Subway A.I CyberSecurity Scoring
Subway
Company Information
Website:http://www.subway.com
Employees number:115,155
Number of followers:405,846
NAICS:7225
Industry Type:Restaurants
Homepage:subway.com
Subway Risk Score (AI oriented)
Between 750 and 799
SubwayRestaurants
Updated:
02/04/2026
02/04/2026
769/1000
Fair
Baa
Subway Global Score (TPRM)
xxxx
SubwayRestaurants
Score locked

SubwayFair
Current Score
769Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
771
MAY 2026
770
APRIL 2026
770
MARCH 2026
769
FEBRUARY 2026
768
JANUARY 2026
767
DECEMBER 2025
767
NOVEMBER 2025
766
OCTOBER 2025
765
SEPTEMBER 2025
765
AUGUST 2025
764
JULY 2025
763
AUGUST 2021
812
Ransomware
01 Aug 2021 • Subway
Subway and Prospect Medical Holdings: FBI issues warning to Gmail, Outlook email users. Here's how to spot Medusa ransomware
Medusa Ransomware Attacks Escalate, Targeting Hundreds of Organizations Nationwide
700
CRITICAL-112
SUBPRO1768802374
Medusa Ransomware Attacks Escalate, Targeting Hundreds of Organizations Nationwide
Federal authorities, including the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC), have issued a warning about the growing threat of Medusa ransomware, a sophisticated cyberattack campaign that has compromised over 400 victims across sectors including healthcare, education, legal, insurance, technology, and manufacturing.
The attacks, active since 2021, follow a double-extortion model: threat actors encrypt victims’ systems, exfiltrate sensitive data, and publicly leak samples to pressure targets into paying ransoms. Victims receive a 48-hour ultimatum via a ransom note, often followed by direct contact from attackers via phone or email. Demands range from $100,000 to $15 million, with an additional $10,000 cryptocurrency fee to extend the countdown timer. In some cases, attackers have employed triple extortion, demanding a second payment after claiming the initial ransom was stolen by a rogue negotiator.
The Medusa operation has evolved into an affiliate-based model, where independent cybercriminals deploy the ransomware while core developers retain control over negotiations. Attackers gain initial access by purchasing stolen credentials from dark web marketplaces or through phishing schemes, then exploit vulnerabilities in unpatched systems. Once inside, they encrypt data and post ransom demands on a dedicated leak site, providing direct links to cryptocurrency wallets.
Connecticut has seen a sharp rise in ransomware incidents, with 861 reported in 2024 up from 644 in 2023 and 562 in 2022. Since August 2021, the state has logged 2,278 attacks, including high-profile breaches at Prospect Medical Holdings (2023) and Subway (2024). While federal investigators have not named specific suspects, a group called Spearwing has claimed responsibility for some attacks, while Inc Ransom was linked to the Subway breach.
Authorities emphasize that no sector is immune, though larger organizations including municipalities, corporations, and critical infrastructure remain primary targets. The FBI and CISA recommend offline backups, multifactor authentication, and regular software updates as key defenses, though they note that even prepared entities can fall victim to evolving tactics.
The Medusa campaign underscores the expanding reach of ransomware-as-a-service (RaaS), where sophisticated tools are leased to less-skilled criminals, amplifying the scale and frequency of attacks. With no signs of slowing, the threat continues to disrupt operations, extract millions in ransoms, and expose sensitive data across industries.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Subway ??
What was Subway's A.I Rankiteo Cyber Score in May 2026 ??
What was Subway's A.I Rankiteo Cyber Score in April 2026 ??
What was Subway's A.I Rankiteo Cyber Score in March 2026 ??
What was Subway's A.I Rankiteo Cyber Score in February 2026 ??
What was Subway's A.I Rankiteo Cyber Score in January 2026 ??
What was Subway's A.I Rankiteo Cyber Score in December 2025 ??
What was Subway's A.I Rankiteo Cyber Score in November 2025 ??
What was Subway's A.I Rankiteo Cyber Score in October 2025 ??
What was Subway's A.I Rankiteo Cyber Score in September 2025 ??
What was Subway's A.I Rankiteo Cyber Score in August 2025 ??
What was Subway's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Subway's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Subway ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Subway's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?