Company Details
the-boxoffice-company
163
8,490
5112
boxoffice.com
184
THE_2369547
Completed

The Boxoffice Company Company CyberSecurity Posture
boxoffice.comBoxoffice is the world’s #1 provider of media, technology, and data for the global film industry. The company operates a global network of media brands (AlloCine, AdoroCinema, SensaCine, Espinof, Filmstarts, MoviePilot and Beyazperde) reaching over 74M movie fans across Europe and Latin America. Boxoffice also partners with leading search and discovery platforms, studios, and exhibitors of all sizes to help them connect directly with fans and moviegoers, using the latest innovations in ticketing, business intelligence, and digital marketing. Boxoffice offers a collection of premium products including websites, CRM, online ticketing, and mobile applications for thousands of exhibitors worldwide that generate hundreds of millions of dollars in box office revenue for movie theaters every year. Over 90% of internet audiences searching for movie showtimes and listings are exposed to data powered by Boxoffice. Uniquely positioned at the heart of the entertainment industry, Boxoffice also publishes Boxoffice Pro magazine, the world’s leading source of business information for cinema professionals. Part of the Paris-based Webedia Group, Boxoffice is headquartered in Los Angeles with offices in New York, Mexico, Brazil, France, UK, Spain, Germany, Turkey, and Morocco. Part of the Paris-based Webedia Group, The Boxoffice Company is headquartered in Los Angeles with offices in New York, Mexico, Brazil, France, UK, Spain, and Germany
Company Details
the-boxoffice-company
163
8,490
5112
boxoffice.com
184
THE_2369547
Completed
Between 700 and 749

BC Global Score (TPRM)XXXX

Description: The Maine Office of the Attorney General reported a data breach involving The Boxoffice Company on June 18, 2024. The breach, which occurred on April 4, 2024, was identified as an external system breach (hacking) affecting a total of 480 individuals, with 3 residents specifically affected. Identity theft protection services, namely a 24-month membership to Experian IdentityWorks, were offered as a response.


No incidents recorded for The Boxoffice Company in 2025.
No incidents recorded for The Boxoffice Company in 2025.
No incidents recorded for The Boxoffice Company in 2025.
BC cyber incidents detection timeline including parent company and subsidiaries

Boxoffice is the world’s #1 provider of media, technology, and data for the global film industry. The company operates a global network of media brands (AlloCine, AdoroCinema, SensaCine, Espinof, Filmstarts, MoviePilot and Beyazperde) reaching over 74M movie fans across Europe and Latin America. Boxoffice also partners with leading search and discovery platforms, studios, and exhibitors of all sizes to help them connect directly with fans and moviegoers, using the latest innovations in ticketing, business intelligence, and digital marketing. Boxoffice offers a collection of premium products including websites, CRM, online ticketing, and mobile applications for thousands of exhibitors worldwide that generate hundreds of millions of dollars in box office revenue for movie theaters every year. Over 90% of internet audiences searching for movie showtimes and listings are exposed to data powered by Boxoffice. Uniquely positioned at the heart of the entertainment industry, Boxoffice also publishes Boxoffice Pro magazine, the world’s leading source of business information for cinema professionals. Part of the Paris-based Webedia Group, Boxoffice is headquartered in Los Angeles with offices in New York, Mexico, Brazil, France, UK, Spain, Germany, Turkey, and Morocco. Part of the Paris-based Webedia Group, The Boxoffice Company is headquartered in Los Angeles with offices in New York, Mexico, Brazil, France, UK, Spain, and Germany

Pitney Bowes is a technology-driven products and services company that provides SaaS shipping solutions, mailing innovation, and financial services to clients around the world – including more than 90 percent of the Fortune 500. Small businesses to large enterprises, and government entities rely on
Baidu is a leading AI company with strong Internet foundation, driven by our mission to “make the complicated world simpler through technology”. Founded in 2000 as a search engine platform, we were an early adopter of artificial intelligence in 2010. Since then, we have established a full AI stack,

GlobalLogic, a Hitachi Group company, is a trusted partner in design, data, and digital engineering for the world’s largest and most innovative companies. Since our inception in 2000, we have been at the forefront of the digital revolution, helping to create some of the most widely used digital prod

Walmart has a long history of transforming retail and using technology to deliver innovations that improve how the world shops and empower our 2.1 million associates. It began with Sam Walton and continues today with Global Tech associates working together to power Walmart and lead the next retail d

Dassault Systèmes is a catalyst for human progress. Since 1981, the company has pioneered virtual worlds to improve real life for consumers, patients and citizens. With Dassault Systèmes’ 3DEXPERIENCE platform, 370,000 customers of all sizes, in all industries, can collaborate, imagine and create
We're a global online visual communications platform on a mission to empower the world to design. Featuring a simple drag-and-drop user interface and a vast range of templates ranging from presentations, documents, websites, social media graphics, posters, apparel to videos, plus a huge library of f

NiCE is transforming the world with AI that puts people first. Our purpose-built AI-powered platforms automate engagements into proactive, safe, intelligent actions, empowering individuals and organizations to innovate and act, from interaction to resolution. Trusted by organizations throughout 150
Shopify is a leading global commerce company, providing trusted tools to start, grow, market, and manage a retail business of any size. Shopify makes commerce better for everyone with a platform and services that are engineered for reliability, while delivering a better shopping experience for consu

Meta's mission is to build the future of human connection and the technology that makes it possible. Our technologies help people connect, find communities, and grow businesses. When Facebook launched in 2004, it changed the way people connect. Apps like Messenger, Instagram and WhatsApp further e
.png)
The year 2025 had been anticipated as a decisive moment for the box office, promising a major adjustment after several years of uncertainty.
TechD Cybersecurity shares debuted at ₹366.70 on the NSE SME, achieving a 90% premium over its issue price of ₹193. The IPO, which closed...
“Superman” opened with an impressive $122 million at the domestic box office, Warner Bros. told multiple outlets Sunday.
Apple's high-octane racing film "F1: The Movie" roared to the top of the U.S. and Canadian box office this weekend, fueled by star-power and...
A major user data breach at SK Telecom is raising serious concerns about Korea's national cybersecurity amid growing suspicions that the attack was an act of...
International-Business News: TikTok is preparing to launch its e-commerce platform, TikTok Shop, in Japan, allowing users to sell products...
The animated biblical movie The King of Kings turned into a box office powerhouse in its second weekend with a mere 10% drop in business from its debut weekend.
Jaipur: Tickets for Rajasthan Royals home games against RCB, LSG, GT, MI, and PBKS are available across all categories, starting from Rs...
Ticketmaster is facing a proposed class action accusing it of failing to adopt adequate security measures to prevent against hacks.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of The Boxoffice Company is https://company.boxoffice.com.
According to Rankiteo, The Boxoffice Company’s AI-generated cybersecurity score is 702, reflecting their Moderate security posture.
According to Rankiteo, The Boxoffice Company currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, The Boxoffice Company is not certified under SOC 2 Type 1.
According to Rankiteo, The Boxoffice Company does not hold a SOC 2 Type 2 certification.
According to Rankiteo, The Boxoffice Company is not listed as GDPR compliant.
According to Rankiteo, The Boxoffice Company does not currently maintain PCI DSS compliance.
According to Rankiteo, The Boxoffice Company is not compliant with HIPAA regulations.
According to Rankiteo,The Boxoffice Company is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
The Boxoffice Company operates primarily in the Software Development industry.
The Boxoffice Company employs approximately 163 people worldwide.
The Boxoffice Company presently has no subsidiaries across any sectors.
The Boxoffice Company’s official LinkedIn profile has approximately 8,490 followers.
The Boxoffice Company is classified under the NAICS code 5112, which corresponds to Software Publishers.
No, The Boxoffice Company does not have a profile on Crunchbase.
Yes, The Boxoffice Company maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/the-boxoffice-company.
As of November 30, 2025, Rankiteo reports that The Boxoffice Company has experienced 1 cybersecurity incidents.
The Boxoffice Company has an estimated 26,905 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with offered 24-month membership to experian identityworks..
Title: Data Breach at The Boxoffice Company
Description: The Maine Office of the Attorney General reported a data breach involving The Boxoffice Company on June 18, 2024. The breach, which occurred on April 4, 2024, was identified as an external system breach (hacking) affecting a total of 480 individuals, with 3 residents specifically affected. Identity theft protection services, namely a 24-month membership to Experian IdentityWorks, were offered as a response.
Date Detected: 2024-04-04
Date Publicly Disclosed: 2024-06-18
Type: Data Breach
Attack Vector: External System Breach (Hacking)
Common Attack Types: The most common types of attacks the company has faced is Breach.

Identity Theft Risk: High

Entity Name: The Boxoffice Company
Entity Type: Company
Customers Affected: 480

Remediation Measures: Offered 24-month membership to Experian IdentityWorks

Number of Records Exposed: 480
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Offered 24-month membership to Experian IdentityWorks.

Source: Maine Office of the Attorney General
Date Accessed: 2024-06-18
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2024-06-18.
Most Recent Incident Detected: The most recent incident detected was on 2024-04-04.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-06-18.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 480.0.
Most Recent Source: The most recent source of information about an incident is Maine Office of the Attorney General.
.png)
A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can lead to use of hard-coded cryptographic key . The physical device can be targeted for the attack. A high complexity level is associated with this attack. The exploitation appears to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment retrieval endpoint in the Recruitment module serves files based solely on an authenticated session and user-supplied identifiers, without verifying whether the requester has permission to access the associated interview record. Because the server does not perform any recruitment-level authorization checks, an ESS-level user with no access to recruitment workflows can directly request interview attachment URLs and receive the corresponding files. This exposes confidential interview documents—including candidate CVs, evaluations, and supporting files—to unauthorized users. The issue arises from relying on predictable object identifiers and session presence rather than validating the user’s association with the relevant recruitment process. This issue has been patched in version 5.8.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitment attachment retrieval endpoint does not enforce the required authorization checks before serving candidate files. Even users restricted to ESS-level access, who have no permission to view the Recruitment module, can directly access candidate attachment URLs. When an authenticated request is made to the attachment endpoint, the system validates the session but does not confirm that the requesting user has the necessary recruitment permissions. As a result, any authenticated user can download CVs and other uploaded documents for arbitrary candidates by issuing direct requests to the attachment endpoint, leading to unauthorized exposure of sensitive applicant data. This issue has been patched in version 5.8.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not invalidate existing sessions when a user is disabled or when a password change occurs, allowing active session cookies to remain valid indefinitely. As a result, a disabled user, or an attacker using a compromised account, can continue to access protected pages and perform operations as long as a prior session remains active. Because the server performs no session revocation or session-store cleanup during these critical state changes, disabling an account or updating credentials has no effect on already-established sessions. This makes administrative disable actions ineffective and allows unauthorized users to retain full access even after an account is closed or a password is reset, exposing the system to prolonged unauthorized use and significantly increasing the impact of account takeover scenarios. This issue has been patched in version 5.8.
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflow does not enforce that the username submitted in the final reset request matches the account for which the reset process was originally initiated. After obtaining a valid reset link for any account they can receive email for, an attacker can alter the username parameter in the final reset request to target a different user. Because the system accepts the supplied username without verification, the attacker can set a new password for any chosen account, including privileged accounts, resulting in full account takeover. This issue has been patched in version 5.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.