Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Social Security Organization, IRAN

Social Security Organization, IRAN Vendor Cyber Rating & Cyber Score

tamin.ir

Social Security Organization (SSO) is a social insurer organization in Iran which provides coverage of wage-earners and salaried workers as well as voluntary coverage of self-employed persons. In 1975, the Social Security Law was approved and the SSO was established. Iran did not legislate in favor of a universal social protection, but in 1996, the Center of the Statistics of Iran estimated that more than 73% of the Iranian population was covered by social security. Membership in the social security system is compulsory for all employees. SSO is a nongovernmental organization and it is solely financed by contributions (with participation of insured (7%), employer (20–23%) and government (3%)). Social protection is extended to the


SSOI A.I CyberSecurity Scoring

SSOI
Company Information
Website:http://www.tamin.ir
Employees number:1,034
Number of followers:1,804
NAICS:524
Industry Type:Insurance
Homepage:tamin.ir
SSOI Risk Score (AI oriented)
Between 0 and 549
logo
SSOIInsurance
Updated:
04/04/2026
328/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SSOI Global Score (TPRM)
xxxx
logo
SSOIInsurance
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SSOI
SSOICritical
Current Score
328C (CRITICAL)
01000
4 incidents
-116.67 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
350Before Incident
MAY 2026
338Before Incident
APRIL 2026
335Before Incident
MARCH 2026
482Before Incident
Breach
10 Mar 2026SSOI
Social Security Administration: Report Says DOGE Employee Stole Social Security Data

Former SSA Engineer Allegedly Exfiltrated Sensitive Data on Thumb Drive

322After Incident
CRITICAL-160
SOC1773184594
Former SSA Engineer Allegedly Exfiltrated Sensitive Data on Thumb Drive A whistleblower complaint, reported by The Washington Post, alleges that a former software engineer with the Department of Government Efficiency (DOGE) exfiltrated highly restricted Social Security Administration (SSA) databases onto a thumb drive. The SSA’s Office of Inspector General is investigating the incident, which raises concerns about insider threats, removable media controls, and the protection of sensitive federal data. The engineer, who worked with DOGE while embedded at the SSA, reportedly claimed to have taken two critical datasets the Numident and the Death Master File and intended to use the information at a new employer. The Numident is the SSA’s master record of Social Security numbers, containing names, birth details, citizenship status, and parental information, while the Death Master File includes records of deceased individuals, a dataset tightly controlled due to identity theft risks. If verified, the stolen material could involve data linked to over 500 million living and deceased individuals, amplifying risks of identity theft, credit fraud, tax refund fraud, and synthetic identity schemes. Insider threats remain a persistent challenge in cybersecurity, with privileged users often bypassing perimeter defenses. Removable media, such as thumb drives, further exacerbates the risk, as even robust endpoint detection can fail to prevent large-scale exfiltration without strict controls. Federal guidelines, including NIST SP 800-53, mandate least-privilege access, continuous monitoring, and restrictions on portable storage to mitigate such risks. The SSA’s investigation will likely examine access logs, removable media registries, and anomalous data transfers tied to the engineer. If violations are confirmed, potential legal consequences could include charges under the Privacy Act, Computer Fraud and Abuse Act, and theft of government records. Standard containment measures such as suspending credentials, forensic imaging of systems, and validating seized devices are expected. This incident follows broader controversies involving DOGE’s access to SSA systems, including previous allegations of improper data handling and unauthorized cloud uploads. A federal judge previously blocked DOGE from further SSA access, citing concerns over mission clarity and privileged access controls. Investigators are focusing on three key questions: what data was accessed, what was removed, and who else may have received it. Agencies handling SSA data are under pressure to demonstrate stronger controls over removable media, just-in-time privilege elevation, and real-time data loss prevention (DLP) for sensitive datasets. For affected individuals, credit freezes, tax transcript monitoring, and vigilance for benefits-related anomalies remain critical precautions.
INCIDENT DETAILS -
TYPE
Insider Threat, Data Exfiltration
MOTIVATION
Intended use at a new employer
IMPACT
Data Compromised: Numident and Death Master File datasetsSystems Affected: SSA databasesOperational Impact: Potential legal consequences, reputational damage to SSA and DOGEBrand Reputation Impact: High (SSA and DOGE)Legal Liabilities: Potential charges under Privacy Act, Computer Fraud and Abuse Act, and theft of government recordsIdentity Theft Risk: High (500 million living and deceased individuals at risk)
DATA BREACH
Social Security numbersNamesBirth detailsCitizenship statusParental informationDeath recordsNumber Of Records Exposed: 500 million (living and deceased individuals)Sensitivity Of Data: High (Personally Identifiable Information, sensitive federal data)Data Exfiltration: Yes (via thumb drive)Personally Identifiable Information: Yes
FEBRUARY 2026
571Before Incident
Breach
04 Feb 2026SSOI
Social Security Administration: The Social Security data breach is a national-security disaster that could hurt Americans for the rest of their lives: whistleblower

Social Security Data Breach Exposes Personal Information of All Americans

476After Incident
CRITICAL-95
SOC1770530510
Social Security Data Breach Exposes Personal Information of All Americans, Whistleblower Warns A former chief data officer at the Social Security Administration (SSA) has raised alarms over a potential national security disaster, alleging that the personal data of every American with a Social Security number past or present may have been exposed due to government mismanagement. Chuck Borges, who resigned from his position in August, filed a whistleblower complaint accusing the so-called Department of Government Efficiency (DOGE) of uploading a copy of the SSA’s database to an unsecured cloud environment. The exposed data reportedly includes names, Social Security numbers, and addresses, leaving millions vulnerable to fraud and identity theft. Borges described the breach as a "national-security disaster" with lifelong consequences for affected individuals. The incident has prompted calls for a congressional investigation into the handling of sensitive personal data by federal agencies. The allegations highlight critical gaps in oversight and security protocols within government systems, raising concerns about the protection of citizens' most sensitive information. No official response from the SSA or DOGE has been confirmed at this time.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Names, Social Security numbers, addressesSystems Affected: Social Security Administration (SSA) databaseBrand Reputation Impact: Critical gaps in oversight and security protocols highlightedIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Number Of Records Exposed: Millions (potentially all Americans with a Social Security number)Sensitivity Of Data: HighPersonally Identifiable Information: Names, Social Security numbers, addresses
JANUARY 2026
571Before Incident
DECEMBER 2025
567Before Incident
NOVEMBER 2025
563Before Incident
OCTOBER 2025
559Before Incident
SEPTEMBER 2025
555Before Incident
AUGUST 2025
642Before Incident
Breach
01 Aug 2025SSOI
Social Security Administration: The Social Security data breach is a national-security disaster that could hurt Americans for the rest of their lives: whistleblower

Social Security Data Breach Exposes Personal Information of All Americans

547After Incident
CRITICAL-95
SOC1770422068
Social Security Data Breach Exposes Personal Information of All Americans, Whistleblower Warns A former chief data officer at the Social Security Administration (SSA) has raised alarms over a potential national security disaster, alleging that the personal data of every American with a Social Security number past or present may have been compromised. Chuck Borges, who resigned in August, claims employees of the Department of Government Efficiency (DOGE) uploaded a copy of the SSA’s database to an unsecured cloud environment, leaving sensitive information including names, Social Security numbers, and addresses vulnerable to exploitation. Borges, now a whistleblower, has filed a complaint, asserting that the government’s mismanagement of this data poses a lifelong risk of fraud for millions. The breach, if confirmed, could have far-reaching consequences, exposing individuals to identity theft and financial harm. The incident has prompted calls for a congressional investigation into the handling of Americans’ private data. The SSA has not yet publicly addressed the allegations, but the claims underscore growing concerns over federal data security practices. The full scope of the breach and its potential impact remain under scrutiny.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Names, Social Security numbers, addressesSystems Affected: Social Security Administration (SSA) databaseBrand Reputation Impact: High (National security and public trust concerns)Legal Liabilities: Potential (Congressional investigation, regulatory violations)Identity Theft Risk: High (Lifelong risk of fraud for millions)
DATA BREACH
Personally Identifiable Information (PII)Social Security NumbersAddressesNumber Of Records Exposed: Potentially all Americans with a Social Security numberSensitivity Of Data: HighPersonally Identifiable Information: Yes
JULY 2025
642Before Incident
FEBRUARY 2025
757Before Incident
Breach
01 Feb 2025SSOI
Social Security Administration: Whistleblower claims ex-DOGE member says he took Social Security data to new job

Former DOGE Engineer Accused of Exfiltrating Sensitive Social Security Data

628After Incident
CRITICAL-129
SOC1773203381
Former DOGE Engineer Accused of Exfiltrating Sensitive Social Security Data The Social Security Administration’s (SSA) inspector general is investigating allegations that a former Defense Operational and Geospatial Engineering (DOGE) Service employee accessed and removed highly sensitive agency databases, potentially compromising the personal data of over 70 million Americans. According to sources familiar with the probe, the ex-engineer allegedly transferred the data onto a thumb drive before leaving the agency, raising concerns about an unprecedented breach of security protocols. The incident came to light after a whistleblower reported that the former employee claimed to have taken the information to share with a private employer. The SSA, headquartered in Woodlawn, Maryland, has not confirmed the authenticity of the data or the extent of the exposure. The investigation, which began in early 2026, remains ongoing as authorities assess the potential fallout of the alleged security lapse. The case underscores vulnerabilities in federal data protection measures, particularly at agencies handling vast repositories of personally identifiable information. No further details on the suspect or the private employer have been disclosed.
INCIDENT DETAILS -
TYPE
Data Exfiltration
MOTIVATION
Sharing with private employer
IMPACT
Data Compromised: Highly sensitive agency databasesBrand Reputation Impact: Potential reputational damage to SSAIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personally identifiable information (PII), Social Security dataNumber Of Records Exposed: 70 millionSensitivity Of Data: HighData Exfiltration: Yes (transferred onto a thumb drive)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SSOI ?
?
What was SSOI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SSOI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SSOI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SSOI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SSOI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SSOI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SSOI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SSOI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SSOI's A.I Rankiteo Cyber Score in September 2025 ?
?
What was SSOI's A.I Rankiteo Cyber Score in August 2025 ?
?
What was SSOI's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on SSOI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SSOI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SSOI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?