Samsung Mobile A.I CyberSecurity Scoring
Samsung Mobile
Company Information
Website:http://smsng.co/SamsungUnpacked
Employees number:19,542
Number of followers:651,119
NAICS:
Industry Type:Consumer Electronics
Homepage:smsng.co
Samsung Mobile Risk Score (AI oriented)
Between 700 and 749
Samsung MobileConsumer Electronics
Updated:
01/04/2026
01/04/2026
745/1000
Moderate
Ba
Samsung Mobile Global Score (TPRM)
xxxx
Samsung MobileConsumer Electronics
Score locked

Samsung MobileModerate
Current Score
745Ba (MODERATE)
01000
7 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749
MAY 2026
747
APRIL 2026
746
MARCH 2026
744
FEBRUARY 2026
744
JANUARY 2026
743
DECEMBER 2025
741
NOVEMBER 2025
740
OCTOBER 2025
739
SEPTEMBER 2025
738
AUGUST 2025
737
JULY 2025
735
APRIL 2025
733
Vulnerability
01 Apr 2025 • Samsung Mobile
Samsung
LANDFALL Android Spyware Campaign Exploiting Samsung Zero-Day (CVE-2025-21042)
730
CRITICAL-3
SAM1862118110825
The LANDFALL spyware campaign exploited a zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library, targeting Galaxy devices (S22, S23, S24, Z Fold4, Z Flip4). Distributed via malformed DNG image files on WhatsApp, the malware enabled extensive surveillance—including microphone recording, location tracking, call log theft, and extraction of photos, contacts, and SMS messages. The attack leveraged SELinux manipulation for persistence and evasion, with evidence linking it to commercial spyware operations (e.g., Stealth Falcon, Variston framework) and targeted intrusions in the Middle East (Iraq, Iran, Turkey, Morocco). The vulnerability remained unpatched until April 2025, exposing users for nearly a year. While Samsung later patched related flaws (e.g., CVE-2025-21043), the campaign’s modular design suggests potential for expanded payloads. The attack’s sophistication—combining zero-day exploitation, encrypted C2 communication, and anti-forensic techniques—highlights risks to high-profile individuals, government entities, and critical infrastructure in the region. Palo Alto’s Unit 42 confirmed no WhatsApp vulnerabilities were involved, but the use of a trusted messaging platform amplified the attack’s reach and credibility.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2024
725
Vulnerability
01 Aug 2024 • Samsung Mobile
Samsung
Exploitation of CVE-2024-7399 in Samsung MagicINFO v9 Server
722
LOW-3
SAM301050625
In late 2024, attackers began exploiting CVE-2024-7399, an easily reachable path traversal flaw in Samsung MagicINFO v9 Server, to deploy a malicious JSP payload. The vulnerability allowed unauthenticated actors to upload and execute arbitrary scripts on signage management servers, which are commonly deployed in retail stores, transportation hubs, corporate lobbies and healthcare facilities. Once executed, the payload installed a downloader for the Mirai botnet, turning commercial displays into nodes for distributed denial-of-service attacks. Although no sensitive customer or employee information was stolen, the intrusion compromised system integrity and posed a risk of large-scale service disruptions. Administrators reported sporadic outages of digital signage and unusual outbound connections from Windows Server instances. Samsung released a patch in August 2024, but exploitation surged after a proof-of-concept exploit was published. Organizations running MagicINFO v9 prior to version 21.1050.0 faced ongoing exposure until they applied the update. The incident underscores the critical need for timely patch management to avoid opportunistic bottleneck attacks on nontraditional devices.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
JULY 2024
728
Vulnerability
01 Jul 2024 • Samsung Mobile
Samsung
LANDFALL Android Spyware Campaign Exploiting Samsung Zero-Day (CVE-2025-21042)
724
CRITICAL-4
SAM5892158110825
Security researchers at Palo Alto Networks uncovered LANDFALL, a sophisticated Android spyware campaign exploiting a zero-day vulnerability (CVE-2025-21042, CVSS 8.8) in Samsung Galaxy devices (S22, S23, S24, Z Fold 4, Z Flip 4). The attack leveraged malformed DNG image files (disguised as WhatsApp transfers) to deploy modular spyware capable of recording audio/calls, tracking location, harvesting SMS/contacts/files, and maintaining persistence via SELinux manipulation. Targets included high-value individuals in Middle East/North Africa (Iraq, Iran, Turkey, Morocco), suggesting state-sponsored or commercial espionage motives. While the flaw was patched in April 2025, the campaign operated since July 2024, exposing users to prolonged surveillance risks. The attack’s zero-click potential (unconfirmed) and modular design (loader + privilege escalation + C2) align with advanced threat actors like Stealth Falcon, historically linked to regional espionage. The incident underscores rising risks in mobile ecosystems, where image-processing libraries (e.g., `libimagecodec.quram.so`) are increasingly exploited for targeted intrusions.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2022
711
Cyber Attack
01 Dec 2022 • Samsung Mobile
Samsung Mobile
Samsung Galaxy Devices Hacked at Pwn2Own Event
696
CRITICAL-15
SAM221971222
Last year, during the Pwn2Own hacking event in Austin, Texas, the Samsung Galaxy S21 devices were hacked, not once but twice, across a period of just 48 hours.
This year also the Samsung’s flagship Galaxy S22 smartphone fell to zero-day exploits twice on the same day.
But this time, Samsung fixed the issues before malicious threat actors can do any harm.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
SEPTEMBER 2022
753
Breach
01 Sep 2022 • Samsung Mobile
Samsung Mobile
Samsung Data Breach
707
CRITICAL-46
SAM15243922
Samsung suffered from a data breach incident, hackers hacked Samsung systems in the U.S that exposed some personal data of U.S customers.
The compromised information includes name, contact details, demographic data, date of birth, and product registration data.
Samsung said that no credit or debit card information was accessed, nor social security numbers.
Customers were warned to be on the lookout for unauthorized emails, messages, or phone calls that could exploit the stolen data to engage them and they got a free credit report.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2022
794
Breach
01 Mar 2022 • Samsung Mobile
Samsung Mobile
Lapsus$ Hacker Group Attack on Samsung
748
CRITICAL-46
SAM22357322
Samsung was targeted by the Lapsus$ hacker group recently.
The attackers gained access to its servers and stole 190GB of confidential data, including the source code of Galaxy devices.
The company immediately took off its systems and strengthen its security systems.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2015
794
Vulnerability
01 Jun 2015 • Samsung Mobile
Samsung Mobile
Samsung Keyboard Software Bug
790
CRITICAL-4
SAM21281522
Back in2015 more than 600 million Samsung mobile phones around the world were vulnerable to a software bug was discovered in the phone's keyboard.
The bug could allow hackers to secretly monitor the phone's camera and microphone, install apps without permission and monitor text messages.
The company identifies the bug and fixed it in the next update to lower down the risks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Samsung Mobile ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in May 2026 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in April 2026 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in March 2026 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in February 2026 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in January 2026 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in December 2025 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in November 2025 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in October 2025 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in September 2025 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in August 2025 ??
What was Samsung Mobile's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Samsung Mobile's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Samsung Mobile ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Samsung Mobile's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?