Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Subway

Subway Vendor Cyber Rating & Cyber Score

subway.com

Subway is one of the world's largest quick service restaurant brands, serving freshly made-to-order sandwiches, wraps, salads and bowls to millions of guests, across over 100 countries in more than 37,000 restaurants every day. Subway restaurants are owned and operated by Subway franchisees – a network that includes more than 20,000 dedicated entrepreneurs and small business owners – who are committed to delivering the best guest experience possible in their local communities. Ready to join the Subway team? There are plenty of incredible opportunities to be part of Subway, from our corporate headquarters and worldwide regional offices to our remote development teams. Our thousands of franchised restaurants across the globe offer


Subway A.I CyberSecurity Scoring

Subway
Company Information
Website:http://www.subway.com
Employees number:115,155
Number of followers:405,846
NAICS:7225
Industry Type:Restaurants
Homepage:subway.com
Subway Risk Score (AI oriented)
Between 750 and 799
logo
SubwayRestaurants
Updated:
02/04/2026
769/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Subway Global Score (TPRM)
xxxx
logo
SubwayRestaurants
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Subway
SubwayFair
Current Score
769Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
771Before Incident
MAY 2026
770Before Incident
APRIL 2026
770Before Incident
MARCH 2026
769Before Incident
FEBRUARY 2026
768Before Incident
JANUARY 2026
767Before Incident
DECEMBER 2025
767Before Incident
NOVEMBER 2025
766Before Incident
OCTOBER 2025
765Before Incident
SEPTEMBER 2025
765Before Incident
AUGUST 2025
764Before Incident
JULY 2025
763Before Incident
AUGUST 2021
812Before Incident
Ransomware
01 Aug 2021Subway
Subway and Prospect Medical Holdings: FBI issues warning to Gmail, Outlook email users. Here's how to spot Medusa ransomware

Medusa Ransomware Attacks Escalate, Targeting Hundreds of Organizations Nationwide

700After Incident
CRITICAL-112
SUBPRO1768802374
Medusa Ransomware Attacks Escalate, Targeting Hundreds of Organizations Nationwide Federal authorities, including the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), have issued a warning about the growing threat of Medusa ransomware, a sophisticated cyberattack campaign that has compromised over 400 victims across sectors including healthcare, education, legal, insurance, technology, and manufacturing. The attacks, active since 2021, follow a double-extortion model: threat actors encrypt victims’ systems, exfiltrate sensitive data, and publicly leak samples to pressure targets into paying ransoms. Victims receive a 48-hour ultimatum via a ransom note, often followed by direct contact from attackers via phone or email. Demands range from $100,000 to $15 million, with an additional $10,000 cryptocurrency fee to extend the countdown timer. In some cases, attackers have employed triple extortion, demanding a second payment after claiming the initial ransom was stolen by a rogue negotiator. The Medusa operation has evolved into an affiliate-based model, where independent cybercriminals deploy the ransomware while core developers retain control over negotiations. Attackers gain initial access by purchasing stolen credentials from dark web marketplaces or through phishing schemes, then exploit vulnerabilities in unpatched systems. Once inside, they encrypt data and post ransom demands on a dedicated leak site, providing direct links to cryptocurrency wallets. Connecticut has seen a sharp rise in ransomware incidents, with 861 reported in 2024 up from 644 in 2023 and 562 in 2022. Since August 2021, the state has logged 2,278 attacks, including high-profile breaches at Prospect Medical Holdings (2023) and Subway (2024). While federal investigators have not named specific suspects, a group called Spearwing has claimed responsibility for some attacks, while Inc Ransom was linked to the Subway breach. Authorities emphasize that no sector is immune, though larger organizations including municipalities, corporations, and critical infrastructure remain primary targets. The FBI and CISA recommend offline backups, multifactor authentication, and regular software updates as key defenses, though they note that even prepared entities can fall victim to evolving tactics. The Medusa campaign underscores the expanding reach of ransomware-as-a-service (RaaS), where sophisticated tools are leased to less-skilled criminals, amplifying the scale and frequency of attacks. With no signs of slowing, the threat continues to disrupt operations, extract millions in ransoms, and expose sensitive data across industries.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gainData extortion
IMPACT
Financial Loss: Ransom demands ranging from $100,000 to $15 millionData Compromised: Sensitive data exfiltrated and publicly leakedSystems Affected: Encrypted systems across multiple sectorsOperational Impact: Disrupted operations across affected organizationsIdentity Theft Risk: High (due to data exfiltration)Payment Information Risk: High (if payment data was compromised)
DATA BREACH
Type Of Data Compromised: Sensitive dataSensitivity Of Data: High (personally identifiable information, corporate data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Subway ?
?
What was Subway's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Subway's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Subway's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Subway's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Subway's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Subway's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Subway's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Subway's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Subway's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Subway's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Subway's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Subway's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Subway ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Subway's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Subway Cyber Scoring History | Rankiteo