Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Saint-Gobain

Saint-Gobain Vendor Cyber Rating & Cyber Score

saint-gobain.com

Saint-Gobain designs, manufactures and distributes materials and solutions for the construction, mobility and industrial markets. Developed through a continuous innovation process, our integrated solutions provide sustainability and performance in daily life, addressing the renovation of public and


Saint-Gobain A.I CyberSecurity Scoring

Saint-Gobain
Company Information
Website:https://www.saint-gobain.com/fr
Employees number:36,161
Number of followers:1,125,428
NAICS:4233
Industry Type:Wholesale Building Materials
Homepage:saint-gobain.com
Saint-Gobain Risk Score (AI oriented)
Between 650 and 699
logo
Saint-GobainWholesale Building Materials
Updated:
02/04/2026
694/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Saint-Gobain Global Score (TPRM)
xxxx
logo
Saint-GobainWholesale Building Materials
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Saint-Gobain
Saint-GobainWeak
Current Score
694B (WEAK)
01000
3 incidents
-44 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
706Before Incident
MAY 2026
702Before Incident
APRIL 2026
700Before Incident
MARCH 2026
693Before Incident
FEBRUARY 2026
692Before Incident
JANUARY 2026
693Before Incident
Vulnerability
26 Jan 2026Saint-Gobain
Cisco, City of Saint Paul and Minnesota: Ransomware crims abused Cisco 0-day weeks before disclosure

Interlock Ransomware Exploited Zero-Day in Cisco Firewall Before Patch

690After Incident
CRITICAL-3
CISSAI1773859283
Interlock Ransomware Exploited Zero-Day in Cisco Firewall Before Patch Ransomware group Interlock exploited a maximum-severity zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center more than a month before the vendor released a patch. The flaw, allowing unauthenticated remote attackers to execute arbitrary Java code as root, was actively abused starting January 26, while Cisco issued fixes on March 4. Amazon’s CJ Moses, CISO of Amazon Integrated Security, revealed the timeline, stating that the company’s MadPot honeypot network detected exploit traffic tied to Interlock’s infrastructure. A misconfigured server also exposed the group’s attack toolkit, providing defenders with critical intelligence. ### Interlock’s Tactics and Toolkit Interlock, a ransomware crew active since 2025, has targeted hospitals, medical facilities, and government entities, disrupting critical services including chemotherapy sessions and pre-surgery appointments and leaking sensitive data. Victims include Davita (kidney dialysis), Kettering Health, and the city of Saint Paul, Minnesota, where a 43 GB data breach forced a state of emergency. The group’s post-exploitation toolkit includes: - A PowerShell script harvesting system details (OS, hardware, services, software, storage, VM inventory, user files, RDP logs, and browser data). - Custom remote access trojans (RATs) in JavaScript and Java, providing persistent access, command execution, file transfer, and SOCKS5 proxy capabilities. - A Bash script configuring Linux servers as reverse proxies, wiping logs, and ensuring persistence. - Memory-resident backdoors and lightweight network beacons to evade detection. - Legitimate tools like ConnectWise ScreenConnect, Volatility, and Certify to blend malicious activity with authorized remote access. ### Redundant Access and Extortion Tactics Interlock deploys multiple backdoors including dual-language implants (JavaScript and Java) to maintain access even if one is detected. Their ransom notes threaten regulatory exposure, leveraging compliance violations alongside data encryption and leaks to pressure victims. Cisco has updated its security advisory, urging customers to apply patches immediately. The incident underscores the growing sophistication of ransomware groups in exploiting zero-days before public disclosure.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain, data extortion, regulatory pressure
IMPACT
Data Compromised: 43 GB (Saint Paul, Minnesota incident)Systems Affected: Cisco Secure Firewall Management Center, hospital systems, government entitiesOperational Impact: Disrupted chemotherapy sessions, pre-surgery appointments, and critical servicesBrand Reputation Impact: High (data leaks, service disruptions)Legal Liabilities: Potential regulatory violationsIdentity Theft Risk: High (sensitive data leaked)
DATA BREACH
Type Of Data Compromised: Sensitive personal data, medical records, government dataSensitivity Of Data: High (PII, medical data)Data Exfiltration: Yes (43 GB leaked in Saint Paul incident)Data Encryption: Yes (ransomware encryption)Personally Identifiable Information: Yes
DECEMBER 2025
691Before Incident
NOVEMBER 2025
768Before Incident
OCTOBER 2025
768Before Incident
Ransomware
20 Oct 2025Saint-Gobain
Kettering Health

ClickFix (Fake CAPTCHA) Social Engineering Attacks

683After Incident
CRITICAL-85
KET5232452102025
Kettering Health, a major healthcare provider, fell victim to a ClickFix attack linked to the Interlock ransomware group, resulting in a significant data breach. The attack exploited social engineering tactics, tricking employees into executing malicious scripts via browser-based lures (e.g., fake CAPTCHAs or error-fixing prompts). The malicious payload was copied to the clipboard via obfuscated JavaScript and executed locally, bypassing traditional email security and endpoint detection. The breach compromised sensitive patient and employee data, including medical records, financial details, and personally identifiable information (PII). The attack leveraged SEO poisoning and malvertising via Google Search, evading conventional phishing defenses. Despite EDR (Endpoint Detection and Response) being the last line of defense, the obfuscated, user-initiated commands delayed detection, allowing the ransomware to encrypt critical systems. The incident disrupted healthcare operations, risked patient safety due to delayed treatments, and exposed Kettering Health to reputational damage, financial penalties, and potential legal liabilities. The breach underscored vulnerabilities in both technical controls and user awareness, particularly against browser-based, fileless attacks.
INCIDENT DETAILS -
TYPE
Social EngineeringMalvertisingSEO PoisoningClipboard HijackingFake CAPTCHAWatering Hole Attack
MOTIVATION
Financial Gain (Ransomware, Data Theft)Credential HarvestingLateral Movement for Targeted AttacksEspionage (APT-Linked)Session Hijacking
IMPACT
Credentials (Stored in Browsers)Cookies (Session Tokens)Potentially PII (Depending on Follow-on Exploitation)Endpoints (User Devices)Browsers (Chrome, Edge, Firefox, etc.)Potential Network Lateral MovementDisruption from Ransomware (Linked Cases)Incident Response OverheadProductivity Loss (User Remediation)Erosion of Trust (Phishing/Social Engineering)Associated with High-Profile Breaches (e.g., Healthcare, Education)High (If Credentials/Cookies Stolen)Potential (If Browser-Stored Payment Data Accessed)
DATA BREACH
CredentialsSession CookiesPotentially PII (Context-Dependent)High (If Credentials/Cookies Lead to Further Compromise)Likely (For Ransomware/APT Groups)Possible (If Follow-on Attacks Occur)
SEPTEMBER 2025
766Before Incident
AUGUST 2025
765Before Incident
JULY 2025
764Before Incident
JANUARY 2024
803Before Incident
Ransomware
01 Jan 2024Saint-Gobain
City of Saint Paul, Minnesota and Texas Tech University System: AI-built Slopoly malware used in ransomware attacks

New AI-Assisted Malware 'Slopoly' Linked to Hive0163 Ransomware Campaigns

745After Incident
CRITICAL-58
SAITEX1773412315
New AI-Assisted Malware "Slopoly" Linked to Hive0163 Ransomware Campaigns A recently identified malware strain, Slopoly, is being deployed in ransomware attacks tied to the financially motivated threat group Hive0163. Security researchers at IBM X-Force report that the backdoor shows signs of generative AI-assisted development, marking an emerging trend in cybercriminal tooling. The malware was used in an Interlock ransomware attack where attackers lingered on a compromised server for over a week, exfiltrating sensitive data. The intrusion began with a ClickFix social-engineering tactic, followed by the installation of Slopoly as a PowerShell script communicating with a command-and-control (C2) server. While Slopoly’s code includes unusually polished features such as detailed comments, structured logging, and robust error handling researchers could not confirm which large language model (LLM) was used in its creation. Despite its self-described "polymorphic" label, the malware lacks true polymorphic capabilities, instead relying on a builder tool to randomize configuration values like beaconing intervals and C2 addresses. Once deployed in C:\ProgramData\Microsoft\Windows\Runtime\, Slopoly performs several functions: - Collects system information - Sends heartbeat signals to the C2 server every 30 seconds - Polls for commands every 50 seconds - Executes commands via cmd.exe and relays results - Maintains persistence via a scheduled task named "Runtime Broker" The malware supports commands for downloading and executing payloads (EXE, DLL, JavaScript), running shell commands, adjusting beaconing intervals, updating itself, or terminating its process. In the same campaign, attackers also deployed NodeSnake and InterlockRAT backdoors before delivering the Interlock ransomware via the JunkFiction loader. First observed in 2024, the Interlock ransomware operation is known for ClickFix and FileFix social-engineering techniques and has previously targeted organizations like Texas Tech University System, DaVita, Kettering Health, and the city of Saint Paul, Minnesota. IBM researchers also noted possible connections between Hive0163 and developers linked to other malware families, including Broomstick, SocksShell, PortStarter, SystemBC, and Rhysida ransomware, suggesting overlapping tools or collaboration within the cybercrime ecosystem.
INCIDENT DETAILS -
TYPE
ransomwaremalware
MOTIVATION
financial
IMPACT
Data Compromised: sensitive data exfiltrated
DATA BREACH
Type Of Data Compromised: sensitive data

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Saint-Gobain ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Saint-Gobain's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Saint-Gobain's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Saint-Gobain ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Saint-Gobain's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?