Vectra AI A.I CyberSecurity Scoring
Vectra AI
Company Information
Website:https://www.vectra.ai
Employees number:668
Number of followers:56,704
NAICS:541514
Industry Type:Computer and Network Security
Homepage:vectra.ai
Vectra AI Risk Score (AI oriented)
Between 0 and 549
Vectra AIComputer and Network Security
Updated:
07/07/2026
07/07/2026
502/1000
Critical
C
Vectra AI Global Score (TPRM)
xxxx
Vectra AIComputer and Network Security
Score locked

Vectra AICritical
Current Score
502C (CRITICAL)
01000
2 incidents
-136.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
516
AUGUST 2026
512
JULY 2026
501
JUNE 2026
498
MAY 2026
487
APRIL 2026
652
Ransomware
29 Apr 2026 • Vectra AI
VECT 2.0: New VECT 2.0 Ransomware Targets Multi-Platform Systems
VECT 2.0 Ransomware Flaw Turns It Into a Data Wiper, Destroying Files Permanently
487
CRITICAL-165
VEC1777466071
VECT 2.0 Ransomware Flaw Turns It Into a Data Wiper, Destroying Files Permanently
Cybersecurity researchers have identified a critical flaw in VECT 2.0, a Ransomware-as-a-Service (RaaS) operation, that renders victim data permanently unrecoverable even after paying the ransom. Unlike traditional ransomware, which encrypts files for extortion, VECT 2.0 destroys files larger than 128 KB due to a cryptographic error, effectively functioning as a data wiper.
### The Fatal Flaw: How VECT 2.0 Fails at Encryption
VECT 2.0 uses the ChaCha20-IETF cipher across its Windows, Linux, and VMware ESXi variants. However, a coding mistake causes the malware to overwrite encryption nonces in memory. For files exceeding 131,072 bytes (128 KB), the ransomware splits data into four chunks, each requiring a unique nonce. Due to the flaw, only the final nonce is retained, making decryption of the first three chunks mathematically impossible even for the attackers.
Enterprise databases, virtual machine disks, and standard office documents most of which exceed 128 KB are irreversibly corrupted. Researchers initially misidentified the cipher as ChaCha20-Poly1305 AEAD, but confirmed the malware lacks integrity protection or authentication tags, further complicating recovery efforts.
### Multi-Platform Threat: Enterprise-Wide Destruction
Despite amateur coding errors such as an aggressive thread scheduler that slows encryption and self-canceling obfuscation VECT 2.0 poses a severe risk to enterprise networks. The malware targets multiple platforms in coordinated attacks:
- Windows: Manipulates Safe Mode boot settings to disable security tools, then spreads laterally via SMB and WinRM.
- Linux: Wipes system logs and targets enterprise file servers.
- VMware ESXi: Disables hypervisor monitoring services and destroys virtual machine disk files.
### Threat Actor Alliances Expand Attack Surface
VECT 2.0 has formed strategic partnerships with major cybercrime groups, amplifying its reach:
- BreachForums: All forum members are now automatic affiliates, granting VECT a vast distribution network.
- TeamPCP: A threat actor known for supply chain attacks on developer tools like Trivy and Checkmarx KICS, providing VECT with a direct pipeline to exploit downstream consumers.
With no possibility of data recovery, organizations face total data loss if infected. The flaw underscores the growing trend of ransomware evolving into destructive wipers, shifting the focus from extortion to outright sabotage.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
756
Ransomware
01 Mar 2026 • Vectra AI
Unnamed Victim Organization and Vect: Sophos Flags Vect-TeamPCP Cybercriminal Ransomware Alliance
Sophos Uncovers Vect-TeamPCP Ransomware Alliance
648
CRITICAL-108
REVVEC1783441774
Sophos Uncovers Vect-TeamPCP Ransomware Alliance, Signaling a New Era in Cybercrime Collaboration
In a major evolution of the cybercrime landscape, Sophos’ X-Ops Counter Threat Unit (CTU) has exposed a strategic partnership between the ransomware-as-a-service (RaaS) group Vect and the cybercriminal outfit TeamPCP (also known as PCPcat, ShellForce, and DeadCatx3). The alliance, which combines TeamPCP’s expertise in credential theft and supply chain compromise with Vect’s RaaS infrastructure, has already resulted in at least one confirmed ransomware attack, demonstrating the growing industrialization of cybercrime.
Key Details of the Threat:
- Who: Vect, a RaaS operation that emerged in December 2025, and TeamPCP, a group linked to the English-speaking cybercriminal network The Com, have formed a partnership to streamline attacks.
- What: TeamPCP specializes in compromising trusted open-source development tools to harvest credentials at scale, which are then funneled to Vect for ransomware deployment. The collaboration mirrors legitimate business models, with threat actors outsourcing specialized functions to maximize efficiency.
- When: The partnership was uncovered in 2026, following a series of high-profile supply chain attacks between March and May of that year. Vect had previously announced a collaboration with BreachForums in March, signaling its ambition to reshape the ransomware ecosystem.
- Why: The alliance lowers the barrier to entry for cybercriminals, enabling less technically skilled attackers to launch sophisticated ransomware campaigns by leveraging stolen credentials and pre-built infrastructure. Sophos warns that the rise of AI-driven automation will further accelerate this trend, making attacks faster and more scalable.
- Impact: The Vect-TeamPCP pipeline has already been used in active ransomware attacks, with Sophos confirming at least one successful deployment. The model also reflects a broader shift in cybercrime, where groups like Lapsus$ and others monetize stolen data through strategic partnerships.
Broader Implications:
The partnership underscores how cybercriminal organizations are adopting corporate-like structures, pooling resources, and specializing in niche areas to enhance their operations. As supply chain attacks become a direct pathway to ransomware, enterprises face heightened risks from compromised third-party updates and development environments an attack surface that remains poorly governed. The industrialization of ransomware, fueled by AI and collaborative crime networks, is expected to escalate the frequency and sophistication of future threats.
INCIDENT DETAILS -
TYPE
MOTIVATION
DATA BREACH
REFERENCES
FEBRUARY 2026
756
JANUARY 2026
756
DECEMBER 2025
756
NOVEMBER 2025
756
OCTOBER 2025
756
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Vectra AI ??
What was Vectra AI's A.I Rankiteo Cyber Score in August 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in July 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in June 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in May 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in April 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in March 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in February 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in January 2026 ??
What was Vectra AI's A.I Rankiteo Cyber Score in December 2025 ??
What was Vectra AI's A.I Rankiteo Cyber Score in November 2025 ??
What was Vectra AI's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Vectra AI's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Vectra AI ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Vectra AI's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?