Western Digital A.I CyberSecurity Scoring
Western Digital
Company Information
Website:https://www.westerndigital.com
Employees number:22,591
Number of followers:805,765
NAICS:3341
Industry Type:Computer Hardware Manufacturing
Homepage:westerndigital.com
Western Digital Risk Score (AI oriented)
Between 750 and 799
Western DigitalComputer Hardware Manufacturing
Updated:
03/04/2026
03/04/2026
773/1000
Fair
Baa
Western Digital Global Score (TPRM)
xxxx
Western DigitalComputer Hardware Manufacturing
Score locked

Western DigitalFair
Current Score
773Baa (FAIR)
01000
4 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
791
MAY 2026
788
APRIL 2026
782
MARCH 2026
781
FEBRUARY 2026
770
JANUARY 2026
770
DECEMBER 2025
754
NOVEMBER 2025
753
OCTOBER 2025
752
SEPTEMBER 2025
753
Vulnerability
23 Sep 2025 • Western Digital
Western Digital
Western Digital My Cloud NAS Critical OS Command Injection Vulnerability (CVE-2025-30247)
750
CRITICAL-3
WES5892358093025
Western Digital disclosed a critical OS command injection vulnerability (CVE-2025-30247) in multiple My Cloud NAS models, including PR2100, PR4100, EX4100, EX2 Ultra, Mirror Gen 2, DL2100, EX2100, DL4100, and WDBCTLxxxxxx-10. The flaw allows remote attackers to execute arbitrary system commands via crafted HTTP POST requests, potentially leading to unauthorized file access, modification, deletion, user enumeration, or binary execution. While primarily affecting small businesses, home offices, and consumers, exploitation could enable data theft, botnet recruitment, proxy misuse, or ransomware deployment. Two models (DL4100 and DL2100) are end-of-support (EoS), leaving them unpatched. Users are urged to update to firmware 5.31.108 immediately or disconnect devices until patched. Automatic updates were rolled out on September 23, 2025, but manual updates are also available. Failure to patch risks severe compromise of stored data, including potential lateral movement into connected networks or ransomware attacks targeting backups and sensitive files.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
AUGUST 2025
752
JULY 2025
751
JUNE 2025
752
Vulnerability
16 Jun 2025 • Western Digital
Western Digital
Critical Remote Code Execution Vulnerability in Western Digital My Cloud NAS Devices (CVE-2025-30247)
749
CRITICAL-3
WES5632056093025
Western Digital disclosed a critical remote code execution (RCE) vulnerability (CVE-2025-30247) in the firmware of its My Cloud NAS devices, affecting models like My Cloud PR2100, PR4100, EX2 Ultra, and others running firmware versions prior to v5.31.108. The flaw, an OS command injection in the user interface, allows unauthenticated attackers to execute arbitrary system commands via a crafted HTTP POST request without user interaction.A successful exploit grants full system control, enabling attackers to access, encrypt, delete, or modify all stored data, including backups, project files, and sensitive documents. The compromised device could also serve as a launchpad for lateral movement within the same network, risking further breaches of connected systems.While no in-the-wild exploitation has been reported, the vulnerability poses a severe risk to home and small business users relying on these devices for storage and backups. Western Digital urged immediate firmware updates, with automatic updates already applied to connected devices. Failure to patch could lead to data loss, ransomware deployment, or network-wide compromise if exploited by threat actors.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MAY 2023
750
Breach
01 May 2023 • Western Digital
Western Digital
Western Digital Data Breach
711
CRITICAL-39
WES04621023
Customers of Western Digital are being informed of a data breach that exposed their private information.
It stopped a number of its services in response to the incident.
The business acknowledged that various systems had been compromised by an unauthorised individual.
To confirm that threat actors stole sensitive personal information in the March attack, the organisation is notifying customers of data breaches through letters.
According to the corporation, they are collaborating with law enforcement to examine the full scope of the occurrence with the help of renowned forensic and security specialists.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2023
817
Ransomware
01 Apr 2023 • Western Digital
Western Digital
Western Digital Ransomware Attack
749
HIGH-68
WES233828523
Western Digital experienced a ransomware assault, and as a result, it had to suspend some of its services.
The company acknowledged that various systems had been compromised by an unauthorised individual.
My Cloud, My Cloud Home, My Cloud Home Duo, My Cloud OS5, SanDisk ibi, and SanDisk Ixpand Wireless Charger were all impacted by a service outage encountered by Western Digital.
Customer names, shipping and billing addresses, phone numbers, and email addresses were among the information that was exposed. Customer passwords that had been hashed or salted as well as a portion of their credit card details were found in the hacked database, the company noted.
Customers of Western Digital are advised to exercise caution when responding to unsolicited mailings that request personal information from them or direct them to a website that does the same.
Customers are advised against opening attachments or clicking on links in shady communications.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Western Digital ??
What was Western Digital's A.I Rankiteo Cyber Score in May 2026 ??
What was Western Digital's A.I Rankiteo Cyber Score in April 2026 ??
What was Western Digital's A.I Rankiteo Cyber Score in March 2026 ??
What was Western Digital's A.I Rankiteo Cyber Score in February 2026 ??
What was Western Digital's A.I Rankiteo Cyber Score in January 2026 ??
What was Western Digital's A.I Rankiteo Cyber Score in December 2025 ??
What was Western Digital's A.I Rankiteo Cyber Score in November 2025 ??
What was Western Digital's A.I Rankiteo Cyber Score in October 2025 ??
What was Western Digital's A.I Rankiteo Cyber Score in September 2025 ??
What was Western Digital's A.I Rankiteo Cyber Score in August 2025 ??
What was Western Digital's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Western Digital's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Western Digital ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Western Digital's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?