SG A.I CyberSecurity Scoring
SG
Company Information
Website:https://www.suncitygroup.com.mo/
Employees number:452
Number of followers:17,615
NAICS:71
Industry Type:Entertainment Providers
Homepage:suncitygroup.com.mo
SG Risk Score (AI oriented)
Between 700 and 749
SGEntertainment Providers
Updated:
12/03/2026
12/03/2026
748/1000
Moderate
Ba
SG Global Score (TPRM)
xxxx
SGEntertainment Providers
Score locked

SGModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
749
JUNE 2026
749
MAY 2026
749
APRIL 2026
749
MARCH 2026
748
FEBRUARY 2026
748
JANUARY 2026
748
DECEMBER 2025
748
NOVEMBER 2025
747
OCTOBER 2025
747
SEPTEMBER 2025
747
AUGUST 2025
746
FEBRUARY 2024
765
Cyber Attack
01 Feb 2024 • SG
Gate.io and Suncity Group: Polyfill Supply Chain Attack Impacting 100k Sites Linked to North Korea
Polyfill Supply Chain Attack Linked to North Korean Threat Actors
738
CRITICAL-27
SUNGAT1773312606
Polyfill Supply Chain Attack Linked to North Korean Threat Actors
In February 2024, the widely used Polyfill.io service a JavaScript library for browser compatibility was acquired by Chinese CDN company Funnull. Shortly after, the domain cdn.polyfill.io began injecting malicious code into scripts, affecting over 100,000 websites. The malware targeted mobile users, redirecting them to betting and adult sites while employing evasion techniques. Security firms Sansec and C/side confirmed the attack in June 2024, prompting Cloudflare and Google to mitigate risks.
Initially attributed to Chinese actors, new evidence from cybersecurity firm Hudson Rock reveals North Korean involvement. The firm analyzed data from infostealer malware on a device used by a North Korean hacker, uncovering credentials for Funnull’s DNS management portal and the Polyfill Cloudflare tenant. The stolen data also included conversations about malicious domain configurations, establishing a direct link between the North Korean operative and the attack.
Hudson Rock determined that the Polyfill campaign aimed to funnel users to gambling sites operated by China’s Suncity Group, which allegedly laundered cryptocurrency for North Korea. The operation aligns with North Korea’s broader cybercrime strategy, which reportedly stole over $2 billion in cryptocurrency in 2025. Additionally, the same hacker’s device contained evidence of a separate scheme where a North Korean operative infiltrated cryptocurrency exchange Gate.io to gather intelligence on anti-money laundering procedures.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SG ??
What was SG's A.I Rankiteo Cyber Score in June 2026 ??
What was SG's A.I Rankiteo Cyber Score in May 2026 ??
What was SG's A.I Rankiteo Cyber Score in April 2026 ??
What was SG's A.I Rankiteo Cyber Score in March 2026 ??
What was SG's A.I Rankiteo Cyber Score in February 2026 ??
What was SG's A.I Rankiteo Cyber Score in January 2026 ??
What was SG's A.I Rankiteo Cyber Score in December 2025 ??
What was SG's A.I Rankiteo Cyber Score in November 2025 ??
What was SG's A.I Rankiteo Cyber Score in October 2025 ??
What was SG's A.I Rankiteo Cyber Score in September 2025 ??
What was SG's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on SG's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SG ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SG's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?