Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Sangoma

Sangoma Vendor Cyber Rating & Cyber Score

sangoma.com

Sangoma Technologies Corporation (TSX: STC; Nasdaq: SANG) is a global leader in essential business communications. For more than 40 years, Sangoma has provided secure, reliable, and cost-effective solutions to over 100,000 customers in more than 180 countries. Sangoma is a full-suite partner for all communications needs, offering unified communications, networking, SIP trunking, wholesale voice, and security. Its UC platform is developed fully in-house and available in cloud, hybrid, or on-premises models. Sangoma delivers vertical-specific communications solutions for healthcare, education, hospitality, retail, restaurants, and manufacturing. These services can be bundled, giving organizations one trusted source for voice, data, and


Sangoma A.I CyberSecurity Scoring

Sangoma
Company Information
Website:http://www.sangoma.com
Employees number:622
Number of followers:47,352
NAICS:517
Industry Type:Telecommunications
Homepage:sangoma.com
Sangoma Risk Score (AI oriented)
Between 650 and 699
logo
SangomaTelecommunications
Updated:
20/05/2026
652/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Sangoma Global Score (TPRM)
xxxx
logo
SangomaTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Sangoma
SangomaWeak
Current Score
652B (WEAK)
01000
4 incidents
-6 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
654Before Incident
MAY 2026
651Before Incident
APRIL 2026
651Before Incident
MARCH 2026
649Before Incident
FEBRUARY 2026
646Before Incident
JANUARY 2026
645Before Incident
DECEMBER 2025
642Before Incident
NOVEMBER 2025
639Before Incident
OCTOBER 2025
638Before Incident
SEPTEMBER 2025
635Before Incident
AUGUST 2025
638Before Incident
Vulnerability
21 Aug 2025Sangoma
Sangoma Technologies Corporation

FreePBX Zero-Day Vulnerability Exploited in Administrator Control Panels

632After Incident
CRITICAL-6
SAN537082825
The Sangoma FreePBX Security Team disclosed an actively exploited zero-day vulnerability in FreePBX systems with exposed Administrator Control Panels (ACP). Attackers breached servers since August 21, executing arbitrary commands via the Asterisk user privileges. Multiple customers reported compromises, including 3,000 SIP extensions and 500 trunks affected in one case. Indicators of compromise (IOCs) included modified `/etc/freepbx.conf`, malicious shell scripts (`/var/www/html/.clean.sh`), suspicious Apache logs (`modular.php`), unauthorized calls to extension 9998, and rogue entries in the MariaDB/MySQL `ampusers` table.Victims faced unauthorized international call traffic, potential credential theft, and system takeover. Sangoma urged admins to block ACP access, restore from pre-August 21 backups, rotate all SIP/system credentials, and deploy an EDGE module patch (though expired support contracts left some systems unprotected). The flaw’s exploitation led to full server breaches, financial fraud via telephony abuse, and operational disruption for businesses relying on FreePBX for voice communications. The attack vector leveraged exposed administrative interfaces, highlighting critical gaps in default security configurations.
INCIDENT DETAILS -
TYPE
Zero-day exploitationUnauthorized accessCommand injection
MOTIVATION
Opportunistic exploitationPotential financial gain (e.g., toll fraud via unauthorized calls)
IMPACT
SIP extension configurationsTrunk configurationsCall recordsSystem credentialsFreePBX v16FreePBX v17PBXAct v16PBXAct v17Compromised voice communicationsUnauthorized call routingAdministrator lockouts during responseBrand Reputation Impact: Potential reputational damage due to breached voice systems and exposed customer communications
DATA BREACH
System configurationsCall routing dataCredentialsPotential call metadataSensitivity Of Data: High (voice communications infrastructure)Data Exfiltration: Likely (evidenced by unauthorized database entries and shell scripts)/etc/freepbx.confMariaDB/MySQL ampusers tableApache/Asterisk logsPersonally Identifiable Information: Potential (if call records included PII)
JULY 2025
636Before Incident
OCTOBER 2024
701Before Incident
Breach
23 Oct 2024Sangoma
Sangoma Technologies Inc.

Data Breach at Sangoma Technologies Inc.

614After Incident
HIGH-87
SAN233080525
On May 21, 2025, the Maine Attorney General's Office reported a data breach involving Sangoma Technologies Inc. The breach occurred between October 23 and October 24, 2024, due to unauthorized access to NetFortris systems, affecting approximately 889 individuals. The compromised information included personal details of current and former employees, contractors, and applicants.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Personal details of current and former employees, contractors, and applicantsNetFortris systems
DATA BREACH
Personal details
JANUARY 2021
632Before Incident
Vulnerability
01 Jan 2021Sangoma
Sangoma: FreePBX Vulnerability Allow Attackers to Gain Access to User Portals

Critical FreePBX Vulnerability Exposes User Portals to Unauthenticated Attacks

627After Incident
CRITICAL-5
SAN1779287064
Critical FreePBX Vulnerability Exposes User Portals to Unauthenticated Attacks A severe security flaw in the open-source IP PBX platform FreePBX (CVE-2026-46376) allows unauthenticated attackers to gain access to user portals via hard-coded credentials in the User Control Panel (UCP). The vulnerability affects FreePBX versions prior to 16.0.45 and 17.0.7, stemming from default credentials embedded in the userman module’s generic template during setup. The issue arises when administrators fail to modify default credentials after deployment, leaving systems exposed. Attackers can exploit this flaw without prior access, privileges, or user interaction, making it particularly dangerous in exposed environments. Classified under CWE-798 (Use of Hard-coded Credentials), the vulnerability carries a CVSS v4 score of 9.1 (Critical) due to its low-complexity, network-based attack vector. Successful exploitation could lead to: - Unauthorized access to user accounts via the UCP. - Exposure of sensitive data. - Manipulation of user settings and configurations. The flaw was introduced in a 2021 code change and publicly disclosed under advisory GHSA-m55x-h47x-v3gx by researcher chrsmj, with remediation developed by Sangoma. FreePBX has released patches version 16.0.45+ for FreePBX 16 and 17.0.7+ for FreePBX 17 to address the issue. Organizations are urged to audit deployments for unmodified default credentials and implement additional security measures, such as restricting UCP/ACP access via VPN, MFA, or IP-based restrictions. The incident highlights the risks of insecure default configurations in enterprise systems.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Sensitive data exposureSystems Affected: FreePBX User Control Panel (UCP)Operational Impact: Unauthorized access to user accounts, manipulation of user settings and configurations
DATA BREACH
Type Of Data Compromised: User account data, sensitive configurationsSensitivity Of Data: High (user settings, configurations)
DECEMBER 2020
750Before Incident
Ransomware
01 Dec 2020Sangoma
Sangoma

Conti Ransomware Attack on Sangoma Technologies Corporation

630After Incident
CRITICAL-120
SAN3019222
The data from Sangoma Technologies Corporation was breached in the Conti ransomware attack. The gang published over 26 GB of the stolen data including the company's accounting, financials, acquisitions, employee benefits and salary, and legal documents on their data leak site.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial
IMPACT
accountingfinancialsacquisitionsemployee benefits and salarylegal documents
DATA BREACH
accountingfinancialsacquisitionsemployee benefits and salarylegal documentsSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Sangoma ?
?
What was Sangoma's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Sangoma's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Sangoma's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Sangoma ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Sangoma's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?