ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

As an integrated technology group, the listed company Rheinmetall AG, headquartered in Düsseldorf, stands for a company that is as strong in substance as it is successful internationally, and that is active in various markets with an innovative range of products and services. Rheinmetall is a leading international systems supplier in the defence industry and at the same time a driver of forward-looking technological and industrial innovations in the civilian markets. The focus on sustainability is an integral part of Rheinmetall's strategy. The company aims to achieve CO2 neutrality by 2035. Through our work in various fields, we at Rheinmetall take on responsibility in a dramatically changing world. With our technologies, products and systems, we create the indispensable basis for peace, freedom and sustainable development: security. Find more Information about your career opportunities here: https://www.rheinmetall.com/en/rheinmetall_ag/career_1/index.php IMPRINT AND DATA PROTECTION https://www.rheinmetall.com/en/rheinmetall_ag/service/imprint/index.php

Rheinmetall A.I CyberSecurity Scoring

Rheinmetall

Company Details

Linkedin ID:

rheinmetall

Employees number:

13,148

Number of followers:

405,989

NAICS:

336414

Industry Type:

Defense and Space Manufacturing

Homepage:

rheinmetall.com

IP Addresses:

0

Company ID:

RHE_3248244

Scan Status:

In-progress

AI scoreRheinmetall Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/rheinmetall.jpeg
Rheinmetall Defense and Space Manufacturing
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreRheinmetall Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/rheinmetall.jpeg
Rheinmetall Defense and Space Manufacturing
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Rheinmetall Company CyberSecurity News & History

Past Incidents
2
Attack Types
2
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
RheinmetallCyber Attack60203/2023
Rankiteo Explanation :
Attack limited on finance or reputation

Description: An extensive cyberattack on the arms company Rheinmetall was mostly unharmed. Previously unidentified attackers targeted the company's IT systems in an attempt to collapse them. Only the organization website, which an outside service provider runs, was momentarily down, according to a group representative. There is no evidence that a potential leak may have an impact on the internal Rheinmetall IT system. As the business is providing, among other things, armored personnel carriers to Ukraine to stave off the Russian onslaught, experts predict that Rheinmetall is the target of Russian hackers who are on the Internet.

RheinmetallRansomware75204/2023
Rankiteo Explanation :
Attack limited on finance or reputation

Description: Hackers have assaulted Rheinmetall, a producer of munitions and vehicles. Only civilian business, according to the corporation, is impacted. On its leak-site, the BlackBasta ransomware organisation has already taken responsibility for the attack. The business claimed that the attack had no impact on the arms division's output, but the German media is reporting that the attack was not confined to a single subsidiary. Given that the investigation was still in progress, they were unable to disclose information regarding the attack's severity.

Rheinmetall
Cyber Attack
Severity: 60
Impact: 2
Seen: 03/2023
Blog:
Rankiteo Explanation
Attack limited on finance or reputation

Description: An extensive cyberattack on the arms company Rheinmetall was mostly unharmed. Previously unidentified attackers targeted the company's IT systems in an attempt to collapse them. Only the organization website, which an outside service provider runs, was momentarily down, according to a group representative. There is no evidence that a potential leak may have an impact on the internal Rheinmetall IT system. As the business is providing, among other things, armored personnel carriers to Ukraine to stave off the Russian onslaught, experts predict that Rheinmetall is the target of Russian hackers who are on the Internet.

Rheinmetall
Ransomware
Severity: 75
Impact: 2
Seen: 04/2023
Blog:
Rankiteo Explanation
Attack limited on finance or reputation

Description: Hackers have assaulted Rheinmetall, a producer of munitions and vehicles. Only civilian business, according to the corporation, is impacted. On its leak-site, the BlackBasta ransomware organisation has already taken responsibility for the attack. The business claimed that the attack had no impact on the arms division's output, but the German media is reporting that the attack was not confined to a single subsidiary. Given that the investigation was still in progress, they were unable to disclose information regarding the attack's severity.

Ailogo

Rheinmetall Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Rheinmetall

Incidents vs Defense and Space Manufacturing Industry Average (This Year)

No incidents recorded for Rheinmetall in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Rheinmetall in 2025.

Incident Types Rheinmetall vs Defense and Space Manufacturing Industry Avg (This Year)

No incidents recorded for Rheinmetall in 2025.

Incident History — Rheinmetall (X = Date, Y = Severity)

Rheinmetall cyber incidents detection timeline including parent company and subsidiaries

Rheinmetall Company Subsidiaries

SubsidiaryImage

As an integrated technology group, the listed company Rheinmetall AG, headquartered in Düsseldorf, stands for a company that is as strong in substance as it is successful internationally, and that is active in various markets with an innovative range of products and services. Rheinmetall is a leading international systems supplier in the defence industry and at the same time a driver of forward-looking technological and industrial innovations in the civilian markets. The focus on sustainability is an integral part of Rheinmetall's strategy. The company aims to achieve CO2 neutrality by 2035. Through our work in various fields, we at Rheinmetall take on responsibility in a dramatically changing world. With our technologies, products and systems, we create the indispensable basis for peace, freedom and sustainable development: security. Find more Information about your career opportunities here: https://www.rheinmetall.com/en/rheinmetall_ag/career_1/index.php IMPRINT AND DATA PROTECTION https://www.rheinmetall.com/en/rheinmetall_ag/service/imprint/index.php

Loading...
similarCompanies

Rheinmetall Similar Companies

Leidos

Leidos is a Fortune 500® innovation company rapidly addressing the world’s most vexing challenges in national security and health. The company's global workforce of 48,000 collaborates to create smarter technology solutions for customers in heavily regulated industries. Headquartered in Reston, Virg

Sandia National Laboratories

Sandia National Laboratories is the nation’s premier DOE science and engineering lab for national security and technology innovation. Our team of scientists, engineers, researchers, and business specialists apply their knowledge and skill toward delivering cutting-edge technology in an array of area

Leonardo

Leonardo is a global security company that realises multi-domain technological capabilities in AD&S. With over 53,000 employees worldwide, the company has a significant industrial presence in Italy, the UK, Poland, and the US. It also has a commercial presence in 150 countries through subsidiaries

UK Ministry of Defence

We protect the security, independence and interests of the United Kingdom at home and abroad. We work with our allies and partners whenever possible. Our aim is to ensure that the UK’s Armed Forces have the training, equipment and support necessary for their work, and that we keep within budget.

Aselsan

ASELSAN is a company of Turkish Armed Forces Foundation, established in 1975 in order to meet the communication needs of the Turkish Armed Forces by national means. Currently ​74,20% of the shares are owned by the Foundation whereas the remaining 25,8% runs in İstanbul Borsa stock market. ASELSAN is

L3 Technologies

With headquarters in New York City and approximately 31,000 employees worldwide, L3 develops advanced defense technologies and commercial solutions in pilot training, aviation security, night vision and EO/IR, weapons, maritime systems and space. The company reported 2018 sales of $10.2 billion. To

Naval Sea Systems Command (NAVSEA) Careers

We are NAVSEA. The Force Behind the Fleet. Join us and become part of a mission-driven team, at one of the best places to work in the federal government. This NAVSEA LinkedIn page is all about connecting with talented individuals ready to make a difference through a rewarding career with us. We shar

Amentum

Amentum is a global leader in advanced engineering and innovative technology solutions, trusted by the United States and its allies to address their most significant and complex challenges in science, security and sustainability. Our people apply undaunted curiosity, relentless ambition and boundles

The Indian Army is the largest branch of the Indian Armed Forces and is responsible for land-based military operations. Its primary mission is the National Security and Defense of India from external aggression and threats, and maintaining peace and security within its borders. It also conducts huma

newsone

Rheinmetall CyberSecurity News

December 12, 2025 05:00 PM
3Wire Partners Launches Advisory Board, Enhancing Aerospace and Defense Investment & Merchant Banking Platform’s Capabilities and Reach

WASHINGTON--(BUSINESS WIRE)--3Wire Partners (“3Wire”), an independent investment and merchant bank focused on the Aerospace,...

December 09, 2025 04:36 AM
2026 Defence & Cyber Security Outlook: Where Software Meets Steel

Palantir leads a new era of software-driven defence as the US overhauls military procurement and AI reshapes cyber warfare.

November 18, 2025 08:00 AM
Rheinmetall to buy mostly European steel in future, says CEO

Rheinmetall plans to buy steel mostly in Germany or in Europe in the future, said CEO Armin Papperger on Tuesday after the German defence...

November 05, 2025 08:00 AM
Leonardo and Rheinmetall secure first contract to supply 21 armoured vehicles to Italian Army

Under the contract, the companies will deliver 21 tracked armoured vehicles, including five Rheinmetall Lynx KF-41 models equipped with the...

October 16, 2025 07:00 AM
Discover why Rheinmetall’s new HX3 CTT truck could change US Army's logistics for decades

American Rheinmetall and GM Defense presented the HX3 Common Tactical Truck at AUSA 2025, a modular platform for the U.S. Army's logistics...

September 22, 2025 07:00 AM
German companies face rising cybercrime

Sabotage, data theft and espionage are affecting more and more companies in Germany, costing them billions in damages every year and...

September 11, 2025 07:00 AM
Germany's Rheinmetall to produce shells at new plant in Ukraine, Kyiv says

German arms giant Rheinmetall plans to manufacture artillery shells for Ukrainian forces at a future production plant in Ukraine,...

September 10, 2025 07:00 AM
b

American Rheinmetall has announced their latest $31.7 million investment in Michigan, expected to 450 new jobs. American Rheinmetall...

September 09, 2025 07:00 AM
Battlesuite at DSEI 2025

Rheinmetall Battlesuite - the interoperable military ecosystem of the future; Core element for interconnected digital warfare of the future...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Rheinmetall CyberSecurity History Information

Official Website of Rheinmetall

The official website of Rheinmetall is http://www.rheinmetall.com/career.

Rheinmetall’s AI-Generated Cybersecurity Score

According to Rankiteo, Rheinmetall’s AI-generated cybersecurity score is 780, reflecting their Fair security posture.

How many security badges does Rheinmetall’ have ?

According to Rankiteo, Rheinmetall currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Rheinmetall have SOC 2 Type 1 certification ?

According to Rankiteo, Rheinmetall is not certified under SOC 2 Type 1.

Does Rheinmetall have SOC 2 Type 2 certification ?

According to Rankiteo, Rheinmetall does not hold a SOC 2 Type 2 certification.

Does Rheinmetall comply with GDPR ?

According to Rankiteo, Rheinmetall is not listed as GDPR compliant.

Does Rheinmetall have PCI DSS certification ?

According to Rankiteo, Rheinmetall does not currently maintain PCI DSS compliance.

Does Rheinmetall comply with HIPAA ?

According to Rankiteo, Rheinmetall is not compliant with HIPAA regulations.

Does Rheinmetall have ISO 27001 certification ?

According to Rankiteo,Rheinmetall is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Rheinmetall

Rheinmetall operates primarily in the Defense and Space Manufacturing industry.

Number of Employees at Rheinmetall

Rheinmetall employs approximately 13,148 people worldwide.

Subsidiaries Owned by Rheinmetall

Rheinmetall presently has no subsidiaries across any sectors.

Rheinmetall’s LinkedIn Followers

Rheinmetall’s official LinkedIn profile has approximately 405,989 followers.

NAICS Classification of Rheinmetall

Rheinmetall is classified under the NAICS code 336414, which corresponds to Guided Missile and Space Vehicle Manufacturing.

Rheinmetall’s Presence on Crunchbase

Yes, Rheinmetall has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/rheinmetall.

Rheinmetall’s Presence on LinkedIn

Yes, Rheinmetall maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/rheinmetall.

Cybersecurity Incidents Involving Rheinmetall

As of December 21, 2025, Rankiteo reports that Rheinmetall has experienced 2 cybersecurity incidents.

Number of Peer and Competitor Companies

Rheinmetall has an estimated 2,373 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Rheinmetall ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack and Ransomware.

Incident Details

Can you provide details on each incident ?

Incident : Ransomware

Title: Rheinmetall Cyber Attack

Description: Hackers have assaulted Rheinmetall, a producer of munitions and vehicles. Only civilian business, according to the corporation, is impacted. The attack had no impact on the arms division's output, but the German media is reporting that the attack was not confined to a single subsidiary.

Type: Ransomware

Threat Actor: BlackBasta ransomware organisation

Incident : Cyberattack

Title: Cyberattack on Rheinmetall

Description: An extensive cyberattack on the arms company Rheinmetall was mostly unharmed. Previously unidentified attackers targeted the company's IT systems in an attempt to collapse them. Only the organization website, which an outside service provider runs, was momentarily down. There is no evidence that a potential leak may have an impact on the internal Rheinmetall IT system. As the business is providing, among other things, armored personnel carriers to Ukraine to stave off the Russian onslaught, experts predict that Rheinmetall is the target of Russian hackers who are on the Internet.

Type: Cyberattack

Threat Actor: Russian hackers

Motivation: Political

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : Cyberattack RHE2352823

Systems Affected: Organization website

Downtime: ['Momentary downtime of the website']

Which entities were affected by each incident ?

Incident : Ransomware RHE73630723

Entity Name: Rheinmetall

Entity Type: Corporation

Industry: Munitions, Vehicles

Incident : Cyberattack RHE2352823

Entity Name: Rheinmetall

Entity Type: Company

Industry: Defense

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : Ransomware RHE73630723

Ransomware Strain: BlackBasta

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Ransomware RHE73630723

Investigation Status: Ongoing

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident were an BlackBasta ransomware organisation and Russian hackers.

Impact of the Incidents

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was Organization website.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.

cve

Latest Global CVEs (Not Company-Specific)

Description

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime. An authenticated attacker could abuse this behavior to execute arbitrary code with the privileges of the n8n process. Successful exploitation may lead to full compromise of the affected instance, including unauthorized access to sensitive data, modification of workflows, and execution of system-level operations. This issue has been fixed in versions 1.120.4, 1.121.1, and 1.122.0. Users are strongly advised to upgrade to a patched version, which introduces additional safeguards to restrict expression evaluation. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only; and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

Risk Information
cvss3
Base: 9.9
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description

FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow. `generate_state_token()` is always called with an empty `state_data` dict, so the resulting JWT only contains the fixed audience claim plus an expiration timestamp. On callback, the library merely checks that the JWT verifies under `state_secret` and is unexpired; there is no attempt to match the state value to the browser that initiated the OAuth request, no correlation cookie, and no server-side cache. Any attacker can hit `/authorize`, capture the server-generated state, finish the upstream OAuth flow with their own provider account, and then trick a victim into loading `.../callback?code=<attacker_code>&state=<attacker_state>`. Because the state JWT is valid for any client for \~1 hour, the victim’s browser will complete the flow. This leads to login CSRF. Depending on the app’s logic, the login CSRF can lead to an account takeover of the victim account or to the victim user getting logged in to the attacker's account. Version 15.0.2 contains a patch for the issue.

Risk Information
cvss3
Base: 5.9
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N
Description

FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the application launches.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 8.5
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

LDAP Tool Box Self Service Password 1.5.2 contains a password reset vulnerability that allows attackers to manipulate HTTP Host headers during token generation. Attackers can craft malicious password reset requests that generate tokens sent to a controlled server, enabling potential account takeover by intercepting and using stolen reset tokens.

Risk Information
cvss3
Base: 7.5
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss4
Base: 8.6
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Kimai 1.30.10 contains a SameSite cookie vulnerability that allows attackers to steal user session cookies through malicious exploitation. Attackers can trick victims into executing a crafted PHP script that captures and writes session cookie information to a file, enabling potential session hijacking.

Risk Information
cvss3
Base: 9.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 8.5
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=rheinmetall' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge