ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion. The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies. Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.

Thales A.I CyberSecurity Scoring

Thales

Company Details

Linkedin ID:

thales

Employees number:

67,535

Number of followers:

1,780,450

NAICS:

336414

Industry Type:

Defense and Space Manufacturing

Homepage:

thalesgroup.com

IP Addresses:

207

Company ID:

THA_7781503

Scan Status:

Completed

AI scoreThales Risk Score (AI oriented)

Between 700 and 749

https://images.rankiteo.com/companyimages/thales.jpeg
Thales Defense and Space Manufacturing
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreThales Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/thales.jpeg
Thales Defense and Space Manufacturing
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

Thales Company CyberSecurity News & History

Past Incidents
6
Attack Types
4
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
ImpervaData Leak60308/2019
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: Imperva disclosed a security incident that impacts customers of its cloud web application firewall (WAF), formerly known as Incapsula. The company learned from a third party of a data exposure that impacts a subset of customers of their Cloud WAF product. Exposed data included customer email addresses, along with hashed and salted passwords, for a subset of customers. For a small number of users, API keys and customer-provided SSL certificates were also exposed. Imperva said the security incident only affected customers of its cloud WAF, and not other products.

ImpervaRansomware10066/2016
Rankiteo Explanation :
Attack threatening the economy of a geographical region

Description: The florists associated with Incapsula now known as Imperva, suffered a ransomware attack in the Valentine's week of 2016 which resulted in a huge loss of revenue. ALl of the 34 floristes of Inperva were truck by targeted distributed denial-of-service (DDoS) attacks while one of the website crashed after its content delivery network (CDN) interpreted the attack traffic as legitimate user sessions and routed the traffic through the origin server. One of them also received a ransom demand for restoring the access to the website, however, Imperva immediately helped them get their business online and restore all the access.

ThalesBreach100511/2022
Rankiteo Explanation :
Attack threatening the organization's existence

Description: Hackers claim to have stolen data from France's Thales and was threatening to publish it. The extortion and ransomware group had plans on the dark web to release the data on Nov. 7. It had not received any direct ransom notification. The hackers have not provided proof they have obtained any Thales data.

Thales GroupCyber Attack100804/2023
Rankiteo Explanation :
Attack that could bring to a war

Description: In a significant cybersecurity incident, Thales Group, a prominent player in the aerospace, defense, and security sectors, faced a direct attack on its satellite communication systems. This compromise led to a breach of sensitive communication channels between ground operations and several commercial satellites. The attackers managed to inject malicious code to disrupt the integrity of critical data being relayed for navigation and observation purposes. The profound implications of this event put essential space-based services used by governments and corporations at risk, threatening national security interests and economic stability across multiple regions.

Thales GroupRansomware10086/2022
Rankiteo Explanation :
Attack that could bring to a war

Description: In 2022, the French defense and technology firm **Thales Group** fell victim to a **ransomware attack** executed by the **LockBit 3.0** group. The assault specifically targeted the company’s **advanced technology and defense services**, exposing critical vulnerabilities in systems supporting external services for the **maritime sector**. While the full extent of data compromise or operational disruption remains undisclosed, the attack underscored the severe risks ransomware poses to organizations operating in high-stakes industries like defense and aerospace.The breach raised concerns about potential **intellectual property theft**, **disruption of defense-related operations**, and **compromise of sensitive client data**, including government and military entities. Given Thales’ role in providing mission-critical infrastructure—such as **satellite communications, naval systems, and cybersecurity solutions for global defense partners**—the attack carried implications beyond financial loss, threatening **national security and geopolitical stability**. The incident also highlighted the growing trend of cybercriminal groups targeting **strategic industries** to maximize leverage, whether through data exfiltration, operational sabotage, or ransom demands.Though Thales confirmed containment measures, the attack reinforced the urgency for **enhanced cyber resilience** in sectors where digital breaches can have **cascading effects on supply chains, allied nations, and civilian safety**. The involvement of **LockBit 3.0**, a prolific ransomware-as-a-service (RaaS) operator known for high-profile extortion, further amplified the threat’s severity.

Thales DefenceRansomware60511/2022
Rankiteo Explanation :
Attack threatening the organization's existence

Description: French defense and technology group Thales suffered from a ransomware attack after the hacker group LockBit 3.0 stole some of its data and was threatening to publish it. They had not been directly notified of a ransom demand. Thales has launched an internal inquiry and contacted the ANSSI national cyber security agency but has not yet made a police complaint.

Imperva
Data Leak
Severity: 60
Impact: 3
Seen: 08/2019
Blog:
Rankiteo Explanation
Attack with significant impact with internal employee data leaks

Description: Imperva disclosed a security incident that impacts customers of its cloud web application firewall (WAF), formerly known as Incapsula. The company learned from a third party of a data exposure that impacts a subset of customers of their Cloud WAF product. Exposed data included customer email addresses, along with hashed and salted passwords, for a subset of customers. For a small number of users, API keys and customer-provided SSL certificates were also exposed. Imperva said the security incident only affected customers of its cloud WAF, and not other products.

Imperva
Ransomware
Severity: 100
Impact: 6
Seen: 6/2016
Blog:
Rankiteo Explanation
Attack threatening the economy of a geographical region

Description: The florists associated with Incapsula now known as Imperva, suffered a ransomware attack in the Valentine's week of 2016 which resulted in a huge loss of revenue. ALl of the 34 floristes of Inperva were truck by targeted distributed denial-of-service (DDoS) attacks while one of the website crashed after its content delivery network (CDN) interpreted the attack traffic as legitimate user sessions and routed the traffic through the origin server. One of them also received a ransom demand for restoring the access to the website, however, Imperva immediately helped them get their business online and restore all the access.

Thales
Breach
Severity: 100
Impact: 5
Seen: 11/2022
Blog:
Rankiteo Explanation
Attack threatening the organization's existence

Description: Hackers claim to have stolen data from France's Thales and was threatening to publish it. The extortion and ransomware group had plans on the dark web to release the data on Nov. 7. It had not received any direct ransom notification. The hackers have not provided proof they have obtained any Thales data.

Thales Group
Cyber Attack
Severity: 100
Impact: 8
Seen: 04/2023
Blog:
Rankiteo Explanation
Attack that could bring to a war

Description: In a significant cybersecurity incident, Thales Group, a prominent player in the aerospace, defense, and security sectors, faced a direct attack on its satellite communication systems. This compromise led to a breach of sensitive communication channels between ground operations and several commercial satellites. The attackers managed to inject malicious code to disrupt the integrity of critical data being relayed for navigation and observation purposes. The profound implications of this event put essential space-based services used by governments and corporations at risk, threatening national security interests and economic stability across multiple regions.

Thales Group
Ransomware
Severity: 100
Impact: 8
Seen: 6/2022
Blog:
Rankiteo Explanation
Attack that could bring to a war

Description: In 2022, the French defense and technology firm **Thales Group** fell victim to a **ransomware attack** executed by the **LockBit 3.0** group. The assault specifically targeted the company’s **advanced technology and defense services**, exposing critical vulnerabilities in systems supporting external services for the **maritime sector**. While the full extent of data compromise or operational disruption remains undisclosed, the attack underscored the severe risks ransomware poses to organizations operating in high-stakes industries like defense and aerospace.The breach raised concerns about potential **intellectual property theft**, **disruption of defense-related operations**, and **compromise of sensitive client data**, including government and military entities. Given Thales’ role in providing mission-critical infrastructure—such as **satellite communications, naval systems, and cybersecurity solutions for global defense partners**—the attack carried implications beyond financial loss, threatening **national security and geopolitical stability**. The incident also highlighted the growing trend of cybercriminal groups targeting **strategic industries** to maximize leverage, whether through data exfiltration, operational sabotage, or ransom demands.Though Thales confirmed containment measures, the attack reinforced the urgency for **enhanced cyber resilience** in sectors where digital breaches can have **cascading effects on supply chains, allied nations, and civilian safety**. The involvement of **LockBit 3.0**, a prolific ransomware-as-a-service (RaaS) operator known for high-profile extortion, further amplified the threat’s severity.

Thales Defence
Ransomware
Severity: 60
Impact: 5
Seen: 11/2022
Blog:
Rankiteo Explanation
Attack threatening the organization's existence

Description: French defense and technology group Thales suffered from a ransomware attack after the hacker group LockBit 3.0 stole some of its data and was threatening to publish it. They had not been directly notified of a ransom demand. Thales has launched an internal inquiry and contacted the ANSSI national cyber security agency but has not yet made a police complaint.

Ailogo

Thales Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for Thales

Incidents vs Defense and Space Manufacturing Industry Average (This Year)

No incidents recorded for Thales in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for Thales in 2025.

Incident Types Thales vs Defense and Space Manufacturing Industry Avg (This Year)

No incidents recorded for Thales in 2025.

Incident History — Thales (X = Date, Y = Severity)

Thales cyber incidents detection timeline including parent company and subsidiaries

Thales Company Subsidiaries

SubsidiaryImage

Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion. The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies. Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.

Loading...
similarCompanies

Thales Similar Companies

Aselsan

ASELSAN is a company of Turkish Armed Forces Foundation, established in 1975 in order to meet the communication needs of the Turkish Armed Forces by national means. Currently ​74,20% of the shares are owned by the Foundation whereas the remaining 25,8% runs in İstanbul Borsa stock market. ASELSAN is

Republic of Korea Air Force

The Republic of Korea Air Force (ROKAF; Korean: 대한민국 공군; Hanja: 大韓民國 空軍; Revised Romanization: Daehanminguk Gong-gun), also known as the ROK Air Force, is the aerial warfare service branch of South Korea, operating under the South Korean Ministry of National Defense. The ROKAF has about 450 combat

V2X Inc

V2X is a leading provider of critical mission solutions and support to defense clients globally, formed by the 2022 Merger of Vectrus and Vertex to build on more than 120 combined years of successful mission support. We deliver a comprehensive suite of integrated solutions across the operations and

General Dynamics

From Gulfstream business jets and combat vehicles to nuclear-powered submarines and communications systems, people around the world depend on our products and services for their safety and security. General Dynamics is headquartered in Reston, Virginia, and employs over 100,000 people in 43 countri

Leidos

Leidos is a Fortune 500® innovation company rapidly addressing the world’s most vexing challenges in national security and health. The company's global workforce of 48,000 collaborates to create smarter technology solutions for customers in heavily regulated industries. Headquartered in Reston, Virg

Amentum

Amentum is a global leader in advanced engineering and innovative technology solutions, trusted by the United States and its allies to address their most significant and complex challenges in science, security and sustainability. Our people apply undaunted curiosity, relentless ambition and boundles

Lockheed Martin

The world relies on what we do. Headquartered in Bethesda, Maryland, with offices across the U.S. and around the globe, our team delivers solutions that strengthen national security, shape industries and push engineering and technology to new levels. We collaborate to win. We put our customers fi

Naval Sea Systems Command (NAVSEA) Careers

We are NAVSEA. The Force Behind the Fleet. Join us and become part of a mission-driven team, at one of the best places to work in the federal government. This NAVSEA LinkedIn page is all about connecting with talented individuals ready to make a difference through a rewarding career with us. We shar

BAE Systems

At BAE Systems, we help our customers to stay a step ahead when protecting people and national security, critical infrastructure and vital information. We provide some of the world’s most advanced, technology-led defence, aerospace and security solutions and employ a skilled workforce of 107,000 peo

newsone

Thales CyberSecurity News

December 01, 2025 04:52 PM
Thales and CEA: an unprecedented partnership to strengthen French post-quantum cybersecurity

As the quantum revolution compels us to rethink the foundations of cybersecurity, Thales a high-tech leader in Defense, Aerospace,...

December 01, 2025 01:54 PM
Thales, CEA partner on post-quantum cybersecurity

Thales SA: Thales and CEA: an unprecedented partnership to strengthen French post-quantum cybersecurity Company's and CEA's IT security...

December 01, 2025 07:39 AM
University of New Brunswick - UNB's McKenna Institute announces cybersecurity training program for Indigenous talent in partnership with JEDI, Thales

The McKenna Institute at the University of New Brunswick, the Joint Economic Development Initiative (JEDI) and Thales announced today (Nov...

November 27, 2025 04:25 AM
Thales opens Cyber security office

Defence company Thales Australia has opened a new cyber Security Operations Centre (SOC) in Canberra to protect Government and Critical...

November 26, 2025 05:26 AM
Thales Australia opens cyber Security Operations Centre in Canberra

Thales Australia has announced the opening of a sovereign and protected cyber Security Operations Centre in Canberra.

November 25, 2025 03:37 PM
Would Your Business Survive a Black Friday Cyberattack?

Black Friday and Cyber Monday can make or break the year for retailers. Sales soar, carts fill, and data pours in. However, the same things...

November 25, 2025 02:16 AM
Netpoleon expands security portfolio with Thales & Imperva

Netpoleon enhances its cybersecurity portfolio in Australia and New Zealand by integrating Thales and Imperva solutions, boosting data and...

November 24, 2025 12:48 AM
Thales Strengthens European Cybersecurity with Post-Quantum MISTRAL Encryptor

At the European Cyber Week, held in Rennes (France) from 17 to 20 November 2025, Thales announced the launch of the MISTRAL post-quantum...

November 21, 2025 03:04 PM
Thales and the UAE Cyber Security Council join forces to develop a Cyber Centre of Excellence

In line with the UAE's vision to enhance National Cyber Sovereignty, Thales and the UAE Cyber Security Council sign a Memorandum of...

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Thales CyberSecurity History Information

Official Website of Thales

The official website of Thales is http://www.thalesgroup.com/.

Thales’s AI-Generated Cybersecurity Score

According to Rankiteo, Thales’s AI-generated cybersecurity score is 733, reflecting their Moderate security posture.

How many security badges does Thales’ have ?

According to Rankiteo, Thales currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does Thales have SOC 2 Type 1 certification ?

According to Rankiteo, Thales is not certified under SOC 2 Type 1.

Does Thales have SOC 2 Type 2 certification ?

According to Rankiteo, Thales does not hold a SOC 2 Type 2 certification.

Does Thales comply with GDPR ?

According to Rankiteo, Thales is not listed as GDPR compliant.

Does Thales have PCI DSS certification ?

According to Rankiteo, Thales does not currently maintain PCI DSS compliance.

Does Thales comply with HIPAA ?

According to Rankiteo, Thales is not compliant with HIPAA regulations.

Does Thales have ISO 27001 certification ?

According to Rankiteo,Thales is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of Thales

Thales operates primarily in the Defense and Space Manufacturing industry.

Number of Employees at Thales

Thales employs approximately 67,535 people worldwide.

Subsidiaries Owned by Thales

Thales presently has no subsidiaries across any sectors.

Thales’s LinkedIn Followers

Thales’s official LinkedIn profile has approximately 1,780,450 followers.

NAICS Classification of Thales

Thales is classified under the NAICS code 336414, which corresponds to Guided Missile and Space Vehicle Manufacturing.

Thales’s Presence on Crunchbase

Yes, Thales has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/thales-group.

Thales’s Presence on LinkedIn

Yes, Thales maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/thales.

Cybersecurity Incidents Involving Thales

As of December 14, 2025, Rankiteo reports that Thales has experienced 6 cybersecurity incidents.

Number of Peer and Competitor Companies

Thales has an estimated 2,359 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at Thales ?

Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack, Data Leak, Ransomware and Breach.

What was the total financial impact of these incidents on Thales ?

Total Financial Loss: The total financial loss from these incidents is estimated to be $0.

How does Thales detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with imperva, and remediation measures with restored access and got the business back online, and incident response plan activated with internal inquiry launched, and third party assistance with contacted the anssi national cyber security agency..

Incident Details

Can you provide details on each incident ?

Incident : Ransomware

Title: Ransomware and DDoS Attack on Imperva Florists

Description: Incapsula (now Imperva) florists suffered a ransomware attack during Valentine's week of 2016, resulting in significant revenue loss. All 34 florists were hit by targeted DDoS attacks, with one website crashing due to attack traffic being routed through the origin server. One florist received a ransom demand, but Imperva helped restore access and get the business back online.

Date Detected: February 2016

Type: Ransomware

Attack Vector: DDoSRansomware

Motivation: Financial Gain

Incident : Data Breach

Title: Data Theft Incident at Thales

Description: Hackers claim to have stolen data from France's Thales and were threatening to publish it. The extortion and ransomware group had plans on the dark web to release the data on Nov. 7. It had not received any direct ransom notification. The hackers have not provided proof they have obtained any Thales data.

Type: Data Breach

Attack Vector: Unknown

Threat Actor: Unknown

Motivation: Extortion

Incident : Ransomware

Title: Thales Ransomware Attack

Description: French defense and technology group Thales suffered from a ransomware attack after the hacker group LockBit 3.0 stole some of its data and was threatening to publish it.

Type: Ransomware

Threat Actor: LockBit 3.0

Motivation: Data theft and extortion

Incident : Data Exposure

Title: Imperva Cloud WAF Data Exposure Incident

Description: Imperva disclosed a security incident that impacts customers of its cloud web application firewall (WAF), formerly known as Incapsula. The company learned from a third party of a data exposure that impacts a subset of customers of their Cloud WAF product. Exposed data included customer email addresses, along with hashed and salted passwords, for a subset of customers. For a small number of users, API keys and customer-provided SSL certificates were also exposed. Imperva said the security incident only affected customers of its cloud WAF, and not other products.

Type: Data Exposure

Incident : Cyber Attack

Title: Cyber Attack on Thales Group's Satellite Communication Systems

Description: Thales Group, a prominent player in the aerospace, defense, and security sectors, faced a direct attack on its satellite communication systems. This compromise led to a breach of sensitive communication channels between ground operations and several commercial satellites. The attackers managed to inject malicious code to disrupt the integrity of critical data being relayed for navigation and observation purposes. The profound implications of this event put essential space-based services used by governments and corporations at risk, threatening national security interests and economic stability across multiple regions.

Type: Cyber Attack

Attack Vector: Malicious Code Injection

Vulnerability Exploited: Satellite Communication Systems

Motivation: National Security DisruptionEconomic Instability

Incident : ransomware

Title: Ransomware Attack on Thales Group by LockBit 3.0

Description: The French defense and technology firm Thales Group suffered a ransomware attack by LockBit 3.0 in 2022. The attack targeted the company's advanced technology and defense services, illustrating the potential dangers ransomware poses to organizations that offer external service to the maritime sector.

Type: ransomware

Threat Actor: LockBit 3.0

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Ransomware.

How does the company identify the attack vectors used in incidents ?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Satellite Communication Systems.

Impact of the Incidents

What was the impact of each incident ?

Incident : Ransomware IMP141910522

Financial Loss: Significant

Systems Affected: WebsitesCDN

Downtime: Significant

Operational Impact: High

Revenue Loss: Significant

Incident : Ransomware THA142321122

Data Compromised: Some data stolen

Incident : Data Exposure IMP11810423

Data Compromised: Email addresses, Hashed and salted passwords, Api keys, Customer-provided ssl certificates

Systems Affected: Cloud WAF

Incident : Cyber Attack THA430051424

Data Compromised: Sensitive Communication Channels

Systems Affected: Satellite Communication Systems

Operational Impact: Disruption of Critical Data Integrity

What is the average financial loss per incident ?

Average Financial Loss: The average financial loss per incident is $0.00.

What types of data are most commonly compromised in incidents ?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Email Addresses, Hashed And Salted Passwords, Api Keys, Customer-Provided Ssl Certificates, and Sensitive Communication Data.

Which entities were affected by each incident ?

Incident : Ransomware IMP141910522

Entity Name: Imperva Florists

Entity Type: Business

Industry: Floristry

Size: 34 florists

Incident : Data Breach THA123821122

Entity Name: Thales

Entity Type: Organization

Industry: Defense and Security

Location: France

Incident : Ransomware THA142321122

Entity Name: Thales

Entity Type: Defense and Technology Group

Industry: Defense and Technology

Location: France

Incident : Data Exposure IMP11810423

Entity Name: Imperva

Entity Type: Company

Industry: Cybersecurity

Customers Affected: Subset of customers

Incident : Cyber Attack THA430051424

Entity Name: Thales Group

Entity Type: Company

Industry: Aerospace, Defense, Security

Incident : ransomware THA858092125

Entity Name: Thales Group

Entity Type: defense and technology firm

Industry: defense, technology, maritime services

Location: France

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Ransomware IMP141910522

Third Party Assistance: Imperva

Remediation Measures: Restored access and got the business back online

Incident : Ransomware THA142321122

Incident Response Plan Activated: Internal inquiry launched

Third Party Assistance: Contacted the ANSSI national cyber security agency

What is the company's incident response plan?

Incident Response Plan: The company's incident response plan is described as Internal inquiry launched.

How does the company involve third-party assistance in incident response ?

Third-Party Assistance: The company involves third-party assistance in incident response through Imperva, Contacted the ANSSI national cyber security agency.

Data Breach Information

What type of data was compromised in each breach ?

Incident : Ransomware THA142321122

Data Exfiltration: Some data stolen

Incident : Data Exposure IMP11810423

Type of Data Compromised: Email addresses, Hashed and salted passwords, Api keys, Customer-provided ssl certificates

Sensitivity of Data: High

Data Encryption: Hashed and salted passwords

Personally Identifiable Information: email addresses

Incident : Cyber Attack THA430051424

Type of Data Compromised: Sensitive Communication Data

Sensitivity of Data: High

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Restored access and got the business back online.

Ransomware Information

Was ransomware involved in any of the incidents ?

Incident : Ransomware IMP141910522

Ransom Demanded: Yes

Incident : Ransomware THA142321122

Ransomware Strain: LockBit 3.0

Data Exfiltration: Some data stolen

Incident : ransomware THA858092125

Ransomware Strain: LockBit 3.0

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Ransomware THA142321122

Investigation Status: Internal inquiry launched

Initial Access Broker

How did the initial access broker gain entry for each incident ?

Incident : Cyber Attack THA430051424

Entry Point: Satellite Communication Systems

High Value Targets: Commercial Satellites

Data Sold on Dark Web: Commercial Satellites

Post-Incident Analysis

What is the company's process for conducting post-incident analysis ?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Imperva, Contacted the ANSSI national cyber security agency.

Additional Questions

General Information

What was the amount of the last ransom demanded ?

Last Ransom Demanded: The amount of the last ransom demanded was Yes.

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident were an Unknown, LockBit 3.0 and LockBit 3.0.

Incident Details

What was the most recent incident detected ?

Most Recent Incident Detected: The most recent incident detected was on February 2016.

Impact of the Incidents

What was the highest financial loss from an incident ?

Highest Financial Loss: The highest financial loss from an incident was Significant.

What was the most significant data compromised in an incident ?

Most Significant Data Compromised: The most significant data compromised in an incident were Some data stolen, email addresses, hashed and salted passwords, API keys, customer-provided SSL certificates, and Sensitive Communication Channels.

What was the most significant system affected in an incident ?

Most Significant System Affected: The most significant system affected in an incident was WebsitesCDN and Cloud WAF and .

Response to the Incidents

What third-party assistance was involved in the most recent incident ?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Imperva, Contacted the ANSSI national cyber security agency.

Data Breach Information

What was the most sensitive data compromised in a breach ?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Some data stolen, hashed and salted passwords, API keys, customer-provided SSL certificates, Sensitive Communication Channels and email addresses.

Ransomware Information

What was the highest ransom demanded in a ransomware incident ?

Highest Ransom Demanded: The highest ransom demanded in a ransomware incident was Yes.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Internal inquiry launched.

Initial Access Broker

What was the most recent entry point used by an initial access broker ?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an Satellite Communication Systems.

cve

Latest Global CVEs (Not Company-Specific)

Description

A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the attack remotely. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit has been released to the public and may be exploited.

Risk Information
cvss2
Base: 2.6
Severity: HIGH
AV:N/AC:H/Au:N/C:N/I:P/A:N
cvss3
Base: 3.7
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
cvss4
Base: 6.3
Severity: HIGH
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_student.php. This manipulation of the argument stud_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation of the argument user_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Risk Information
cvss2
Base: 7.5
Severity: LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
cvss3
Base: 7.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=thales' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge