Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
The Vatican

The Vatican Vendor Cyber Rating & Cyber Score

vaticanstate.va

The Vatican City State is a landlocked independent country, city-state, micro-state, and enclave within Rome, Italy. It became independent from Italy in 1929 with the Lateran Treaty, and it is a distinct territory under "full ownership, exclusive dominion, and sovereign authority and jurisdiction" of the Holy See, itself a sovereign entity under international law, which maintains the city-state's temporal power and governance, diplomatic, and spiritual independence. Vatican City contains religious and cultural sites such as St. Peter's Basilica, the Sistine Chapel, the Vatican Apostolic Library, and the Vatican Museums. They feature some of the world's most famous paintings and sculptures. The unique economy of Vatican City is supported


The Vatican A.I CyberSecurity Scoring

The Vatican
Company Information
Website:https://www.vaticanstate.va/it/
Employees number:411
Number of followers:0
NAICS:92
Industry Type:Government Administration
Homepage:vaticanstate.va
The Vatican Risk Score (AI oriented)
Between 750 and 799
logo
The VaticanGovernment Administration
Updated:
27/07/2026
787/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
The Vatican Global Score (TPRM)
xxxx
logo
The VaticanGovernment Administration
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

The Vatican
The VaticanFair
Current Score
787Baa (FAIR)
01000
1 incidents
-49 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
836Before Incident
Breach
24 Jul 2026The Vatican
Vatican: Vatican's Pope-Promoted Prayer App Was a Phishing Goldmine

Vatican’s Click To Pray App Exposed 700,000 Users’ Data Due to Basic API Flaw

787After Incident
CRITICAL-49
VAT1785184303
Vatican’s Click To Pray App Exposed 700,000 Users’ Data Due to Basic API Flaw In a stark example of avoidable security failures, the Vatican’s Click To Pray app personally endorsed by Pope Francis in 2019 leaked the personal data of over 700,000 users for months due to an elementary API vulnerability. The flaw, discovered by white-hat hacker BobDaHacker in January 2026, was only patched on July 24, 2026, after seven months of unanswered disclosure attempts. The issue stemmed from a sequential user ID system in the app’s backend API. By simply incrementing a numeric ID in the endpoint `https://api.clicktopray.org/user/users/[ID]`, anyone could access full user profiles including names, email addresses, dates of birth, countries, and account roles without authentication. The server, running on the basic Express Node.js framework, lacked rate limiting, allowing automated scraping of the entire dataset. Despite multiple emails to Vatican and app contacts, the vulnerability remained unaddressed until BobDaHacker went public. The fix, implemented silently after the disclosure, now restricts access to a user’s own data while exposing only public-facing details for others. Notably, legitimate app emails had also triggered phishing warnings in mail clients, further eroding user trust. The exposed data posed significant risks, particularly for the app’s predominantly older, less tech-savvy user base. With verified names, emails, and ties to a high-trust religious institution, attackers could craft highly convincing phishing campaigns. The incident underscores how even basic oversights like a missing authentication check can lead to large-scale breaches, especially when compounded by delayed responses from institutions. The Click To Pray app remains available, with user data now secured behind the authorization controls that should have been in place from the start. The case serves as a reminder of the consequences when foundational security practices are overlooked.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Ethical disclosure
IMPACT
Data Compromised: Names, email addresses, dates of birth, countries, account rolesSystems Affected: Click To Pray app backend APIOperational Impact: Loss of user trust, potential phishing risksBrand Reputation Impact: Erosion of user trust, phishing warnings in mail clientsIdentity Theft Risk: High (due to exposed PII)
DATA BREACH
Type Of Data Compromised: Personally Identifiable Information (PII)Number Of Records Exposed: 700,000Sensitivity Of Data: High (names, emails, dates of birth, countries, account roles)Data Exfiltration: Possible via automated scrapingPersonally Identifiable Information: Names, email addresses, dates of birth, countries, account roles
JUNE 2026
836Before Incident
MAY 2026
836Before Incident
APRIL 2026
836Before Incident
MARCH 2026
836Before Incident
FEBRUARY 2026
836Before Incident
JANUARY 2026
836Before Incident
DECEMBER 2025
836Before Incident
NOVEMBER 2025
836Before Incident
OCTOBER 2025
836Before Incident
SEPTEMBER 2025
836Before Incident
AUGUST 2025
836Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for The Vatican ?
?
What was The Vatican's A.I Rankiteo Cyber Score in June 2026 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in May 2026 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in April 2026 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in March 2026 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in February 2026 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in January 2026 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in December 2025 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in November 2025 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in October 2025 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in September 2025 ?
?
What was The Vatican's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on The Vatican's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with The Vatican ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view The Vatican's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?