Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
SendGrid

SendGrid Vendor Cyber Rating & Cyber Score

sendgrid.com

SendGrid is a proven cloud-based customer communication platform that successfully delivers over 45 billion emails each month for Internet and mobile-based customers like Airbnb, Pandora, Hubspot, Spotify, Uber, and FourSquare, as well as more traditional enterprises like Taco Bell, Intuit and Costco.


SendGrid A.I CyberSecurity Scoring

SendGrid
Company Information
Website:https://http://www.sendgrid.com/
Employees number:41
Number of followers:20,135
NAICS:
Industry Type:Information Technology & Services
Homepage:sendgrid.com
SendGrid Risk Score (AI oriented)
Between 700 and 749
logo
SendGridInformation Technology & Services
Updated:
10/03/2026
737/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SendGrid Global Score (TPRM)
xxxx
logo
SendGridInformation Technology & Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SendGrid
SendGridModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
738Before Incident
MAY 2026
738Before Incident
APRIL 2026
737Before Incident
MARCH 2026
737Before Incident
FEBRUARY 2026
736Before Incident
JANUARY 2026
736Before Incident
DECEMBER 2025
735Before Incident
NOVEMBER 2025
735Before Incident
OCTOBER 2025
753Before Incident
Cyber Attack
01 Oct 2025SendGrid
SendGrid: Initial access hackers switch to Tsundere Bot for ransomware attacks

TA584 Initial Access Broker Expands Operations with Tsundere Bot and XWorm in Ransomware-Linked Campaigns

734After Incident
CRITICAL-19
SEN1769647301
TA584 Initial Access Broker Expands Operations with Tsundere Bot and XWorm in Ransomware-Linked Campaigns A prolific initial access broker (IAB) tracked as TA584 has escalated its activity, deploying the Tsundere Bot malware alongside the XWorm remote access trojan (RAT) to compromise networks likely as a precursor to ransomware attacks. Researchers at Proofpoint, who have monitored the group since 2020, report a threefold increase in TA584’s campaign volume in late 2025, expanding its targeting beyond traditional regions (North America, UK/Ireland) to include Germany, other European countries, and Australia. ### Attack Chain & Tactics TA584’s latest campaigns begin with phishing emails sent via compromised, aged accounts using SendGrid and Amazon SES. Each target receives a unique URL, with geofencing, IP filtering, and redirect chains (often leveraging Keitaro TDS) to evade detection. Victims who bypass these filters encounter a CAPTCHA page, followed by a ClickFix prompt instructing them to execute a PowerShell command a tactic designed to bypass static defenses. The command fetches an obfuscated script that loads XWorm or Tsundere Bot into memory, while the browser redirects to a benign site to mask the infection. TA584 has historically deployed a range of payloads, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT (still observed in 2025). ### Tsundere Bot: A Malware-as-a-Service Threat Originally documented by Kaspersky in 2024 and linked to a Russian-speaking operator (with ties to 123 Stealer), Tsundere Bot functions as both a backdoor and loader. Key features include: - Node.js dependency: The malware installs Node.js on victim systems via its command-and-control (C2) panel. - Blockchain-based C2 retrieval: Uses a variant of EtherHiding to fetch C2 addresses from the Ethereum blockchain, with a hardcoded fallback. - WebSocket communication: Evades traditional network monitoring. - Geofencing: Aborts execution if the system locale matches CIS (Commonwealth of Independent States) languages, suggesting Russian origin. - Data exfiltration & lateral movement: Collects system information, executes arbitrary JavaScript, and can turn infected hosts into SOCKS proxies. - Bot marketplace: Operators can buy and sell access to compromised machines. ### Broader Implications Proofpoint assesses with high confidence that Tsundere Bot infections could lead to ransomware deployment, given TA584’s history of facilitating such attacks. The group’s expanded targeting and experimentation with payloads suggest a growing threat, with researchers anticipating further diversification in victims and attack methods.
INCIDENT DETAILS -
TYPE
phishingmalwareinitial access broker activitypotential ransomware precursor
MOTIVATION
financial gainfacilitating ransomware attacks
IMPACT
system informationpotential personally identifiable information (PII)compromised networksinfected hostspotential lateral movementdata exfiltrationhigh (if PII is exfiltrated)
DATA BREACH
system informationpotential PIIhigh (if PII is exfiltrated)Data Exfiltration: possible (Tsundere Bot and XWorm capabilities)Personally Identifiable Information: possible
SEPTEMBER 2025
753Before Incident
AUGUST 2025
753Before Incident
JULY 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SendGrid ?
?
What was SendGrid's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in September 2025 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in August 2025 ?
?
What was SendGrid's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on SendGrid's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SendGrid ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SendGrid's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?