score in September 2025 ??
What was Proofpoint's A.I Rankiteo Cyber Score in August 2025 ??
What was Proofpoint's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Proofpoint's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Proofpoint ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Proofpoint's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?