ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

We’re a leading producer of the energy and chemicals that drive global commerce and enhance the daily lives of people around the globe by continuing delivering an uninterrupted supply of energy to the world. Our resilience and agility has built one of the world’s largest integrated energy and chemicals companies. And we are part of the global effort toward building a low carbon economy. Our horizon has never been clearer.

aramco A.I CyberSecurity Scoring

aramco

Company Details

Linkedin ID:

saudi-aramco

Employees number:

152,474

Number of followers:

6,041,279

NAICS:

211

Industry Type:

Oil and Gas

Homepage:

aramco.com

IP Addresses:

0

Company ID:

ARA_2248243

Scan Status:

In-progress

AI scorearamco Risk Score (AI oriented)

Between 800 and 849

https://images.rankiteo.com/companyimages/saudi-aramco.jpeg
aramco Oil and Gas
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscorearamco Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/saudi-aramco.jpeg
aramco Oil and Gas
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

aramco Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
Saudi AramcoCyber Attack10058/2017
Rankiteo Explanation :
Attack threatening the organization’s existence

Description: In August 2017, the Petro Rabigh complex, part-operated by Saudi Aramco, experienced a significant cybersecurity incident involving the Triton malware. This malware targeted Schneider Electric safety equipment within the facility, leading to the shutdown of part of the complex. The attack was distinguished by its sophistication, targeting the safety systems designed to prevent catastrophic industrial accidents. The Triton malware attack not only signaled a new chapter in cyber warfare aimed at industrial control systems but also demonstrated the potential for causing physical damage and even loss of life. The attack was later attributed with high confidence to a state-backed actor, showcasing the evolving landscape of cyber threats to critical infrastructure around the globe. The incident underscored the necessity for heightened cybersecurity measures and resilience against sophisticated cyberespionage tools targeting industrial safety and control systems.

Saudi Aramco
Cyber Attack
Severity: 100
Impact: 5
Seen: 8/2017
Blog:
Rankiteo Explanation
Attack threatening the organization’s existence

Description: In August 2017, the Petro Rabigh complex, part-operated by Saudi Aramco, experienced a significant cybersecurity incident involving the Triton malware. This malware targeted Schneider Electric safety equipment within the facility, leading to the shutdown of part of the complex. The attack was distinguished by its sophistication, targeting the safety systems designed to prevent catastrophic industrial accidents. The Triton malware attack not only signaled a new chapter in cyber warfare aimed at industrial control systems but also demonstrated the potential for causing physical damage and even loss of life. The attack was later attributed with high confidence to a state-backed actor, showcasing the evolving landscape of cyber threats to critical infrastructure around the globe. The incident underscored the necessity for heightened cybersecurity measures and resilience against sophisticated cyberespionage tools targeting industrial safety and control systems.

Ailogo

aramco Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for aramco

Incidents vs Oil and Gas Industry Average (This Year)

No incidents recorded for aramco in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for aramco in 2025.

Incident Types aramco vs Oil and Gas Industry Avg (This Year)

No incidents recorded for aramco in 2025.

Incident History — aramco (X = Date, Y = Severity)

aramco cyber incidents detection timeline including parent company and subsidiaries

aramco Company Subsidiaries

SubsidiaryImage

We’re a leading producer of the energy and chemicals that drive global commerce and enhance the daily lives of people around the globe by continuing delivering an uninterrupted supply of energy to the world. Our resilience and agility has built one of the world’s largest integrated energy and chemicals companies. And we are part of the global effort toward building a low carbon economy. Our horizon has never been clearer.

Loading...
similarCompanies

aramco Similar Companies

Baker Hughes

Baker Hughes (NASDAQ: BKR) is an energy technology company that provides solutions for energy and industrial customers worldwide. Built on a century of experience and conducting business in over 120 countries, our innovative technologies and services are taking energy forward – making it safer, clea

PDVSA Petróleos de Venezuela S.A.

Petróleos de Venezuela S.A. is a Venezuelan state company, began operations on January 1st, 1976 and whose activities are the oil exploration, production, refining, marketing and transportation of Venezuelan oil as well as the orimulsion, chemical, petrochemical businesses and coal. We have the lar

En YPF, tenemos un Plan 4x4 para convertirnos en una compañía de clase mundial y lograr transformarnos en grandes exportadores de hidrocarburos. Nuestros cuatro pilares son: la aceleración de la producción de petróleo en Vaca Muerta, el activo más importante que tiene nuestro país; la disciplina f

Weatherford

Weatherford International plc (Nasdaq: WFRD) is a leading global energy services company. Operating in approximately 75 countries, the Company answers the challenges of the energy industry with its global talent network of approximately 17,000 team members and approximately 350 operating locations,

Valero

Valero is an international manufacturer and marketer of transportation fuels and petrochemical products. We are a Fortune 500 company based in San Antonio, Texas, fueled by nearly 10,000 employees and 15 petroleum refineries with a combined throughput capacity of approximately 3.2 million barrels pe

NOV delivers technology-driven solutions to empower the global energy industry. For more than 150 years, NOV has pioneered innovations that enable its customers to safely produce abundant energy while minimizing environmental impact. The energy industry depends on NOV’s deep expertise and technology

PEMEX

Petróleos Mexicanos es la mayor empresa de México, el mayor contribuyente fiscal del país, así como una de las empresas más grandes de América Latina. Es de las pocas empresas petroleras del mundo que desarrolla toda la cadena productiva de la industria, desde la exploración, hasta la distribució

Nosso propósito é prover energia que assegure prosperidade de forma ética, justa, segura e competitiva. Queremos ser a melhor empresa diversificada e integrada de energia na geração de valor, construindo um mundo mais sustentável, conciliando o foco em óleo e gás com a diversificação em negócios de

TechnipFMC

TechnipFMC is a leading technology provider to the traditional and new energies industry, delivering fully integrated projects, products, and services. With our proprietary technologies and comprehensive solutions, we are transforming our clients’ project economics, helping them unlock new possibi

newsone

aramco CyberSecurity News

November 27, 2025 09:38 AM
Aramco Ventures to Open Paris Office in 2026 to Expand AI Investment

Aramco Ventures, the investment arm of Saudi oil-major Saudi Aramco, is opening an office in Paris to manage and expand its European...

March 17, 2025 07:00 AM
Saudi Arabia grants Tier 1 cybersecurity licenses to six MSOC providers

Saudi Arabia's National Cybersecurity Authority (NCA) has granted Tier 1 licenses to six companies to provide Managed Security Operations...

March 04, 2025 08:00 AM
Saudi Intelligence Data Leak Surfaces on the Dark Web

A threat actor operating on a dark web forum has allegedly published 11 GB of data purportedly belonging to Saudi Arabia's General Intelligence Presidency (GIP...

February 04, 2025 08:00 AM
WEF: Supply Chains at Heart of Cybersecurity Threats

As risks evolve, organisations must strengthen resilience through collaboration and vigilance, the World Economic Forum advises in its...

January 13, 2025 08:00 AM
New Honeywell cybersecurity services center launches in Saudi Arabia’s Jubail to enhance industrial protection

Honeywell (NASDAQ: HON) has launched a new center in Jubail, Saudi Arabia, dedicated to providing localized Honeywell cybersecurity...

December 25, 2024 08:00 AM
How to Get a Cybersecurity Analyst Role in Saudi Arabia?

Discover how to get a cybersecurity analyst role in Saudi Arabia. Learn about education, essential skills, networking, and job search...

December 05, 2024 08:00 AM
Top 10: CISOs

With CISOs leading the security posture of a company, Cyber Magazine examines the top 10 CISOs who exemplify excellence in the field.

October 03, 2024 07:00 AM
Aramco Digital aims to make Saudi Arabia a cybersecurity, AI leader, says top executive

Aramco Digital is at the forefront of Saudi Arabia's shift toward a technology-driven economy, implementing key initiatives in cybersecurity, 5G infrastructure...

September 10, 2024 07:00 AM
Aramco unveils new initiatives to drive digital development

Ahmad Al-Khowaiter, Aramco EVP of Technology & Innovation, speaks at the Global AI Summit (GAIN) in Riyadh, Saudi Arabia.

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

aramco CyberSecurity History Information

Official Website of aramco

The official website of aramco is https://www.aramco.com.

aramco’s AI-Generated Cybersecurity Score

According to Rankiteo, aramco’s AI-generated cybersecurity score is 836, reflecting their Good security posture.

How many security badges does aramco’ have ?

According to Rankiteo, aramco currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does aramco have SOC 2 Type 1 certification ?

According to Rankiteo, aramco is not certified under SOC 2 Type 1.

Does aramco have SOC 2 Type 2 certification ?

According to Rankiteo, aramco does not hold a SOC 2 Type 2 certification.

Does aramco comply with GDPR ?

According to Rankiteo, aramco is not listed as GDPR compliant.

Does aramco have PCI DSS certification ?

According to Rankiteo, aramco does not currently maintain PCI DSS compliance.

Does aramco comply with HIPAA ?

According to Rankiteo, aramco is not compliant with HIPAA regulations.

Does aramco have ISO 27001 certification ?

According to Rankiteo,aramco is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of aramco

aramco operates primarily in the Oil and Gas industry.

Number of Employees at aramco

aramco employs approximately 152,474 people worldwide.

Subsidiaries Owned by aramco

aramco presently has no subsidiaries across any sectors.

aramco’s LinkedIn Followers

aramco’s official LinkedIn profile has approximately 6,041,279 followers.

NAICS Classification of aramco

aramco is classified under the NAICS code 211, which corresponds to Oil and Gas Extraction.

aramco’s Presence on Crunchbase

Yes, aramco has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/aramco-overseas-company.

aramco’s Presence on LinkedIn

Yes, aramco maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/saudi-aramco.

Cybersecurity Incidents Involving aramco

As of December 06, 2025, Rankiteo reports that aramco has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

aramco has an estimated 10,499 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at aramco ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.

Incident Details

Can you provide details on each incident ?

Incident : Cyberattack

Title: Triton Malware Attack on Petro Rabigh Complex

Description: In August 2017, the Petro Rabigh complex, part-operated by Saudi Aramco, experienced a significant cybersecurity incident involving the Triton malware. This malware targeted Schneider Electric safety equipment within the facility, leading to the shutdown of part of the complex. The attack was distinguished by its sophistication, targeting the safety systems designed to prevent catastrophic industrial accidents. The Triton malware attack not only signaled a new chapter in cyber warfare aimed at industrial control systems but also demonstrated the potential for causing physical damage and even loss of life. The attack was later attributed with high confidence to a state-backed actor, showcasing the evolving landscape of cyber threats to critical infrastructure around the globe. The incident underscored the necessity for heightened cybersecurity measures and resilience against sophisticated cyberespionage tools targeting industrial safety and control systems.

Date Detected: August 2017

Type: Cyberattack

Attack Vector: Malware

Vulnerability Exploited: Schneider Electric safety equipment

Threat Actor: State-backed actor

Motivation: Cyber warfare, industrial espionage

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Impact of the Incidents

What was the impact of each incident ?

Incident : Cyberattack SAU507050724

Systems Affected: Schneider Electric safety equipment

Downtime: Partial shutdown of the complex

Operational Impact: Significant

Brand Reputation Impact: High

Which entities were affected by each incident ?

Incident : Cyberattack SAU507050724

Entity Name: Petro Rabigh

Entity Type: Industrial Complex

Industry: Oil and Gas

Location: Saudi Arabia

Lessons Learned and Recommendations

What lessons were learned from each incident ?

Incident : Cyberattack SAU507050724

Lessons Learned: Necessity for heightened cybersecurity measures and resilience against sophisticated cyberespionage tools targeting industrial safety and control systems.

What recommendations were made to prevent future incidents ?

Incident : Cyberattack SAU507050724

Recommendations: Heightened cybersecurity measures and resilience against sophisticated cyberespionage tools.

What are the key lessons learned from past incidents ?

Key Lessons Learned: The key lessons learned from past incidents are Necessity for heightened cybersecurity measures and resilience against sophisticated cyberespionage tools targeting industrial safety and control systems.

What recommendations has the company implemented to improve cybersecurity ?

Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Heightened cybersecurity measures and resilience against sophisticated cyberespionage tools..

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Cyberattack SAU507050724

Root Causes: Vulnerabilities in Schneider Electric safety equipment

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an State-backed actor.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on August 2017.

Impact of the Incidents

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was Schneider Electric safety equipment.

Lessons Learned and Recommendations

What was the most significant lesson learned from past incidents ?

Most Significant Lesson Learned: The most significant lesson learned from past incidents was Necessity for heightened cybersecurity measures and resilience against sophisticated cyberespionage tools targeting industrial safety and control systems.

What was the most significant recommendation implemented to improve cybersecurity ?

Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Heightened cybersecurity measures and resilience against sophisticated cyberespionage tools..

cve

Latest Global CVEs (Not Company-Specific)

Description

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social login providers such as Google, GitHub, GitLab, Facebook or Dropbox lack CSRF protection, since they don't send a state parameter and verify the response using this parameter. This vulnerability is fixed in 1.10.4.

Risk Information
cvss3
Base: 3.7
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
Description

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. An attacker-controlled origin can therefore obtain fresh access_token / refresh_token pairs for a victim session. Obtained tokens permit access to authenticated endpoints — including built-in code-execution functionality — allowing the attacker to execute arbitrary code and achieve full system compromise.

Risk Information
cvss4
Base: 9.4
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was detected in xerrors Yuxi-Know up to 0.4.0. This vulnerability affects the function OtherEmbedding.aencode of the file /src/models/embed.py. Performing manipulation of the argument health_url results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The patch is named 0ff771dc1933d5a6b78f804115e78a7d8625c3f3. To fix this issue, it is recommended to deploy a patch. The vendor responded with a vulnerability confirmation and a list of security measures they have established already (e.g. disabled URL parsing, disabled URL upload mode, removed URL-to-markdown conversion).

Risk Information
cvss2
Base: 5.8
Severity: LOW
AV:N/AC:L/Au:M/C:P/I:P/A:P
cvss3
Base: 4.7
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 5.1
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rarlab.rar. Such manipulation leads to path traversal. It is possible to launch the attack remotely. Attacks of this nature are highly complex. It is indicated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 7.20 build 128 is able to mitigate this issue. You should upgrade the affected component. The vendor responded very professional: "This is the real vulnerability affecting RAR for Android only. WinRAR and Unix RAR versions are not affected. We already fixed it in RAR for Android 7.20 build 128 and we publicly mentioned it in that version changelog. (...) To avoid confusion among users, it would be useful if such disclosure emphasizes that it is RAR for Android only issue and WinRAR isn't affected."

Risk Information
cvss2
Base: 5.1
Severity: HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
cvss3
Base: 5.0
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
cvss4
Base: 2.3
Severity: HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument safe_dir causes command injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 9.0
Severity: LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
cvss3
Base: 8.8
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cvss4
Base: 7.4
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=saudi-aramco' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge