Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Stellantis

Stellantis Vendor Cyber Rating & Cyber Score

stellantis.com

Our storied and iconic brands embody the passion of their visionary founders and today’s customers in their innovative products and services: they include Abarth, Alfa Romeo, Chrysler, Citroën, Dodge, DS Automobiles, Fiat, Jeep®, Lancia, Maserati, Opel, Peugeot, Ram, Vauxhall and mobility brands Free2move and Leasys. Powered by our diversity, we lead the way the world moves – aspiring to become the greatest sustainable mobility tech company, not the biggest, while creating added value for all stakeholders as well as the communities in which we operate.


Stellantis A.I CyberSecurity Scoring

Stellantis
Company Information
Website:https://www.stellantis.com
Employees number:113,145
Number of followers:2,447,601
NAICS:3361
Industry Type:Motor Vehicle Manufacturing
Homepage:stellantis.com
Stellantis Risk Score (AI oriented)
Between 550 and 599
logo
StellantisMotor Vehicle Manufacturing
Updated:
20/05/2026
586/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Stellantis Global Score (TPRM)
xxxx
logo
StellantisMotor Vehicle Manufacturing
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Stellantis
StellantisVery Poor
Current Score
586Ca (VERY POOR)
01000
5 incidents
-58.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
585Before Incident
MAY 2026
586Before Incident
APRIL 2026
587Before Incident
MARCH 2026
572Before Incident
FEBRUARY 2026
588Before Incident
JANUARY 2026
597Before Incident
DECEMBER 2025
609Before Incident
Cyber Attack
25 Dec 2025Stellantis
Stellantis: Everest Ransomware Group Claims Theft of Over 1TB of Chrysler Data

Everest Ransomware Group Claims Breach of Chrysler Systems

593After Incident
CRITICAL-16
STE1766793304
Everest Ransomware Group Claims Massive Data Breach of Chrysler Systems On December 25, the Everest ransomware group announced on its dark web leak site that it had breached Chrysler’s systems, exfiltrating over 1 TB (1088 GB) of data spanning from 2021 to 2025. The stolen material includes 105 GB of Salesforce-related records, containing sensitive personal and operational data tied to customers, dealers, and internal agents. Leaked screenshots reviewed by researchers reveal structured databases, internal spreadsheets, and CRM exports detailing customer names, contact information, vehicle details, recall case notes, and call logs. Additional files appear to include dealer network directories, HR records with employee names and statuses, and internal tooling documentation linked to Stellantis, Chrysler’s parent company. The group has threatened to release the full dataset—and potentially audio recordings of customer service interactions—once its countdown timer expires, pressuring Chrysler to respond. While the breach has not been publicly confirmed by Chrysler or independently verified, the scale and sensitivity of the exposed data raise concerns about customer privacy, operational security, and third-party platform governance. Ransomware groups often exploit holidays to maximize disruption, as incident response teams may be understaffed. As of now, Chrysler has not issued a statement on the claims. This incident follows a separate cyberattack on Stellantis in September 2025. Further developments are expected.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Extortion
IMPACT
Data Compromised: 1088 GB of data, including 105 GB of Salesforce-related informationSalesforceInternal databasesCRM systemsFile serversOperational Impact: Potential disruption to customer service and recall management processesBrand Reputation Impact: SignificantLegal Liabilities: PotentialIdentity Theft Risk: High
DATA BREACH
Customer interaction logsPersonal recordsOperational recordsSalesforce dataRecall case narrativesEmployee recordsSensitivity Of Data: HighData Exfiltration: YesDatabasesSpreadsheetsCRM exportsDirectory treesAudio recordingsNamesPhone numbersEmail addressesPhysical addressesVehicle detailsEmployment status
NOVEMBER 2025
619Before Incident
OCTOBER 2025
680Before Incident
Breach
07 Oct 2025Stellantis
Stellantis

Stellantis Data Breach via Third-Party Salesforce Platform

613After Incident
MEDIUM-67
STE4792047100725
Automotive giant Stellantis suffered a data breach after attackers infiltrated a third-party Salesforce platform used for North American customer services. The breach exposed customer contact details (names, emails, phone numbers), which were later used for phishing campaigns and extortion attempts. The attack was linked to the ShinyHunters extortion group, which exploited OAuth token vulnerabilities in Salesforce integrations (e.g., Salesloft’s Drift AI chat tool) to harvest metadata, credentials, and AWS keys. Stellantis confirmed no financial, health, or deeply sensitive data (e.g., SSNs, payment details) was compromised. The company activated incident response protocols, contained the breach, notified authorities, and warned customers about phishing risks. While the exact number of affected customers was undisclosed, ShinyHunters claimed to have stolen 18 million records from Stellantis’ Salesforce instance. The breach aligns with a broader wave of attacks targeting Salesforce clients, including Google, Allianz, and Dior.
INCIDENT DETAILS -
TYPE
Data BreachThird-Party VulnerabilityCloud CRM Compromise
MOTIVATION
Data Theft for ExtortionPhishing Campaign EnablementDark Web Data Monetization
IMPACT
Customer Contact Details (names, emails, phone numbers, possibly addresses)Third-Party Salesforce PlatformSalesloft Drift AI Chat IntegrationIncident Response ActivationCustomer NotificationsPhishing Warning CampaignsPotential Erosion of TrustAssociated with Broader Salesforce Breach WaveLow (limited to contact details)Phishing/Scam Risk ElevatedPayment Information Risk: None (confirmed not exposed)
DATA BREACH
Contact Information (names, emails, phone numbers)Possibly addressesNumber Of Records Exposed: 18 million (claimed by ShinyHunters)Sensitivity Of Data: Low (no financial/health data)Data Exfiltration: YesNamesEmail AddressesPhone Numbers
OCTOBER 2025
671Before Incident
Cyber Attack
06 Oct 2025Stellantis
Renault

Renault UK Customer Data Breach via Third-Party Supplier

587After Incident
CRITICAL-84
REN2632226100625
Renault notified an unspecified number of customers that their personal data was compromised due to a cyber-attack on a third-party supplier. The breach exposed customers' first and last names, gender, phone numbers, email and postal addresses, as well as vehicle identification and registration numbers. While no financial data or passwords were stolen, the exposed information increases the risk of targeted phishing scams. The incident was isolated to the supplier’s systems, with Renault confirming its own infrastructure remained uncompromised. The third-party provider contained and removed the threat, and Renault is collaborating with them to ensure appropriate measures are taken. Authorities were notified, and customers were advised to remain vigilant against unsolicited requests for personal information. The breach follows a trend of supply chain attacks in the transport sector, highlighting vulnerabilities in vendor security.
INCIDENT DETAILS -
TYPE
Data Breach (Supply Chain Attack)
MOTIVATION
Likely financial (data theft for phishing/scams)
IMPACT
First and last nameGenderPhone numberEmail addressPostal addressVehicle identification numberVehicle registration numberThird-party supplier's systemsOperational Impact: Increased risk of phishing attacks targeting customers; reputational harmCustomer Complaints: Reported on social media (e.g., Dacia customers)Brand Reputation Impact: Negative (public disclosure, supply chain vulnerability highlighted)Identity Theft Risk: High (personal data exposed)Payment Information Risk: None (explicitly stated as not compromised)
DATA BREACH
Personally Identifiable Information (PII)Vehicle InformationNumber Of Records Exposed: UnspecifiedSensitivity Of Data: Moderate to High (enough for targeted phishing)Data Exfiltration: YesPersonally Identifiable Information: Yes (names, gender, contact details)
SEPTEMBER 2025
746Before Incident
Breach
24 Sep 2025Stellantis
Stellantis

Stellantis Data Breach Affecting North American Customers

679After Incident
MEDIUM-67
STE1093810092425
Stellantis, the automaker behind brands like Jeep, Citroën, and FIAT, suffered a data breach via a compromised third-party vendor (Salesforce/Salesloft integration). Attackers, allegedly the ShinyHunters group, accessed 18+ million customer records, including names, addresses, phone numbers, and email addresses—though no financial or highly sensitive data (e.g., SSNs, payment details) was exposed. The breach exploited stolen OAuth tokens from Salesloft’s Drift AI chat tool, allowing unauthorized Salesforce data exfiltration. Stellantis activated incident response protocols, notified authorities, and warned customers of potential phishing risks. While operational disruption was minimal, the incident underscores third-party vulnerabilities in automotive supply chains and the escalating tactics of persistent threat actors targeting cloud ecosystems. The FBI issued an alert urging Salesforce users to revoke suspicious tokens, highlighting the breach’s broader implications for industries reliant on SaaS platforms.
INCIDENT DETAILS -
TYPE
Data BreachThird-Party CompromiseUnauthorized Access
MOTIVATION
Data TheftExtortionPhishing Enablement
IMPACT
Customer NamesAddressesPhone NumbersEmail AddressesSalesforce (via Third-Party Integration)Customer Service OperationsPotential Phishing Risks for CustomersReputation DamageModerate (Due to Customer Data Exposure and Phishing Risks)Low (No Financial/Sensitive Data Exposed)None
DATA BREACH
Customer Contact InformationNumber Of Records Exposed: 18,000,000+ (Claimed by ShinyHunters)Low (No Financial or Highly Sensitive Data)NamesAddressesPhone NumbersEmail Addresses
AUGUST 2025
745Before Incident
JULY 2025
744Before Incident
MAY 2025
799Before Incident
Breach
01 May 2025Stellantis
Stellantis

Stellantis Data Breach Affecting Jeep, Chrysler, and Dodge Customers

740After Incident
CRITICAL-59
STE5202252112025
Stellantis, the parent company of Jeep, Chrysler, and Dodge, experienced a data breach in May, which was disclosed later. The breach exposed the names and contact details of approximately 18 million customers, though sensitive data such as Social Security numbers and payment information remained uncompromised. Experts warn that scammers could exploit the stolen data—such as vehicle ownership records (e.g., Jeep Grand Cherokee)—to craft convincing phishing attacks. Victims may receive fraudulent emails, texts, or calls impersonating Stellantis or its brands, tricking them into clicking malicious links, sharing further personal information, or making fake payments. While no direct financial theft occurred, the breach heightens risks of identity fraud, targeted scams, and reputational harm due to the scale of exposed customer data. Security professionals recommend freezing credit reports to mitigate potential misuse of the leaked information.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Likely financial gain (data exploitation for scams/phishing)
IMPACT
Customer namesContact information (e.g., email, phone)Vehicle ownership details (e.g., Jeep Grand Cherokee)Brand Reputation Impact: Potential erosion of trust due to delayed disclosure and risk of scams targeting customersIdentity Theft Risk: Moderate (phishing/social engineering risk due to personalized data)Payment Information Risk: None (explicitly stated as not exposed)
DATA BREACH
Personal identifiable information (PII)Vehicle ownership recordsNumber Of Records Exposed: 18,000,000Sensitivity Of Data: Moderate (no SSNs or payment info, but enough for targeted phishing)Data Exfiltration: YesNamesContact detailsVehicle model ownership

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Stellantis ?
?
What was Stellantis's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Stellantis's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Stellantis's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Stellantis ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Stellantis's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?