UPS A.I CyberSecurity Scoring
UPS
Company Information
Website:https://about.ups.com/
Employees number:182,515
Number of followers:2,301,741
NAICS:484
Industry Type:Truck Transportation
Homepage:ups.com
UPS Risk Score (AI oriented)
Between 750 and 799
UPSTruck Transportation
Updated:
15/09/2026
15/09/2026
794/1000
Fair
Baa
UPS Global Score (TPRM)
xxxx
UPSTruck Transportation
Score locked

UPSFair
Current Score
794Baa (FAIR)
01000
3 incidents
-12 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
794
AUGUST 2026
793
JULY 2026
805
Cyber Attack
25 Jul 2026 • UPS
Malaysia’s Inland Revenue Board and UPS Forwarding Hub: Phantom Stealer Campaign Abuses UPS and Tax Audit Emails to Steal Credentials
Sophisticated Phishing Campaign Deploys Phantom Stealer Malware via Fake Logistics and Tax Lures
793
CRITICAL-12
LHDUPS1784960664
Sophisticated Phishing Campaign Deploys Phantom Stealer Malware via Fake Logistics and Tax Lures
A multi-stage phishing campaign, documented by Seqrite, is targeting organizations by impersonating trusted entities including UPS Forwarding Hub and Malaysia’s Inland Revenue Board (LHDN) to deploy Phantom Stealer v3.5.0, a credential-harvesting malware.
The campaign employs two distinct phishing lures:
- Fake UPS shipment booking details, aimed at procurement teams, with malicious attachments disguised as legitimate documents (e.g., "UPS Docs_Shipment Number 3264010420-Quote ID 203263067.js").
- Fraudulent tax audit notices in Malay, pressuring finance staff to respond within a 14-day deadline.
Both lures deliver a malicious JavaScript file inside a compressed archive, initiating a four-stage infection chain designed to evade detection:
1. Stage 1 (JavaScript): An obfuscated script decodes and executes a Base64-encoded PowerShell payload in memory, avoiding external downloads.
2. Stage 2 (PowerShell Loader 1): The payload decrypts an AES-encrypted next stage using embedded keys, executing it via `Invoke-Expression`.
3. Stage 3 (PowerShell Loader 2): Delivers an XOR-encrypted .NET injector (key: "DEVILboy56@@") and a PE file (confirmed via "MZ" header), which is reflectively loaded into aspnet_compiler.exe for in-memory execution.
4. Stage 4 (Phantom Stealer v3.5.0): The final payload harvests browser credentials, cookies, payment cards, cryptocurrency wallets, and messaging app data, categorizing stolen files (e.g., Chromium_passwords_<hostname>.txt). Data is exfiltrated via SMTP (port 587) using STARTTLS encryption, mimicking legitimate email traffic.
The malware connects to an SMTP server (ruhi@aktekmetal[.]com[.]tr) with Base64-encoded credentials, sending stolen data before terminating with a QUIT command to avoid detection.
No specific threat actor has been attributed, as Phantom Stealer is commodity malware widely available in cybercriminal markets. The campaign highlights attackers’ use of convincing business pretexts, layered obfuscation, and fileless execution to bypass traditional defenses.
Indicators of Compromise (IOCs) include multiple file hashes and Seqrite detection signatures (e.g., Trojan.Injector.S39585891, PS.Trojan.Loader.50921.GC). Domains and IPs are defanged to prevent accidental resolution.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
805
MAY 2026
804
APRIL 2026
804
MARCH 2026
804
FEBRUARY 2026
803
JANUARY 2026
803
DECEMBER 2025
802
NOVEMBER 2025
802
OCTOBER 2025
802
FEBRUARY 2022
810
Data Leak
01 Feb 2022 • UPS
UPS
UPS Data Breach via SMS Phishing Campaign
772
HIGH-38
UPS134025623
UPS found that between February 2022 and April 2023, the perpetrators of the persistent SMS phishing campaign used its package look-up capabilities to obtain access to delivery information, including the recipients' personal contact information.
The company has now put protections in place to limit access to this sensitive data in order to combat these sophisticated phishing attacks.
The recipient's name, the address to which the box was being shipped, and possibly the phone number and order number were all available information through the parcel look-up facilities.
In order to maintain transparency and raise awareness of the issue, UPS will notify people whose information may have been compromised.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2013
817
Ransomware
01 Sep 2013 • UPS
FedEx and UPS: Cryptolocker ransomware: A look back at its widespread impact
Cryptolocker Ransomware Attack
726
CRITICAL-91
FEDUPS1788791163
Cryptolocker: The Ransomware That Redefined Cybersecurity Threats
In 2013, a new strain of ransomware called Cryptolocker emerged, reshaping public awareness of digital extortion. Unlike earlier variants, Cryptolocker leveraged sophisticated social engineering tactics, spreading primarily through spam emails disguised as legitimate communications. Early campaigns used fake customer complaints, while later versions impersonated UPS and FedEx shipping alerts or flagged "problematic check transactions." These emails contained ZIP file attachments that, when opened, deployed a Trojan horse, infecting systems and linking them to a botnet.
Once activated, Cryptolocker encrypted users' files, demanding ransom payments typically in bitcoin for decryption. By December 2013, the malware had infected an estimated 250,000 computers, with nearly half in the U.S., generating roughly $27 million in ransom payments. The following year, Operation Tovar, a coordinated multinational effort, disrupted the Gameover Zeus botnet a key infrastructure for Cryptolocker and dismantled its command servers. Despite the takedown, the suspected mastermind, Evgeniy Mikhailovich Bogachev, remains at large.
Cryptolocker’s impact extended beyond financial losses, serving as a turning point in cybersecurity by demonstrating the scale and profitability of ransomware attacks. Its legacy persists as a cautionary example of how quickly digital threats can evolve and spread.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for UPS ??
What was UPS's A.I Rankiteo Cyber Score in August 2026 ??
What was UPS's A.I Rankiteo Cyber Score in July 2026 ??
What was UPS's A.I Rankiteo Cyber Score in June 2026 ??
What was UPS's A.I Rankiteo Cyber Score in May 2026 ??
What was UPS's A.I Rankiteo Cyber Score in April 2026 ??
What was UPS's A.I Rankiteo Cyber Score in March 2026 ??
What was UPS's A.I Rankiteo Cyber Score in February 2026 ??
What was UPS's A.I Rankiteo Cyber Score in January 2026 ??
What was UPS's A.I Rankiteo Cyber Score in December 2025 ??
What was UPS's A.I Rankiteo Cyber Score in November 2025 ??
What was UPS's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on UPS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with UPS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view UPS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?