Proofpoint A.I CyberSecurity Scoring
Proofpoint
Company Information
Website:https://www.proofpoint.com
Employees number:5,224
Number of followers:201,409
NAICS:541514
Industry Type:Computer and Network Security
Homepage:proofpoint.com
Proofpoint Risk Score (AI oriented)
Between 0 and 549
ProofpointComputer and Network Security
Updated:
29/08/2026
29/08/2026
289/1000
Critical
C
Proofpoint Global Score (TPRM)
xxxx
ProofpointComputer and Network Security
Score locked

ProofpointCritical
Current Score
289C (CRITICAL)
01000
8 incidents
-98.17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
303
SEPTEMBER 2026
296
AUGUST 2026
284
JULY 2026
421
Ransomware
23 Jul 2026 • Proofpoint
Proofpoint: AI-Powered Ransomware Threatens India: 62% of Hit Firms Report Higher Attack Impact
AI-Powered Ransomware Attacks Surge, Exploiting Human Trust and Credential Theft
275
CRITICAL-146
PRO1784896192
AI-Powered Ransomware Attacks Surge, Exploiting Human Trust and Credential Theft
Proofpoint’s 2026 AI-Era Ransomware Report reveals that artificial intelligence is amplifying the success of ransomware attacks by enhancing phishing, impersonation, and credential theft campaigns. Based on a survey of 953 cybersecurity professionals across 12 countries, the study highlights a shift in ransomware tactics moving beyond encryption to sustained extortion through stolen data and repeated demands.
In India, 62% of organizations affected by ransomware reported that AI increased attack effectiveness, with 16% citing a significant boost. Attackers are leveraging AI to craft more convincing phishing emails, automate reconnaissance, and exploit human trust at scale. The primary entry points remain human-dependent: phishing emails (42%), malicious links (71%), and business email compromise (47%).
Despite warnings against ransom payments, 64% of affected Indian organizations paid, yet nearly half (48%) faced additional extortion demands. Data theft was confirmed in 71% of incidents, underscoring ransomware’s evolution into a multi-stage extortion scheme. When asked why attacks bypassed defenses, 49% of Indian respondents cited user interaction with malicious content, while 42% attributed it to deceptive authenticity evidence of AI’s role in blurring the line between legitimate and fraudulent communications.
India recorded the highest user-interaction bypass rate (49%) among surveyed countries, alongside Japan and Singapore. The findings emphasize that ransomware now thrives by manipulating human behavior, not just exploiting technical vulnerabilities. As AI refines social engineering, organizations must address the human element to mitigate risks before attackers gain access.
INCIDENT DETAILS -
TYPE
MOTIVATION
DATA BREACH
REFERENCES
JUNE 2026
413
MAY 2026
420
Cyber Attack
01 May 2026 • Proofpoint
Shandong Provincial Tax Bureau and Indian Income Tax Department: Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data
Chinese Threat Actor TA4922 Deploys PackClient RAT in Tax-Themed Phishing Campaigns
402
CRITICAL-18
INDPRO1787991896
Chinese Threat Actor TA4922 Deploys PackClient RAT in Tax-Themed Phishing Campaigns
A Chinese-speaking threat group tracked as TA4922 has been deploying the PackClient remote access trojan (RAT) in targeted phishing campaigns against organizations in mainland China and India. The activity, observed by Proofpoint in May and July 2026, highlights the group’s expanding initial-access tactics and the growing availability of sophisticated malware on Chinese-language Telegram marketplaces.
### Attack Overview
PackClient is a modular RAT framework capable of supporting espionage, financial fraud, reconnaissance, credential theft, data exfiltration, and ransomware operations. The malware is sold via Telegram channels and consists of:
- An initial downloader
- A second-stage loader (PackClientLauncher)
- The PackClientCore RAT module
- Downloadable plugins for extended functionality
### Campaign Details
#### China-Targeted Attacks (Late May 2026)
TA4922 impersonated the Shandong Provincial Tax Bureau, sending emails claiming recipients had been selected for a 2026 tax inspection and owed unpaid stamp duties. Victims were directed to download a ZIP archive (数据资料.zip) from gov12366[.]com, a domain mimicking a government tax service.
The archive contained 资料数据.exe, which initiated the infection chain:
1. The downloader checked for elevated permissions, dropped a DLL (e.g., xMain.dll), and executed it via rundll32.exe.
2. It retrieved an encrypted payload, decrypted it, and saved it as %TEMP%\svchost.exe.
3. The malware established persistence via a RunOnce registry entry to survive reboots.
#### India-Targeted Attacks (Mid-July 2026)
TA4922 shifted focus to Indian targets, sending Hindi-language emails impersonating the Indian Income Tax Department. The messages accused recipients of underreporting income or failing to disclose foreign assets, threatening penalties.
Victims were tricked into opening ZIP archives (e.g., Tax_Notice_23665.zip, ITDTAX202601987.zip), which contained IMG disk-image files. Upon mounting, these files executed DLL sideloading to deploy Donut Loader, ultimately installing PackClient.
### Post-Compromise Activity
- Command-and-Control (C2) Traffic: Observed connections to 64[.]81[.]30[.]99 and 192[.]252[.]180[.]45:6666.
- Lateral Movement: Attackers installed ManageEngine Remote Monitoring and Management software hours after initial infection, likely to expand remote access.
- PackClientCore Capabilities: The RAT supports 60+ commands, including:
- Shell command execution
- File management & process enumeration
- Screenshot & webcam capture
- Keylogging & browser data theft
- Registry modification & proxy tunneling
- Clipboard manipulation & plugin downloads
- Telegram Monitoring: The malware checks for Telegram Desktop, suggesting potential plugin-based surveillance of local Telegram communications.
- Configuration Storage: PackClient stores settings in HKCU\SOFTWARE\PackClientConsole\, including C2 servers, ports, campaign IDs, and system UUIDs.
### Detection & Indicators of Compromise (IOCs)
Defenders should monitor for:
- rundll32.exe loading DLLs from temporary directories
- RunOnce registry entries launching %TEMP%\svchost.exe
- Processes using the svchost.exe --guard argument (restarts the RAT if terminated)
- Unexpected outbound TCP traffic on port 6666
- Tax-themed ZIP/IMG attachments
- Unapproved remote-management software deployments
Key IOCs:
- IPs: 154.36.188[.]98:8080, 206.238.196[.]96:6666, 64[.]81[.]30[.]99, 192[.]252[.]180[.]45:6666
- Domain: gov12366[.]com
- SHA-256 Hashes:
- 109d5c9a9581a4ccabd092ffb67bbc3a8e98e807239cd41141fac46fd107a7b7 (数据资料.zip)
- fa2ca62a47819417736d4edc59692bc920fb571d7eae468918f2fffc8920da53 (资料数据.exe)
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
432
Cyber Attack
01 Apr 2026 • Proofpoint
GitLab, Proofpoint, Google, GitHub, Phantom and Firefox: North Korean Hackers Use Fake Coding Tasks to Steal Crypto
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign
413
LOW-19
MOZPHAGITPROGOOGIT1780935989
North Korean Threat Actor Targets Developers in Large-Scale Phishing Campaign
A likely North Korean threat actor has conducted a sophisticated phishing campaign, targeting nearly 100 organizations primarily in the U.S. with fake job offers and code-review requests to steal cryptocurrency and credentials. The operation, tracked by Proofpoint as UNK_DeadDrop, sent over 250 malicious emails in April and May 2026, focusing on employees in technology, education, finance, and cryptocurrency firms.
### How the Attack Worked
The campaign used shifting pretexts including fake full-stack developer roles, AI payment agent projects, and ERC-4626 smart-contract testing to lure victims into cloning malicious GitHub or GitLab repositories. Once opened in VS Code or Cursor, a hidden tasks.json file executed automatically, exploiting a legitimate editor feature.
- VS Code displayed a trust prompt, but Cursor ran the payload silently without user interaction.
- The malware installed a fake Google-themed VS Code extension, ensuring persistence by relaunching on macOS and Linux whenever the editor reopened.
- Linux/macOS systems received a Go-based remote access trojan (RAT) from the open-source Overlord framework, while Windows ran JavaScript directly in the editor, leaving no disk footprint.
### Data Theft & Wallet Drainage
The malware targeted cryptocurrency wallets and browser credentials, including:
- Browser extensions: MetaMask, Phantom, Keplr
- Desktop wallets: Exodus, Electrum, Ledger Live
- Saved passwords & cookies from Chrome, Brave, Edge, and Firefox
To bypass security:
- macOS/Linux displayed a fake password prompt, using the input to escalate privileges and dump keychains.
- Windows bypassed Chrome’s app-bound encryption to extract data.
After exfiltration, the malware deleted itself to evade detection.
### Attribution & Distinct Tactics
While resembling Contagious Interview a long-running North Korean operation Proofpoint tracks UNK_DeadDrop separately due to its email-led delivery, large-scale repository creation, and self-contained payloads that persist even after infrastructure takedowns. Though attribution remains unconfirmed, the campaign aligns with North Korea’s history of targeting developers since 2022.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
432
FEBRUARY 2026
425
JANUARY 2026
700
Ransomware
01 Jan 2026 • Proofpoint
Proofpoint and LockBit: Greedy ransomware crews return for seconds after victims cough up first extortion payments
Ransomware Payments Fail to Guarantee Recovery
412
CRITICAL-288
CYBPRO1784723165
Ransomware Payments Fail to Guarantee Recovery, Proofpoint Data Reveals
A recent Proofpoint survey highlights the risks of paying ransomware demands, with data showing that compliance does not ensure resolution. Among UK organizations hit by ransomware, 58% paid the ransom yet 22% faced repeat extortion, a rate slightly better than the global average of 37%. Regional payment rates varied widely, from 19% in Japan to 93% in the US, influenced by regulatory environments, insurance incentives, and cultural attitudes toward negotiation.
The findings underscore a harsh reality: paying ransomware operators does not restore security. Even after payment, 2% of victims never recovered their files, while others encountered flawed decryptors such as a coding error in Nitrogen’s ESXi ransomware that left some data inaccessible. Law enforcement’s Operation Cronos, which dismantled the LockBit ransomware gang, confirmed long-held suspicions: attackers often retain stolen data even after receiving payment, undermining the assumption that compliance leads to resolution.
Beyond ransomware itself, AI is sharpening the attacks that enable it. In the UK, 65% of security practitioners reported that AI has intensified threats like malicious links, business email compromise, and credential harvesting. While AI has not yet become a core tool in ransomware payloads, it is enhancing phishing lures, impersonation attempts, and post-breach reconnaissance making initial access more effective. As Proofpoint’s Ryan Kalember noted, modern ransomware attacks increasingly exploit human trust and identity, rather than relying solely on technical vulnerabilities.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
DECEMBER 2025
700
NOVEMBER 2025
568
Breach
24 Nov 2025 • Proofpoint
Salesforce
Salesforce Data Breach: ShinyHunters Hack via Gainsight Integration
509
CRITICAL-59
GAI1122911112425
The Salesforce data breach involved the ShinyHunters (UNC6240) hacking group, which exploited stolen OAuth tokens from Salesloft’s GitHub account to infiltrate Drift’s Salesforce integration and subsequently compromise Gainsight, a customer process management platform. The attackers gained unauthorized access to over 200 Salesforce instances, exfiltrating enterprise customer data through third-party service integrations (including HubSpot and Zendesk). While Salesforce revoked access keys and removed affected apps from the AppExchange, the breach exposed sensitive customer data, though the full scope of the leak remains undisclosed. The attack leveraged supply-chain vulnerabilities rather than a direct Salesforce platform flaw. ShinyHunters claimed delayed detection (1–2 weeks post-intrusion) and sought internal accomplices for further exploitation. Salesforce refused ransom demands, but the incident highlights risks in third-party integrations and credential-based attacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
755
Breach
21 Oct 2025 • Proofpoint
Salesloft
Salesloft-Drift OAuth Token Breach
696
CRITICAL-59
DRI1593115102125
The Salesloft-Drift OAuth incident involved attackers stealing OAuth tokens from Salesloft’s development platform, exploiting them to access customer data across integrated applications like Salesforce and Google Workspace. The breach, executed by the threat group UNC6395, leveraged voice phishing (vishing) to trick administrators into authorizing malicious apps, bypassing multi-factor authentication (MFA). Over 700 organizations were impacted as the compromised tokens enabled attackers to exfiltrate sensitive customer information, leading to widespread revocation of Drift integrations. The incident exposed systemic risks in SaaS supply chains, where trusted third-party integrations became attack vectors, enabling potential data theft, cloud credential abuse, outages, or ransomware. Beyond immediate data exposure, the breach triggered forensic investigations, regulatory fines, lawsuits, reputational damage, and operational disruptions, highlighting the cascading risks of N-th degree vendor dependencies in modern cybersecurity ecosystems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
769
Breach
01 Aug 2025 • Proofpoint
Gainsight
Gainsight Unauthorized Salesforce Data Access via Stolen OAuth Tokens
754
CRITICAL-15
GAI0292402112125
The incident at Gainsight stemmed from a downstream effect of the August 2025 Salesloft breach, where the Scattered Lapsus$ Hunters group stole OAuth tokens tied to Salesloft’s Drift AI chat integration with Salesforce. These tokens granted unauthorized API access to 760 Salesforce instances, leading to the exfiltration of 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.A subgroup, ShinyHunters, exploited the stolen credentials to breach Gainsight’s systems, extracting customer contact data (names, business emails, phone numbers, regional details), licensing information, and support case contents. Salesforce responded by revoking all active Gainsight-associated tokens and temporarily removing its apps from the AppExchange to mitigate further exposure. While Salesforce clarified that its platform itself was not vulnerable, the breach originated from Gainsight’s external app connections, compromising sensitive corporate and customer data across hundreds of organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Cyber Attack
01 Aug 2025 • Proofpoint
Unidentified Trucking Carriers, Proofpoint and Unidentified Freight Brokers: Cybercriminals Hit Freight and Trucking Companies In Cargo Theft Scheme
Cybercriminals Hijack Freight Shipments in Sophisticated Supply Chain Attacks
754
CRITICAL-15
PRONOVVTS1776407277
Cybercriminals Hijack Freight Shipments in Sophisticated Supply Chain Attacks
A financially motivated cybercrime group is targeting the surface transportation industry, using advanced tactics to steal physical cargo by compromising freight brokers and trucking carriers. Since August 2025, cybersecurity firm Proofpoint has tracked nearly two dozen campaigns involving thousands of malicious messages, resulting in the theft of high-value shipments including electronics and energy drinks which are later resold online or shipped overseas.
The attackers exploit digital load boards, marketplaces where brokers and carriers arrange freight shipments, through three primary methods:
- Compromised Load Boards: Using stolen credentials, they post fraudulent freight listings and send malicious links to responding carriers.
- Email Thread Hijacking: They infiltrate legitimate email chains between supply chain partners, inserting malicious URLs into trusted conversations.
- Direct Email Targeting: Broad phishing campaigns target logistics firms to identify and later steal high-value cargo.
Once a victim clicks a malicious link, it downloads an executable or MSI file that installs legitimate but abused Remote Monitoring and Management (RMM) tools such as ScreenConnect, PDQ Connect, or LogMeIn Resolve enabling attackers to maintain control over compromised systems.
While the threat actors remain unidentified, they demonstrate deep knowledge of trucking industry software and dispatch operations. To mitigate risks, Proofpoint recommends restricting unauthorized RMM tool installations, deploying network monitoring for suspicious activity, blocking executable email attachments, and training staff to recognize phishing attempts.
As digital infrastructure becomes increasingly integral to supply chains, these attacks highlight the growing intersection of cyber threats and physical cargo theft, posing significant financial and operational risks to transportation companies.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Proofpoint ??
What was Proofpoint's A.I Rankiteo Cyber Score in September 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in August 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in July 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in June 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in May 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in April 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in March 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in February 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in January 2026 ??
What was Proofpoint's A.I Rankiteo Cyber Score in December 2025 ??
What was Proofpoint's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Proofpoint's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Proofpoint ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Proofpoint's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?