Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Wells Fargo

Wells Fargo Vendor Cyber Rating & Cyber Score

wellsfargo.com

Wells Fargo & Company (NYSE: WFC) is a diversified, community-based financial services company with approximately $1.9 trillion in assets. Wells Fargo’s vision is to satisfy our customers’ financial needs and help them succeed financially. Founded in 1852 and headquartered in San Francisco, Wells Fargo provides banking, investment and mortgage products and services, as well as consumer and commercial finance, through more than 7,300 locations, 12,000 ATMs, the internet (wellsfargo.com) and mobile banking, and has offices in over 40 countries and territories to support customers who conduct business in the global economy. With approximately 250,000 team members, Wells Fargo serves one in three households in the United States. Wells Fargo &


Wells Fargo A.I CyberSecurity Scoring

Wells Fargo
Company Information
Website:http://www.wellsfargo.com
Employees number:221,512
Number of followers:3,162,962
NAICS:52
Industry Type:Financial Services
Homepage:wellsfargo.com
Wells Fargo Risk Score (AI oriented)
Between 750 and 799
logo
Wells FargoFinancial Services
Updated:
20/05/2026
796/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Wells Fargo Global Score (TPRM)
xxxx
logo
Wells FargoFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Wells Fargo
Wells FargoFair
Current Score
796Baa (FAIR)
01000
4 incidents
-10 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
799Before Incident
MAY 2026
796Before Incident
APRIL 2026
797Before Incident
MARCH 2026
796Before Incident
FEBRUARY 2026
797Before Incident
JANUARY 2026
797Before Incident
DECEMBER 2025
803Before Incident
Cyber Attack
01 Dec 2025Wells Fargo
Navy Federal Credit Union, USAA, Citibank, Fidelity Investments and Wells Fargo: Operation DoppelBrand: Weaponizing Fortune 500 Brands

Operation DoppelBrand: Sophisticated Phishing Campaign Targets Fortune 500 Firms

793After Incident
CRITICAL-10
CITWELNAVUSAFID1771266975
Operation DoppelBrand: Sophisticated Phishing Campaign Targets Fortune 500 Firms An elusive cyberthreat group known as GS7 has been running Operation DoppelBrand, a large-scale phishing campaign targeting Fortune 500 companies, financial institutions, and high-value entities worldwide. First observed between December 2025 and January 2026, the operation leverages near-perfect replicas of corporate login portals to steal credentials and deploy remote management and monitoring (RMM) tools for further exploitation. ### Key Details of the Campaign - Targets: Primarily U.S.-based financial institutions including Wells Fargo, USAA, Navy Federal Credit Union, Fidelity Investments, and Citibank alongside technology, healthcare, and telecommunications firms in Europe and other regions. - Tactics: GS7 registers over 150 malicious domains via registrars like NameCheap and OwnRegistrar, routing traffic through Cloudflare to evade detection. Attackers exfiltrate stolen data usernames, passwords, IP addresses, geolocation, device fingerprints, and timestamps to Telegram bots controlled by the group. - Infrastructure: The group has operated since at least 2022, with claims of activity dating back nearly a decade. Researchers linked GS7 to Brazilian cybercrime forums, where stolen credentials and financial data are traded. - Impact: Beyond credential theft, GS7 installs RMM tools on victim systems, enabling remote access or malware deployment. The campaign’s sophistication including rotating infrastructure and meticulous branding mimicry has allowed it to evade detection until now. ### Researcher Findings Security firm SOCRadar uncovered the operation, identifying a Telegram group ("NfResultz by GS") tied to the threat actor. A self-proclaimed GS7 member provided screenshots of past campaigns, including a Fidelity Investments phishing demo that triggered RMM tool downloads upon login. SOCRadar released TTPs (tactics, techniques, and procedures) and IoCs (indicators of compromise) to help defenders track the group’s activities. With English-speaking markets as the primary focus, GS7’s DoppelBrand campaign remains active, underscoring the growing threat of highly organized, financially motivated phishing operations.
INCIDENT DETAILS -
TYPE
Phishing Campaign
MOTIVATION
Financial gain, data theft
IMPACT
Data Compromised: Usernames, passwords, IP addresses, geolocation, device fingerprints, timestampsSystems Affected: Corporate login portals, victim systems with RMM tools installedOperational Impact: Remote access or malware deployment on victim systemsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials, device fingerprints, geolocation, timestampsSensitivity Of Data: HighData Exfiltration: Yes, to Telegram botsPersonally Identifiable Information: Usernames, passwords, IP addresses, device fingerprints
NOVEMBER 2025
803Before Incident
OCTOBER 2025
802Before Incident
SEPTEMBER 2025
801Before Incident
AUGUST 2025
800Before Incident
JULY 2025
800Before Incident
MAY 2022
790Before Incident
Breach
01 May 2022Wells Fargo
Wells Fargo Bank, N.A.

Wells Fargo Data Breach via Former Employee (2022-2023)

759After Incident
CRITICAL-31
WEL033091825
The Vermont Office of the Attorney General disclosed a data breach at Wells Fargo Bank on September 19, 2024, stemming from unauthorized access to customer personal information by a former employee between May 2022 and March 2023. The breach involved the misuse of internal systems to exfiltrate sensitive data, though the exact number of affected individuals remains undisclosed. The compromised information may include personally identifiable details, exposing customers to potential identity theft, financial fraud, or phishing attacks. The prolonged duration of the breach—nearly a year—suggests systemic vulnerabilities in access controls and post-employment monitoring. While Wells Fargo has not confirmed the scope of the stolen data, the incident underscores risks associated with insider threats and delayed detection. Regulatory scrutiny and customer notifications are expected, with potential reputational damage and legal repercussions for the bank.
INCIDENT DETAILS -
TYPE
Data Breach (Insider Threat)
IMPACT
Data Compromised: Customer Personal InformationIdentity Theft Risk: Potential (PII exposed)
DATA BREACH
Type Of Data Compromised: Personal InformationNumber Of Records Exposed: UnknownSensitivity Of Data: High (PII)
JANUARY 2022
817Before Incident
Breach
31 Dec 2021Wells Fargo
Wells Fargo Bank, N.A.

Wells Fargo Data Breach

786After Incident
HIGH-31
WEL539072925
The California Office of the Attorney General reported a data breach involving Wells Fargo Bank, N.A. on May 5, 2022. The breach occurred on December 31, 2021, when a Wells Fargo employee emailed an encrypted file containing personal information to their personal email address, affecting an unspecified number of individuals. Types of personal information impacted may include names, addresses, phone numbers, email addresses, dates of birth, and social security numbers.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
NamesAddressesPhone NumbersEmail AddressesDates of BirthSocial Security Numbers
DATA BREACH
NamesAddressesPhone NumbersEmail AddressesDates of BirthSocial Security NumbersSensitivity Of Data: HighData Encryption: YesPersonally Identifiable Information: Yes
NOVEMBER 2019
836Before Incident
Breach
06 Nov 2019Wells Fargo
Wells Fargo Bank, N.A.

KDW Automotive Data Breach via Wells Fargo Email Misdelivery

805After Incident
CRITICAL-31
WEL1014090725
On November 6, 2019, Wells Fargo Bank, N.A. discovered a data breach linked to KDW Automotive, where an employee mistakenly sent an email containing sensitive personal information to an unintended financial institution. The exposed data included names and Social Security numbers of affected individuals, potentially putting them at risk of identity theft or fraud. The breach was reported to the California Office of the Attorney General in April 2020, highlighting a lapse in data handling protocols. While the incident did not involve malicious cyber activity, the unauthorized disclosure of personally identifiable information (PII) posed significant privacy concerns. The breach underscored the need for stricter email security measures and employee training to prevent similar errors in the future. No evidence suggested the data was misused, but the exposure alone created reputational and compliance risks for Wells Fargo.
INCIDENT DETAILS -
TYPE
Data Breach (Unintentional Disclosure)
IMPACT
NamesSocial Security NumbersBrand Reputation Impact: Potential (due to exposure of sensitive personal data)Identity Theft Risk: High (due to exposure of SSNs)
DATA BREACH
Personally Identifiable Information (PII)Sensitivity Of Data: High (includes Social Security Numbers)Data Exfiltration: No (unintentional disclosure via email)NamesSocial Security Numbers

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Wells Fargo ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Wells Fargo's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Wells Fargo's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Wells Fargo ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Wells Fargo's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?