Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Samsung Mobile

Samsung Mobile Vendor Cyber Rating & Cyber Score

smsng.co

Samsung Mobile is at the forefront of mobile intelligence, shaping the future with Galaxy AI. With the next evolution of Galaxy AI, we are making lives simpler–reducing stress, creating more time, and getting the help you need without even having to ask. In this era of mobile AI, the freedom to focus on what matters most to you is no longer a dream, but a powerful reality. The future of Galaxy AI is here: more personal, intuitive, and transformative, unlocking endless possibilities and revolutionizing how your Galaxy can work for you. Life opens up with Galaxy AI.


Samsung Mobile A.I CyberSecurity Scoring

Samsung Mobile
Company Information
Website:http://smsng.co/SamsungUnpacked
Employees number:19,542
Number of followers:651,119
NAICS:
Industry Type:Consumer Electronics
Homepage:smsng.co
Samsung Mobile Risk Score (AI oriented)
Between 700 and 749
logo
Samsung MobileConsumer Electronics
Updated:
01/04/2026
745/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Samsung Mobile Global Score (TPRM)
xxxx
logo
Samsung MobileConsumer Electronics
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Samsung Mobile
Samsung MobileModerate
Current Score
745Ba (MODERATE)
01000
7 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
749Before Incident
MAY 2026
747Before Incident
APRIL 2026
746Before Incident
MARCH 2026
744Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
743Before Incident
DECEMBER 2025
741Before Incident
NOVEMBER 2025
740Before Incident
OCTOBER 2025
739Before Incident
SEPTEMBER 2025
738Before Incident
AUGUST 2025
737Before Incident
JULY 2025
735Before Incident
APRIL 2025
733Before Incident
Vulnerability
01 Apr 2025Samsung Mobile
Samsung

LANDFALL Android Spyware Campaign Exploiting Samsung Zero-Day (CVE-2025-21042)

730After Incident
CRITICAL-3
SAM1862118110825
The LANDFALL spyware campaign exploited a zero-day vulnerability (CVE-2025-21042) in Samsung’s Android image processing library, targeting Galaxy devices (S22, S23, S24, Z Fold4, Z Flip4). Distributed via malformed DNG image files on WhatsApp, the malware enabled extensive surveillance—including microphone recording, location tracking, call log theft, and extraction of photos, contacts, and SMS messages. The attack leveraged SELinux manipulation for persistence and evasion, with evidence linking it to commercial spyware operations (e.g., Stealth Falcon, Variston framework) and targeted intrusions in the Middle East (Iraq, Iran, Turkey, Morocco). The vulnerability remained unpatched until April 2025, exposing users for nearly a year. While Samsung later patched related flaws (e.g., CVE-2025-21043), the campaign’s modular design suggests potential for expanded payloads. The attack’s sophistication—combining zero-day exploitation, encrypted C2 communication, and anti-forensic techniques—highlights risks to high-profile individuals, government entities, and critical infrastructure in the region. Palo Alto’s Unit 42 confirmed no WhatsApp vulnerabilities were involved, but the use of a trusted messaging platform amplified the attack’s reach and credibility.
INCIDENT DETAILS -
TYPE
spywarezero-day exploittargeted intrusion
MOTIVATION
surveillancetargeted espionagecommercial spyware deployment
IMPACT
microphone recordingslocation datacall logsphotoscontactsSMS messagesSamsung Galaxy S22/S23/S24Z Fold4Z Flip4potential reputational damage to Samsungconcerns over device securityhigh (PII exfiltration)location tracking
DATA BREACH
PII (contacts, SMS, photos)geolocation datacall logsmicrophone recordingsSensitivity Of Data: high (personal and surveillance data)SELinux policy manipulation for persistenceDNG images (malicious payload)photosSMS databasescontact lists
AUGUST 2024
725Before Incident
Vulnerability
01 Aug 2024Samsung Mobile
Samsung

Exploitation of CVE-2024-7399 in Samsung MagicINFO v9 Server

722After Incident
LOW-3
SAM301050625
In late 2024, attackers began exploiting CVE-2024-7399, an easily reachable path traversal flaw in Samsung MagicINFO v9 Server, to deploy a malicious JSP payload. The vulnerability allowed unauthenticated actors to upload and execute arbitrary scripts on signage management servers, which are commonly deployed in retail stores, transportation hubs, corporate lobbies and healthcare facilities. Once executed, the payload installed a downloader for the Mirai botnet, turning commercial displays into nodes for distributed denial-of-service attacks. Although no sensitive customer or employee information was stolen, the intrusion compromised system integrity and posed a risk of large-scale service disruptions. Administrators reported sporadic outages of digital signage and unusual outbound connections from Windows Server instances. Samsung released a patch in August 2024, but exploitation surged after a proof-of-concept exploit was published. Organizations running MagicINFO v9 prior to version 21.1050.0 faced ongoing exposure until they applied the update. The incident underscores the critical need for timely patch management to avoid opportunistic bottleneck attacks on nontraditional devices.
INCIDENT DETAILS -
TYPE
Botnet Infection
MOTIVATION
DDoS Attacks
IMPACT
Systems Affected: Signage management servers, Windows Server instancesDowntime: Sporadic outages of digital signage
JULY 2024
728Before Incident
Vulnerability
01 Jul 2024Samsung Mobile
Samsung

LANDFALL Android Spyware Campaign Exploiting Samsung Zero-Day (CVE-2025-21042)

724After Incident
CRITICAL-4
SAM5892158110825
Security researchers at Palo Alto Networks uncovered LANDFALL, a sophisticated Android spyware campaign exploiting a zero-day vulnerability (CVE-2025-21042, CVSS 8.8) in Samsung Galaxy devices (S22, S23, S24, Z Fold 4, Z Flip 4). The attack leveraged malformed DNG image files (disguised as WhatsApp transfers) to deploy modular spyware capable of recording audio/calls, tracking location, harvesting SMS/contacts/files, and maintaining persistence via SELinux manipulation. Targets included high-value individuals in Middle East/North Africa (Iraq, Iran, Turkey, Morocco), suggesting state-sponsored or commercial espionage motives. While the flaw was patched in April 2025, the campaign operated since July 2024, exposing users to prolonged surveillance risks. The attack’s zero-click potential (unconfirmed) and modular design (loader + privilege escalation + C2) align with advanced threat actors like Stealth Falcon, historically linked to regional espionage. The incident underscores rising risks in mobile ecosystems, where image-processing libraries (e.g., `libimagecodec.quram.so`) are increasingly exploited for targeted intrusions.
INCIDENT DETAILS -
TYPE
EspionageZero-Day ExploitSpywareMobile Malware
MOTIVATION
Targeted Espionage (likely state-sponsored or commercial spyware)
IMPACT
Microphone Audio/Call RecordingsDevice LocationPhotosSMSFilesContactsCall LogsSamsung Galaxy S22Samsung Galaxy S23Samsung Galaxy S24Samsung Galaxy Z Fold 4Samsung Galaxy Z Flip 4Operational Impact: High (surveillance capabilities, persistence via SELinux policy manipulation)Brand Reputation Impact: Moderate (high-profile zero-day exploit in flagship devices)Identity Theft Risk: High (PII exfiltration)
DATA BREACH
Audio RecordingsLocation DataPhotosSMSFilesContactsCall LogsSensitivity Of Data: High (includes PII and surveillance data)Data Exfiltration: YesDNG Images (malformed, with embedded ZIP payloads)PhotosSMSContactsCall LogsPersonally Identifiable Information: Yes (contacts, call logs, location data)
DECEMBER 2022
711Before Incident
Cyber Attack
01 Dec 2022Samsung Mobile
Samsung Mobile

Samsung Galaxy Devices Hacked at Pwn2Own Event

696After Incident
CRITICAL-15
SAM221971222
Last year, during the Pwn2Own hacking event in Austin, Texas, the Samsung Galaxy S21 devices were hacked, not once but twice, across a period of just 48 hours. This year also the Samsung’s flagship Galaxy S22 smartphone fell to zero-day exploits twice on the same day. But this time, Samsung fixed the issues before malicious threat actors can do any harm.
INCIDENT DETAILS -
TYPE
Zero-day Exploit
MOTIVATION
Research/Event Participation
IMPACT
Samsung Galaxy S21Samsung Galaxy S22
SEPTEMBER 2022
753Before Incident
Breach
01 Sep 2022Samsung Mobile
Samsung Mobile

Samsung Data Breach

707After Incident
CRITICAL-46
SAM15243922
Samsung suffered from a data breach incident, hackers hacked Samsung systems in the U.S that exposed some personal data of U.S customers. The compromised information includes name, contact details, demographic data, date of birth, and product registration data. Samsung said that no credit or debit card information was accessed, nor social security numbers. Customers were warned to be on the lookout for unauthorized emails, messages, or phone calls that could exploit the stolen data to engage them and they got a free credit report.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
namecontact detailsdemographic datadate of birthproduct registration data
DATA BREACH
namecontact detailsdemographic datadate of birthproduct registration datanamecontact detailsdate of birth
MARCH 2022
794Before Incident
Breach
01 Mar 2022Samsung Mobile
Samsung Mobile

Lapsus$ Hacker Group Attack on Samsung

748After Incident
CRITICAL-46
SAM22357322
Samsung was targeted by the Lapsus$ hacker group recently. The attackers gained access to its servers and stole 190GB of confidential data, including the source code of Galaxy devices. The company immediately took off its systems and strengthen its security systems.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Source code of Galaxy devices
DATA BREACH
Source codeSensitivity Of Data: HighData Exfiltration: Yes
JUNE 2015
794Before Incident
Vulnerability
01 Jun 2015Samsung Mobile
Samsung Mobile

Samsung Keyboard Software Bug

790After Incident
CRITICAL-4
SAM21281522
Back in2015 more than 600 million Samsung mobile phones around the world were vulnerable to a software bug was discovered in the phone's keyboard. The bug could allow hackers to secretly monitor the phone's camera and microphone, install apps without permission and monitor text messages. The company identifies the bug and fixed it in the next update to lower down the risks.
INCIDENT DETAILS -
TYPE
Software Vulnerability
MOTIVATION
Unauthorized access and monitoring
IMPACT
Systems Affected: Mobile Phones

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Samsung Mobile ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Samsung Mobile's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Samsung Mobile's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Samsung Mobile ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Samsung Mobile's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?