Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Underdark.ai

Underdark.ai Vendor Cyber Rating & Cyber Score

underdark.ai

Underdark.ai is a specialized company offering cutting-edge cyber threat intelligence services, particularly focused on darknet monitoring and HUMINT (human intelligence) engagements. About Underdark.ai: Underdark.ai is at the forefront of cyber threat intelligence, employing expert techniques in darknet monitoring and engagement with threat actors. The company was established by a team of seasoned professionals, including cybercrime experts with experience in government agencies and the private sector, particularly in fintech and cyber threat intelligence. Core Services: Surgical Cyber Threat Intelligence: Underdark.ai provides precise intelligence alerts based on continuous interactions within various darknet forums, marketplaces,


Underdark.ai A.I CyberSecurity Scoring

Underdark.ai
Company Information
Website:https://underdark.ai/
Employees number:1
Number of followers:1,832
NAICS:541514
Industry Type:Computer and Network Security
Homepage:underdark.ai
Underdark.ai Risk Score (AI oriented)
Between 550 and 599
logo
Underdark.aiComputer and Network Security
Updated:
21/03/2026
558/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Underdark.ai Global Score (TPRM)
xxxx
logo
Underdark.aiComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Underdark.ai
Underdark.aiVery Poor
Current Score
558Ca (VERY POOR)
01000
3 incidents
-76 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
569Before Incident
MAY 2026
566Before Incident
APRIL 2026
563Before Incident
MARCH 2026
556Before Incident
FEBRUARY 2026
554Before Incident
JANUARY 2026
665Before Incident
Ransomware
01 Jan 2026Underdark.ai
Hong Kong precision components supplier and Italian maritime port authority: Ransomware Groups Surge In Q4 2025 – Cyble Insights

Ransomware Attacks Surge 30% in Q4 2025, Targeting Critical Sectors and Supply Chains

547After Incident
CRITICAL-118
CYBITA1770216378
Ransomware Attacks Surge 30% in Q4 2025, Targeting Critical Sectors and Supply Chains Ransomware activity has spiked sharply, with attacks increasing by 30% in the last four months of 2025 compared to the first nine months of the year. Cybersecurity firm Cyble recorded 2,018 claimed attacks in Q4 2025 averaging 673 victims per month while January 2026 saw 679 attacks, maintaining the elevated pace. ### Key Trends and Threat Actors - Qilin led all ransomware groups in January with 115 attacks, followed by Akira (76), Sinobi, and The Gentlemen. - CL0P resurfaced in late 2025, claiming victims in Australia, the U.S., and the UK, including 11 Australian companies across IT, finance, healthcare, and construction. - The U.S. remained the most targeted country, accounting for nearly half of all attacks, while the UK and Australia saw heightened activity due to CL0P’s campaign. ### Targeted Sectors Ransomware groups continued to focus on construction, professional services, and manufacturing, likely due to vulnerabilities in their environments. IT firms also faced frequent attacks, given their access to downstream customer networks. ### Notable January 2026 Attacks - Everest breached a U.S. telecom equipment manufacturer, exfiltrating 11 GB of data, including engineering schematics, PCB layouts, and 3D designs. - Qilin compromised a U.S. airport authority, exposing financial documents, telehealth reports, and internal emails. - Sinobi claimed a breach of an India-based IT services firm, stealing 150 GB of data, including contracts, financial records, and customer data. - Rhysida sold stolen data from a U.S. biotech instrumentation company, including engineering blueprints and NDAs. - RansomHouse targeted a China-based electronics manufacturer, leaking CAD models, PCB designs, and proprietary production data. - INC Ransom breached a Hong Kong precision components supplier, exfiltrating 200 GB of data linked to global tech and automotive brands. - Nitrogen leaked 71 GB of data from a U.S. automotive components firm, including CAD drawings and financial records. - Anubis compromised an Italian maritime port authority, exposing operational data, safety reports, and infrastructure layouts. ### Emerging Ransomware Groups - Green Blood launched a new operation, encrypting files with the “.tgbg” extension and targeting victims in India, Senegal, and Colombia. - DataKeeper introduced a RaaS model with hybrid encryption (RSA-4096), in-memory execution, and TOR-based payment links. - MonoLock debuted a Linux-compatible RaaS using Beacon Object Files (BoF) for stealthy execution, avoiding public leak sites to reduce law enforcement exposure. The sustained rise in ransomware attacks, coupled with the emergence of new threat groups, underscores the evolving tactics of cybercriminals targeting critical infrastructure, supply chains, and high-value industries.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial GainData ExfiltrationEspionage
IMPACT
Engineering schematicsPCB layouts3D designsFinancial documentsTelehealth reportsInternal emailsContractsCustomer dataCAD modelsProprietary production dataNDAsOperational dataSafety reportsInfrastructure layoutsOperational Impact: Disruption of critical infrastructure and supply chainsBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Engineering schematicsPCB layouts3D designsFinancial documentsTelehealth reportsInternal emailsContractsCustomer dataCAD modelsProprietary production dataNDAsOperational dataSafety reportsInfrastructure layoutsSensitivity Of Data: HighCADPDFEmailsFinancial RecordsPersonally Identifiable Information: Likely
DECEMBER 2025
665Before Incident
NOVEMBER 2025
663Before Incident
OCTOBER 2025
661Before Incident
SEPTEMBER 2025
659Before Incident
AUGUST 2025
689Before Incident
Cyber Attack
01 Aug 2025Underdark.ai
ShinyHunters: Canada Goose Investigates Customer Data Leak as Hackers Claim 600,000 Records

Canada Goose Investigates Customer Data Exposure After ShinyHunters Leak

655After Incident
CRITICAL-34
UND1771339192
Canada Goose Investigates Customer Data Exposure After ShinyHunters Leak Canada Goose is probing a potential data exposure affecting over 600,000 customers after the hacking group ShinyHunters published a 1.67GB dataset allegedly tied to the company. The leaked records, which surfaced on the group’s leak site, include names, email addresses, phone numbers, billing and shipping details, order history, and partial payment card data (such as card type and last four digits). The compromised data appears to date back to August 2025 and primarily involves customers in North America and Europe. ShinyHunters claims the breach originated from a third-party payment processor, not Canada Goose’s internal systems. The company has acknowledged the incident but stated it has found no evidence of a direct breach within its own environment. While the leaked data does not include full payment card numbers, Canada Goose confirmed that no unmasked financial information was exposed. The investigation remains ongoing, and the company has not yet determined the total number of affected customers or whether formal notifications will be issued. Despite the lack of full financial details, the exposure poses significant risks. The combination of personal and transactional data such as order history and shipping addresses could enable highly targeted phishing and social engineering attacks. Attackers may use this information to craft convincing scams, particularly against high-value or repeat customers, increasing the potential for fraud and brand distrust. The incident underscores the challenges companies face in managing third-party security risks. Even when a breach occurs outside their direct systems, customers often hold brands accountable for data protection. Clear communication and proactive support will be critical in mitigating reputational damage as the investigation continues.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Data exfiltration for potential financial gain or sale on dark web
IMPACT
Data Compromised: Names, email addresses, phone numbers, billing and shipping details, order history, partial payment card data (card type and last four digits)Systems Affected: Third-party payment processorBrand Reputation Impact: Potential reputational damage due to customer data exposureIdentity Theft Risk: High (due to combination of personal and transactional data enabling phishing/social engineering attacks)Payment Information Risk: Low (only partial payment card data exposed)
DATA BREACH
Personal Identifiable Information (PII)Payment data (partial)Order historyBilling and shipping detailsNumber Of Records Exposed: Over 600,000Sensitivity Of Data: High (PII and transactional data)Data Exfiltration: Yes (published by ShinyHunters)Personally Identifiable Information: Names, email addresses, phone numbers, billing and shipping details
JULY 2025
689Before Incident
JUNE 2023
747Before Incident
Breach
16 Jun 2023Underdark.ai
BreachForums and ShinyHunters: BreachForums Breached, Exposing 324K Cybercriminals

BreachForums Data Leak Exposes 324K Cybercriminals in Dramatic Retaliation

650After Incident
CRITICAL-97
UNDRES1768882773
BreachForums Data Leak Exposes 324K Cybercriminals in Dramatic Retaliation On January 9, an individual using the alias "James" published a massive database containing the real identities and details of 323,986 BreachForums users, including administrators, moderators, and members of the notorious hacking community. The leak, framed as an act of retribution, targeted key figures behind BreachForums and ShinyHunters, with James claiming disillusionment with the groups’ shift toward attacking French targets. The manifesto, written in a theatrical 23-part style, portrayed James as a long-standing hacker who mentored these groups before turning against them. Among those named were French nationals Dorian Dali, Nahyl Ojeda, and Ali Aboussi, many of whom were reportedly teenagers or young adults. James declared the leak a move to "settle their destiny" by exposing them to authorities. Resecurity, a cybersecurity firm, confirmed the authenticity of the leaked data, which included usernames, email addresses, IP addresses, and registration details. While some members used anonymous email services, others relied on mainstream providers like Gmail, making identification easier for law enforcement. The data also revealed a global distribution of members, with concentrations in the U.S., Germany, Netherlands, France, Turkey, and the U.K., as well as significant activity in the Middle East and North Africa. The leak is expected to disrupt cybercriminal operations by stripping away anonymity, a cornerstone of groups like ShinyHunters. Shane Barney, CISO at Keeper Security, noted that the exposure of real identities and IP histories could accelerate investigations, making it harder for members to operate without fear of attribution. BreachForums, a successor to the shuttered RaidForums, has been a hub for trading stolen data, hacking tools, and personal information. Previous law enforcement actions, including the 2023 arrest of Conor Brian Fitzpatrick (pompompurin) and the 2024 sentencing of ShinyHunters member Sebastien Raoult, have failed to permanently dismantle the forum. This latest breach, however, may prove more damaging by exposing the infrastructure and identities of its members. While BreachForums users have dismissed the leak as outdated, Resecurity warned that many reuse registration details across underground platforms, meaning the data remains a valuable resource for law enforcement. The incident underscores the ongoing cat-and-mouse game between cybercriminals and authorities, with this leak marking a significant blow to one of the dark web’s most active marketplaces.
INCIDENT DETAILS -
TYPE
Data Leak
MOTIVATION
Retribution, disillusionment with cybercriminal groups' targeting of French entities
IMPACT
Data Compromised: Usernames, email addresses, IP addresses, registration detailsSystems Affected: BreachForums user databaseOperational Impact: Disruption of cybercriminal operations, loss of anonymity for membersBrand Reputation Impact: Significant reputational damage to BreachForums and ShinyHuntersLegal Liabilities: Increased risk of law enforcement actions against exposed membersIdentity Theft Risk: High risk for exposed individuals due to real identity disclosure
DATA BREACH
UsernamesEmail addressesIP addressesRegistration detailsNumber Of Records Exposed: 323,986Sensitivity Of Data: High (real identities of cybercriminals)Data Exfiltration: Yes (published publicly)Personally Identifiable Information: Yes (real names, locations, and other identifying details)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Underdark.ai ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Underdark.ai's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Underdark.ai's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Underdark.ai ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Underdark.ai's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?