Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
US Transportation Command

US Transportation Command Vendor Cyber Rating & Cyber Score

ustranscom.mil

The mission of the United States Transportation Command (USTRANSCOM) U.S. Transportation Command exists as a combatant command to project and sustain combat power at a time and place of the Nation’s choosing. As the single manager of America’s global defense transportation system, we are tasked with the coordination of people and transportation assets to allow our country to project and sustain forces, whenever, wherever, and for as long as they are needed. We are a diverse, joint, total force of over 140,000 Active, Reserve and Nation Guard Soldier, Sailors, Airmen, Marines, Coast Guardsmen, and DoD civilians working together with our commercial partners, to move the right capabilities to the right place at the right time … every time.


UTC A.I CyberSecurity Scoring

UTC
Company Information
Website:http://www.ustranscom.mil/
Employees number:534
Number of followers:19,318
NAICS:92811
Industry Type:Armed Forces
Homepage:ustranscom.mil
UTC Risk Score (AI oriented)
Between 750 and 799
logo
UTCArmed Forces
Updated:
02/04/2026
753/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
UTC Global Score (TPRM)
xxxx
logo
UTCArmed Forces
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

UTC
UTCFair
Current Score
753Baa (FAIR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
753Before Incident
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
752Before Incident
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
752Before Incident
JULY 2025
752Before Incident
JANUARY 2022
754Before Incident
Cyber Attack
01 Jan 2022UTC
US Transportation Command: Russian hackers breach orgs to track aid routes to Ukraine

Russian State-Sponsored Cyberespionage Campaign by APT28 (Fancy Bear/Forest Blizzard)

737After Incident
CRITICAL-17
US-1765249605
Russian APT28 Cyberespionage Campaign Targets Aid Efforts to Ukraine Since 2022, the Russian state-sponsored threat group APT28 (Fancy Bear/Forest Blizzard), linked to the GRU’s 85th GTsSS (military unit 26165), has conducted a sustained cyberespionage campaign against organizations supporting Ukraine. The operation, detailed in a joint advisory from 21 intelligence and cybersecurity agencies across nearly a dozen countries, targeted entities in defense, transportation, IT services, air traffic, and maritime sectors across 12 European nations and the U.S. ### Tactics and Techniques APT28 employed a mix of stealthy intrusion methods, including: - Password spraying and brute-force attacks - Spear-phishing (credential theft and malware delivery) - Exploitation of known vulnerabilities, such as: - CVE-2023-23397 (Outlook NTLM relay) - CVE-2023-38831 (WinRAR) - Roundcube webmail flaws (CVE-2020-12641, CVE-2020-35730, CVE-2021-44026) - SQL injection and VPN exploits against internet-facing infrastructure To evade detection, the group routed communications through compromised small office/home office (SOHO) devices near targets. Once inside networks, they used native tools (PsExec, Impacket, RDP) and open-source utilities (Certipy, ADExplorer) for lateral movement and data exfiltration. ### Surveillance and Data Theft APT28 prioritized compromising accounts with access to aid shipment details, including: - Sender/recipient information - Cargo contents and travel routes - Container registration numbers - Destination data They also enrolled hijacked accounts in multi-factor authentication (MFA) to maintain persistent access. Among the malware used were the Headlace and Masepie backdoors, with data exfiltration methods tailored to each victim’s environment—often leveraging living-off-the-land (LOtL) techniques to avoid detection. ### Monitoring Aid Shipments via Compromised Cameras A key aspect of the campaign involved hacking internet-connected cameras—including those at border crossings, military installations, rail stations, and traffic monitoring points—to track material movements into Ukraine. The advisory notes that over 10,000 cameras were targeted, with 80% in Ukraine and nearly 1,000 in Romania. Google Threat Intelligence analyst John Hultquist warned that the group’s objectives extend beyond surveillance, aiming to disrupt aid efforts through cyber or physical means. The targeting of logistics and transportation networks suggests a broader strategy to undermine Ukraine’s supply chains. ### Impact and Scope The campaign affected organizations in Bulgaria, Czechia, France, Germany, Greece, Italy, Moldova, the Netherlands, Poland, Romania, Slovakia, Ukraine, and the U.S. The advisory provides indicators of compromise (IoCs), including malicious scripts, threat actor-controlled email providers, and IP addresses linked to the attacks. While mitigation guidance was included, the report underscores the persistent and adaptive nature of APT28’s operations.
INCIDENT DETAILS -
TYPE
Cyberespionage
MOTIVATION
Disrupt aid efforts to Ukraine, cyberespionage, tracking movement of materials into Ukraine
IMPACT
Data Compromised: Email accounts, Office 365 user lists, sensitive information on aid shipments (sender/recipient, cargo content, travel routes, container registration numbers, destination), Active Directory informationSystems Affected: Corporate networks, email systems, internet-connected cameras, VPNs, Microsoft Exchange serversOperational Impact: Disruption of aid shipments to Ukraine, potential physical or cyber disruption of support effortsIdentity Theft Risk: High (Personally Identifiable Information exposed)
DATA BREACH
Email dataOffice 365 user listsSensitive aid shipment detailsActive Directory informationPersonally Identifiable InformationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for UTC ?
?
What was UTC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was UTC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was UTC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was UTC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was UTC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was UTC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was UTC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was UTC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was UTC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was UTC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was UTC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on UTC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with UTC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view UTC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?