Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Telefónica

Telefónica Vendor Cyber Rating & Cyber Score

telefonica.com

Telefónica is today one of the largest telecommunications companies in the world in terms of market capitalisation and number of customers. We have the best infrastructure, as well as an innovative range of digital and data services; therefore, we are favorably positioned to meet the needs of our customers and capture growth in new businesses. We are sensitive to the new challenges demanded by society today and, therefore, we provide the means to facilitate communication between people, providing them with the most secure and cutting-edge technology. Our vision is focused on technology making people's lives easier and our aim is to promote progress in that direction, so that technology can make a positive impact on the world both


Telefónica A.I CyberSecurity Scoring

Telefónica
Company Information
Website:http://www.telefonica.com
Employees number:122,141
Number of followers:1,305,589
NAICS:517
Industry Type:Telecommunications
Homepage:telefonica.com
Telefónica Risk Score (AI oriented)
Between 550 and 599
logo
TelefónicaTelecommunications
Updated:
11/09/2026
577/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
Telefónica Global Score (TPRM)
xxxx
logo
TelefónicaTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

TelefónicaVery Poor
Current Score
577Ca (VERY POOR)
01000
5 incidents
-69 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
574Before Incident
SEPTEMBER 2026
577Before Incident
AUGUST 2026
573Before Incident
JULY 2026
567Before Incident
JUNE 2026
564Before Incident
MAY 2026
559Before Incident
APRIL 2026
557Before Incident
MARCH 2026
549Before Incident
FEBRUARY 2026
547Before Incident
JANUARY 2026
538Before Incident
DECEMBER 2025
605Before Incident
Breach
22 Dec 2025 • Telefónica
Telefónica Móviles: Telefónica Móviles fined €300,000 for GDPR data breach in Spain

Telefónica Móviles (Movistar) GDPR Violation Fine

536After Incident
MEDIUM-69
TEL1766404766
Movistar Fined €300,000 for GDPR Violation in Spain On December 22, 2025, Spain’s Data Protection Agency (AEPD) imposed a €300,000 fine on Telefónica Móviles, operating as Movistar, for violating the EU’s General Data Protection Regulation (GDPR). The penalty stems from the unlawful processing of personal data during a mobile phone line transfer, where customer information was mishandled. The AEPD ruled that Movistar failed to comply with GDPR requirements, though the company has one month to appeal the decision. The case highlights ongoing regulatory scrutiny over telecom providers’ data handling practices under EU privacy laws. Full details of the ruling are available in the attached decision (in Spanish).
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Financial Loss: €300,000Data Compromised: Personal data processed unlawfully during mobile phone line changesBrand Reputation Impact: Potential reputational damage due to GDPR violationLegal Liabilities: Regulatory fine imposed
DATA BREACH
Type Of Data Compromised: Personal dataSensitivity Of Data: High (GDPR-protected data)Personally Identifiable Information: Yes
NOVEMBER 2025
602Before Incident
SEPTEMBER 2025
616Before Incident
Cyber Attack
01 Sep 2025 • Telefónica
Telefónica, JPMorgan Chase, Google and DJI: ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More

Google Play Strengthens Security in 2025, Multi-Stage Phishing Campaign, Critical Flaws in BMC FootPrints, SnappyClient C2 Framework, LiveChat Phishing, GitHub Secrets Exposure, The Gentlemen RaaS, WhatsApp Alphanumeric Passwords, Malicious Packagist Themes, DJI API Flaw, CVE Exploitation Trends, Teams Phishing, EU CSAM Rules, Emerging Threats

589After Incident
CRITICAL-27
DJIJPMTELGOO1789086449
Google Play Strengthens Security in 2025, Blocking Millions of Malicious Apps and Accounts In 2025, Google removed 1.75 million policy-violating Android apps from the Play Store a decline from 2.36 million in 2024 while banning 80,000 developer accounts, down from 158,000 the previous year. The company also blocked 255,000 apps from accessing excessive user data and conducted 10,000 safety checks on published apps, leveraging generative AI to enhance detection. Google’s Play Protect, now scanning 350 billion apps daily, identified 27 million malicious apps sideloaded outside the Play Store. Its expanded fraud protection covered 2.8 billion devices across 185 markets, blocking 266 million installation attempts from 872,000 high-risk apps. Additionally, Google introduced Scam Detection for phone calls on Pixel devices in 12 countries, including the U.S., U.K., and India, to combat fraudulent activity. --- Multi-Stage Phishing Campaign Bypasses Security Filters with Legitimate Infrastructure A sophisticated phishing-as-a-service (PhaaS) toolkit, dubbed Kratos, was used in an unsuccessful attack impersonating JPMorgan Chase. The campaign employed a multi-chain redirect tactic, leveraging Cisco’s infrastructure and trusted services like Nylas to evade security filters. Attackers implemented a Cloudflare-based "human validation" step to ensure only real users reached the credential-harvesting page. --- Critical Flaws in BMC FootPrints ITSM Enable Pre-Auth Remote Code Execution Four vulnerabilities (CVE-2025-71257–71260) in BMC FootPrints, a widely used IT service management (ITSM) solution, were disclosed in September 2025. The flaws could be chained to achieve pre-authentication remote code execution (RCE). The attack begins with an authentication bypass (CVE-2025-71257), extracting a guest session token to exploit an unsanitized Java deserialization sink (CVE-2025-71260). Attackers could also abuse SSRF flaws (CVE-2025-71258, CVE-2025-71259) to leak internal data. --- SnappyClient: A Stealthy C2 Framework Targeting Cryptocurrency Theft A new C++-based command-and-control (C2) framework, SnappyClient, was discovered in December 2025. Distributed via a fake Telefónica website, it employs evasion techniques like AMSI bypass, Heaven’s Gate, direct system calls, and transacted hollowing. The malware steals data from browsers, extensions, and applications, with suspected ties to HijackLoader based on code similarities. --- LiveChat Abused in Phishing Campaign to Harvest Sensitive Data A phishing campaign leveraged LiveChat’s messaging platform to trick users into entering credentials, credit card details, and MFA codes. Attackers sent refund-themed emails, redirecting victims to a LiveChat-hosted link where they engaged in real-time chat impersonating trusted brands. --- GitHub Sees Surge in Hard-Coded Secrets, Including AI Service Credentials In 2025, 28.65 million new secrets were exposed in public GitHub commits a 34% increase from 2024 and a 152% rise since 2021. AI service secrets surged by 81% year-over-year, reaching 1.28 million. Additionally, 24,088 unique secrets were found in MCP-related configuration files, including 2,117 valid credentials. --- The Gentlemen: A New RaaS Operation with Fabricated Claims A nascent Ransomware-as-a-Service (RaaS) group, The Gentlemen, emerged in mid-2025 following a payment dispute with Qilin ransomware operators. The group, consisting of ~20 members, has targeted 94 organizations but has yet to provide credible proof of successful attacks. Researchers noted fabricated data samples on their leak site. --- WhatsApp Introduces Alphanumeric Passwords to Counter SIM Swap Attacks WhatsApp began testing alphanumeric passwords (6–20 characters, with at least one letter and number) to strengthen account security. The measure aims to prevent unauthorized access even if attackers perform a SIM swap to intercept 2FA codes. --- Malicious Packagist Themes Inject Ads and Redirect Users to Gambling Sites Six trojanized Packagist packages, posing as OphimCMS themes, were found distributing malicious JavaScript disguised as jQuery libraries. The malware exfiltrates URLs, injects ads, and redirects mobile users to gambling and adult content sites operated by Funnull. --- DJI Exposes Device Data via Unauthenticated API Access A security flaw in DJI’s backend allowed attackers to access device data including 7,000 Romo smart vacuums and 3,000 portable power stations by simply providing a serial number. The issue was patched after disclosure. --- Only 1% of 2025 CVEs Were Exploited in the Wild A VulnCheck report found that just 1% of disclosed CVEs in 2025 were actively exploited, with network edge devices accounting for a third of all exploited vulnerabilities. Exploit activity by state-sponsored groups decreased by 13% compared to 2024. --- Teams Phishing Campaigns Impersonate IT Staff for Remote Access Threat actors increasingly abuse Microsoft Teams to impersonate internal IT departments, tricking users into launching Quick Assist for remote access. The goal is to deploy malware, exfiltrate data, or move laterally within networks. --- EU Extends Voluntary CSAM Detection Rules Until 2027 The European Union extended a temporary exemption allowing online platforms to voluntarily detect child sexual abuse material (CSAM) until August 2027, pending a long-term legal framework. --- Emerging Threats: AOT Malware, CursorJack, and HijackLoader’s Evolving Tactics - AOT-compiled malware evades analysis by stripping .NET metadata, forcing reliance on native-level tooling. - CursorJack abuses Model Context Protocol (MCP) deep links for arbitrary command execution. - HijackLoader now delivers an updated ACRStealer variant, spreading via pirated games from PiviGames.
INCIDENT DETAILS -
TYPE
Malware DistributionPhishingVulnerability ExploitationData BreachRansomwareFraudCredential Harvesting
MOTIVATION
Financial GainData TheftEspionageFraudRansomware Extortion
IMPACT
User CredentialsCredit Card DetailsMFA CodesBrowser DataAI Service SecretsDevice DataAndroid AppsBMC FootPrints ITSMGitHub RepositoriesLiveChat PlatformDJI BackendMicrosoft TeamsMalicious App DistributionUnauthorized Remote AccessData ExfiltrationService DisruptionGoogle PlayJPMorgan ChaseBMCLiveChatDJIMicrosoft Teams
DATA BREACH
CredentialsPayment InformationBrowser DataAI Service SecretsDevice Data28.65 million GitHub secrets24,088 MCP-related secretsHighConfiguration FilesJavaScript
JUNE 2025
670Before Incident
Breach
03 Jun 2025 • Telefónica
Telefónica and Movistar: A cyberattack affects millions of Telefónica customers, although the company claims none are in Spain.

Cyberattack on BarcelonaTelefónica by Dedale

603After Incident
CRITICAL-67
MOVTEL1767881948
Cybercriminal Dedale Targets BarcelonaTelefónica, Leaks 1M Peruvian Customer Records BarcelonaTelefónica is probing a cyberattack by the threat actor Dedale, who claims to have accessed 22 million customer records—though the breach appears limited in scope. As proof, the attacker leaked a database containing one million records, primarily affecting users in Peru. The compromised data includes multiple entries per customer (e.g., names, ID numbers, addresses), meaning the incident does not equate to 22 million unique individuals being exposed. Telefónica confirmed that Spanish customers remain unaffected, as the breach is tied to its former Peruvian subsidiary. The attack surfaced after HackManac disclosed details on X (formerly Twitter). Notably, Dedale is demanding a $1,500 ransom—a fraction of typical extortion demands—raising questions about the attacker’s motives. The breach coincides with Telefónica’s recent sale of its bankrupt Peruvian operations to Integra Tec International for €900,000, finalized last month. Investigations are ongoing.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: 22 million customer records accessed, 1 million records leakedIdentity Theft Risk: High
DATA BREACH
Full nameID numberAddressNumber Of Records Exposed: 1 million records leaked (22 million accessed)Sensitivity Of Data: High (Personally Identifiable Information)Data Exfiltration: YesPersonally Identifiable Information: Yes
MAY 2025
787Before Incident
Ransomware
01 May 2025 • Telefónica
Telefónica

Telefónica Data Breach Incident

667After Incident
CRITICAL-120
TEL732070725
A cybercriminal known as Rey, part of the Hellcat ransomware operation, claims to have stolen 106GB of sensitive data from Telefónica in May 2025. The stolen data includes internal communications, purchase orders, logs, customer records, and various employee data. Rey has released a 2.6GB sample and is threatening to release the full batch unless a payment is made. Telefónica has downplayed the incident, stating that the data is old and there was no new breach.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Ransom
IMPACT
Financial Loss: nullData Compromised: 106GB of sensitive files, including internal communications, purchase orders, logs, customer records, and employee dataSystems Affected: Internal Jira development and ticketing serverDowntime: nullOperational Impact: nullConversion Rate Impact: nullRevenue Loss: nullCustomer Complaints: nullBrand Reputation Impact: nullLegal Liabilities: nullIdentity Theft Risk: nullPayment Information Risk: null
DATA BREACH
Type Of Data Compromised: Internal communications, purchase orders, logs, customer records, and employee dataNumber Of Records Exposed: 380,000 filesSensitivity Of Data: SensitiveData Exfiltration: 106GBData Encryption: nullFile Types Exposed: Invoices, email addresses, internal communications, purchase orders, logs, customer records, and employee dataPersonally Identifiable Information: Email addresses, invoices for business partners or customers
MAY 2017
800Before Incident
Ransomware
12 May 2017 • Telefónica
Telefónica: WannaCry, the ransomware attack that changed the history of cybersecurity

WannaCry Ransomware Attack

712After Incident
CRITICAL-88
TEL1778581673
WannaCry: The Ransomware Attack That Reshaped Global Cybersecurity On May 12, 2017, the WannaCry ransomware attack exploited a critical vulnerability in Microsoft Windows’ SMBv1 protocol (CVE-2017-0144, aka EternalBlue), infecting over 200,000 systems across 150 countries within hours. The malware, derived from an NSA-developed exploit leaked by the hacker group Shadow Brokers, spread autonomously as a worm, bypassing traditional phishing methods. Key targets included healthcare systems in the UK, telecommunications networks in Spain, and organizations in the U.S., China, Russia, and beyond. Once inside a system, WannaCry encrypted files and demanded a $300 Bitcoin ransom, escalating over time to pressure victims. Its lateral movement scanning and infecting unpatched systems without user interaction made it uniquely destructive. The attack was temporarily halted when security researcher Marcus Hutchins (MalwareTech) discovered and activated a "kill switch" by registering an unregistered domain hardcoded in the malware. This accidental mitigation slowed the spread but did not eliminate the threat. Investigations later linked WannaCry to North Korea’s Lazarus Group, underscoring how state-developed cyber tools can be repurposed for criminal use. The incident exposed systemic failures, including delayed patch management Microsoft had released a fix (MS17-010) in March 2017 and poor network segmentation, which allowed the worm to propagate unchecked. WannaCry’s legacy persists in modern cybersecurity practices, emphasizing the need for timely patching, network resilience, and international collaboration. Though not the most sophisticated ransomware, its global impact demonstrated the far-reaching consequences of unaddressed vulnerabilities and the risks of stockpiled cyber weapons.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain, potential state-sponsored disruption
IMPACT
Data Compromised: Files encrypted on infected systemsSystems Affected: Over 200,000 systemsOperational Impact: Significant disruption to healthcare, telecommunications, and other critical servicesBrand Reputation Impact: Global reputational damage to affected organizations
DATA BREACH
Type Of Data Compromised: Encrypted files (no confirmed exfiltration)Sensitivity Of Data: Varies (potentially sensitive in healthcare and government systems)Data Exfiltration: No confirmed evidenceData Encryption: Yes (AES-128 encryption)Personally Identifiable Information: Potential in healthcare systems

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Telefónica ?
?
What was Telefónica's A.I Rankiteo Cyber Score in September 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Telefónica's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on Telefónica's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Telefónica ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Telefónica's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?