UPS A.I CyberSecurity Scoring
UPS
Company Information
Website:https://about.ups.com/
Employees number:182,515
Number of followers:2,301,741
NAICS:484
Industry Type:Truck Transportation
Homepage:ups.com
UPS Risk Score (AI oriented)
Between 800 and 849
UPSTruck Transportation
Updated:
25/07/2026
25/07/2026
800/1000
Good
A
UPS Global Score (TPRM)
xxxx
UPSTruck Transportation
Score locked

UPSGood
Current Score
800A (GOOD)
01000
2 incidents
-12 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
798
JULY 2026
812
Cyber Attack
25 Jul 2026 • UPS
Malaysia’s Inland Revenue Board and UPS Forwarding Hub: Phantom Stealer Campaign Abuses UPS and Tax Audit Emails to Steal Credentials
Sophisticated Phishing Campaign Deploys Phantom Stealer Malware via Fake Logistics and Tax Lures
800
CRITICAL-12
LHDUPS1784960664
Sophisticated Phishing Campaign Deploys Phantom Stealer Malware via Fake Logistics and Tax Lures
A multi-stage phishing campaign, documented by Seqrite, is targeting organizations by impersonating trusted entities including UPS Forwarding Hub and Malaysia’s Inland Revenue Board (LHDN) to deploy Phantom Stealer v3.5.0, a credential-harvesting malware.
The campaign employs two distinct phishing lures:
- Fake UPS shipment booking details, aimed at procurement teams, with malicious attachments disguised as legitimate documents (e.g., "UPS Docs_Shipment Number 3264010420-Quote ID 203263067.js").
- Fraudulent tax audit notices in Malay, pressuring finance staff to respond within a 14-day deadline.
Both lures deliver a malicious JavaScript file inside a compressed archive, initiating a four-stage infection chain designed to evade detection:
1. Stage 1 (JavaScript): An obfuscated script decodes and executes a Base64-encoded PowerShell payload in memory, avoiding external downloads.
2. Stage 2 (PowerShell Loader 1): The payload decrypts an AES-encrypted next stage using embedded keys, executing it via `Invoke-Expression`.
3. Stage 3 (PowerShell Loader 2): Delivers an XOR-encrypted .NET injector (key: "DEVILboy56@@") and a PE file (confirmed via "MZ" header), which is reflectively loaded into aspnet_compiler.exe for in-memory execution.
4. Stage 4 (Phantom Stealer v3.5.0): The final payload harvests browser credentials, cookies, payment cards, cryptocurrency wallets, and messaging app data, categorizing stolen files (e.g., Chromium_passwords_<hostname>.txt). Data is exfiltrated via SMTP (port 587) using STARTTLS encryption, mimicking legitimate email traffic.
The malware connects to an SMTP server (ruhi@aktekmetal[.]com[.]tr) with Base64-encoded credentials, sending stolen data before terminating with a QUIT command to avoid detection.
No specific threat actor has been attributed, as Phantom Stealer is commodity malware widely available in cybercriminal markets. The campaign highlights attackers’ use of convincing business pretexts, layered obfuscation, and fileless execution to bypass traditional defenses.
Indicators of Compromise (IOCs) include multiple file hashes and Seqrite detection signatures (e.g., Trojan.Injector.S39585891, PS.Trojan.Loader.50921.GC). Domains and IPs are defanged to prevent accidental resolution.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
811
MAY 2026
809
APRIL 2026
809
MARCH 2026
809
FEBRUARY 2026
809
JANUARY 2026
809
DECEMBER 2025
807
NOVEMBER 2025
807
OCTOBER 2025
807
SEPTEMBER 2025
807
FEBRUARY 2022
817
Data Leak
01 Feb 2022 • UPS
UPS
UPS Data Breach via SMS Phishing Campaign
785
HIGH-32
UPS134025623
UPS found that between February 2022 and April 2023, the perpetrators of the persistent SMS phishing campaign used its package look-up capabilities to obtain access to delivery information, including the recipients' personal contact information.
The company has now put protections in place to limit access to this sensitive data in order to combat these sophisticated phishing attacks.
The recipient's name, the address to which the box was being shipped, and possibly the phone number and order number were all available information through the parcel look-up facilities.
In order to maintain transparency and raise awareness of the issue, UPS will notify people whose information may have been compromised.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for UPS ??
What was UPS's A.I Rankiteo Cyber Score in July 2026 ??
What was UPS's A.I Rankiteo Cyber Score in June 2026 ??
What was UPS's A.I Rankiteo Cyber Score in May 2026 ??
What was UPS's A.I Rankiteo Cyber Score in April 2026 ??
What was UPS's A.I Rankiteo Cyber Score in March 2026 ??
What was UPS's A.I Rankiteo Cyber Score in February 2026 ??
What was UPS's A.I Rankiteo Cyber Score in January 2026 ??
What was UPS's A.I Rankiteo Cyber Score in December 2025 ??
What was UPS's A.I Rankiteo Cyber Score in November 2025 ??
What was UPS's A.I Rankiteo Cyber Score in October 2025 ??
What was UPS's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on UPS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with UPS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view UPS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?