Telefónica A.I CyberSecurity Scoring
Telefónica
Company Information
Website:http://www.telefonica.com
Employees number:119,880
Number of followers:1,279,598
NAICS:517
Industry Type:Telecommunications
Homepage:telefonica.com
Telefónica Risk Score (AI oriented)
Between 550 and 599
TelefónicaTelecommunications
Updated:
12/05/2026
12/05/2026
582/1000
Very Poor
Ca
Telefónica Global Score (TPRM)
xxxx
TelefónicaTelecommunications
Score locked

TelefónicaVery Poor
Current Score
582Ca (VERY POOR)
01000
4 incidents
-68 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
587
MAY 2026
582
APRIL 2026
581
MARCH 2026
574
FEBRUARY 2026
572
JANUARY 2026
565
DECEMBER 2025
630
Breach
22 Dec 2025 • Telefónica
Telefónica Móviles: Telefónica Móviles fined €300,000 for GDPR data breach in Spain
Telefónica Móviles (Movistar) GDPR Violation Fine
562
MEDIUM-68
TEL1766404766
Movistar Fined €300,000 for GDPR Violation in Spain
On December 22, 2025, Spain’s Data Protection Agency (AEPD) imposed a €300,000 fine on Telefónica Móviles, operating as Movistar, for violating the EU’s General Data Protection Regulation (GDPR). The penalty stems from the unlawful processing of personal data during a mobile phone line transfer, where customer information was mishandled.
The AEPD ruled that Movistar failed to comply with GDPR requirements, though the company has one month to appeal the decision. The case highlights ongoing regulatory scrutiny over telecom providers’ data handling practices under EU privacy laws. Full details of the ruling are available in the attached decision (in Spanish).
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
628
OCTOBER 2025
624
SEPTEMBER 2025
620
AUGUST 2025
616
JULY 2025
611
JUNE 2025
670
Breach
03 Jun 2025 • Telefónica
Telefónica and Movistar: A cyberattack affects millions of Telefónica customers, although the company claims none are in Spain.
Cyberattack on BarcelonaTelefónica by Dedale
603
CRITICAL-67
MOVTEL1767881948
Cybercriminal Dedale Targets BarcelonaTelefónica, Leaks 1M Peruvian Customer Records
BarcelonaTelefónica is probing a cyberattack by the threat actor Dedale, who claims to have accessed 22 million customer records—though the breach appears limited in scope. As proof, the attacker leaked a database containing one million records, primarily affecting users in Peru.
The compromised data includes multiple entries per customer (e.g., names, ID numbers, addresses), meaning the incident does not equate to 22 million unique individuals being exposed. Telefónica confirmed that Spanish customers remain unaffected, as the breach is tied to its former Peruvian subsidiary.
The attack surfaced after HackManac disclosed details on X (formerly Twitter). Notably, Dedale is demanding a $1,500 ransom—a fraction of typical extortion demands—raising questions about the attacker’s motives. The breach coincides with Telefónica’s recent sale of its bankrupt Peruvian operations to Integra Tec International for €900,000, finalized last month. Investigations are ongoing.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2025
787
Ransomware
01 May 2025 • Telefónica
Telefónica
Telefónica Data Breach Incident
667
CRITICAL-120
TEL732070725
A cybercriminal known as Rey, part of the Hellcat ransomware operation, claims to have stolen 106GB of sensitive data from Telefónica in May 2025. The stolen data includes internal communications, purchase orders, logs, customer records, and various employee data. Rey has released a 2.6GB sample and is threatening to release the full batch unless a payment is made. Telefónica has downplayed the incident, stating that the data is old and there was no new breach.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2017
800
Ransomware
12 May 2017 • Telefónica
Telefónica: WannaCry, the ransomware attack that changed the history of cybersecurity
WannaCry Ransomware Attack
712
CRITICAL-88
TEL1778581673
WannaCry: The Ransomware Attack That Reshaped Global Cybersecurity
On May 12, 2017, the WannaCry ransomware attack exploited a critical vulnerability in Microsoft Windows’ SMBv1 protocol (CVE-2017-0144, aka EternalBlue), infecting over 200,000 systems across 150 countries within hours. The malware, derived from an NSA-developed exploit leaked by the hacker group Shadow Brokers, spread autonomously as a worm, bypassing traditional phishing methods.
Key targets included healthcare systems in the UK, telecommunications networks in Spain, and organizations in the U.S., China, Russia, and beyond. Once inside a system, WannaCry encrypted files and demanded a $300 Bitcoin ransom, escalating over time to pressure victims. Its lateral movement scanning and infecting unpatched systems without user interaction made it uniquely destructive.
The attack was temporarily halted when security researcher Marcus Hutchins (MalwareTech) discovered and activated a "kill switch" by registering an unregistered domain hardcoded in the malware. This accidental mitigation slowed the spread but did not eliminate the threat.
Investigations later linked WannaCry to North Korea’s Lazarus Group, underscoring how state-developed cyber tools can be repurposed for criminal use. The incident exposed systemic failures, including delayed patch management Microsoft had released a fix (MS17-010) in March 2017 and poor network segmentation, which allowed the worm to propagate unchecked.
WannaCry’s legacy persists in modern cybersecurity practices, emphasizing the need for timely patching, network resilience, and international collaboration. Though not the most sophisticated ransomware, its global impact demonstrated the far-reaching consequences of unaddressed vulnerabilities and the risks of stockpiled cyber weapons.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Telefónica ??
What was Telefónica's A.I Rankiteo Cyber Score in May 2026 ??
What was Telefónica's A.I Rankiteo Cyber Score in April 2026 ??
What was Telefónica's A.I Rankiteo Cyber Score in March 2026 ??
What was Telefónica's A.I Rankiteo Cyber Score in February 2026 ??
What was Telefónica's A.I Rankiteo Cyber Score in January 2026 ??
What was Telefónica's A.I Rankiteo Cyber Score in December 2025 ??
What was Telefónica's A.I Rankiteo Cyber Score in November 2025 ??
What was Telefónica's A.I Rankiteo Cyber Score in October 2025 ??
What was Telefónica's A.I Rankiteo Cyber Score in September 2025 ??
What was Telefónica's A.I Rankiteo Cyber Score in August 2025 ??
What was Telefónica's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Telefónica's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Telefónica ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Telefónica's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?