Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Sermo

Sermo Vendor Cyber Rating & Cyber Score

sermo.com

Sermo turns physician experience, expertise, and observations into actionable insights for the global healthcare community. Engaging with more than 1 million HCPs across 150 countries, we provide physicians with a social platform and unique community that fosters impactful peer-to-peer collaboration & discussions about issues that are important to them and their patients. Sermo offers on demand access to physicians via a suite of proprietary technology to provide business intelligence that benefits patients, pharmaceutical, healthcare partners and the medical community at large. Doctors and other HCPs can sign up today at https://sermo.link/sign-up-li


Sermo A.I CyberSecurity Scoring

Sermo
Company Information
Website:http://www.sermo.com
Employees number:637
Number of followers:15,141
NAICS:5112
Industry Type:Software Development
Homepage:sermo.com
Sermo Risk Score (AI oriented)
Between 0 and 549
logo
SermoSoftware Development
Updated:
22/02/2026
525/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Sermo Global Score (TPRM)
xxxx
logo
SermoSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Sermo
SermoCritical
Current Score
525C (CRITICAL)
01000
2 incidents
-146 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
553Before Incident
JUNE 2026
549Before Incident
MAY 2026
543Before Incident
APRIL 2026
538Before Incident
MARCH 2026
533Before Incident
FEBRUARY 2026
669Before Incident
Ransomware
10 Feb 2026Sermo
Sermo: Sermo Data Breach Investigation

Sermo Data Breach Following Ransomware Attack

523After Incident
CRITICAL-146
WOR1770840127
Sermo Reports Data Breach Following Ransomware Attack in Denmark Sermo, a healthcare-focused platform, disclosed a data breach after a ransomware attack disrupted operations at its Denmark-based data center. The incident began on April 10, 2024, when a power outage was later identified as a ransomware event, prompting an internal investigation. The company confirmed that an unauthorized third party may have accessed and exfiltrated sensitive personal data between March 19 and April 10, 2024. Exposed information includes names and Social Security numbers, though the exact details vary by individual. On February 9, 2026, Sermo began notifying affected individuals via mail, providing specifics on the compromised data and offering complimentary credit monitoring services. The breach notice was filed with the Attorney General of Maine, where details of the incident are publicly available.
INCIDENT DETAILS -
TYPE
Ransomware
IMPACT
Data Compromised: Names and Social Security numbersOperational Impact: Disrupted operations at Denmark-based data centerIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personal dataSensitivity Of Data: High (Social Security numbers)Data Exfiltration: YesPersonally Identifiable Information: Names, Social Security numbers
JANUARY 2026
668Before Incident
DECEMBER 2025
666Before Incident
NOVEMBER 2025
665Before Incident
OCTOBER 2025
663Before Incident
SEPTEMBER 2025
661Before Incident
AUGUST 2025
659Before Incident
MARCH 2024
756Before Incident
Ransomware
19 Mar 2024Sermo
Sermo: Social network for doctors Sermo breached by ransomware attack

Sermo Data Breach Exposes 2,674 Individuals to SSN Leak in March 2024 Ransomware Attack

620After Incident
CRITICAL-136
WOR1770746319
Sermo Data Breach Exposes 2,674 Individuals to SSN Leak in March 2024 Ransomware Attack Sermo, a social network for physicians, confirmed a March 2024 data breach affecting 2,674 individuals after their Social Security numbers were exposed. The ransomware group Black Basta claimed responsibility for the attack in April 2024, alleging it stole 700 GB of data from the company. A second group, Medusa, later asserted it had also breached Sermo in July 2025, demanding a $500,000 ransom though Sermo did not acknowledge this claim. According to Sermo’s breach notice, the incident began with a power outage at its Denmark data center on April 10, 2024, later identified as a ransomware attack. Unauthorized access occurred between March 19 and April 10, 2024, with Black Basta posting stolen data on its leak site on April 17, 2024. Delays in disclosure were attributed to difficulties retrieving the data, as Black Basta’s site was slow and unstable Sermo only completed the download in September 2024 after months of failed attempts. The group’s leak site was taken down on January 27, 2025, removing public access to the stolen data. As a response, Sermo is offering affected individuals 12 months of free credit monitoring and identity theft restoration through Kroll. Black Basta, a ransomware-as-a-service (RaaS) operation active since early 2022, was known for double extortion demanding payment both to decrypt systems and to prevent data leaks. The group was disrupted by law enforcement in 2025, though some of its breaches, like Sermo’s, are only now coming to light. Prior to its shutdown, Black Basta claimed 173 confirmed attacks since 2022, exposing nearly 12 million people’s data. Other major healthcare-related breaches included Ascension (5.6 million affected) and Numotion (700,000 affected). The incident reflects broader risks in the healthcare sector, where ransomware attacks can disrupt critical systems and expose sensitive patient data. In 2024, researchers tracked 32 confirmed ransomware attacks on healthcare-related businesses, compromising over 196 million records. While 2025 saw fewer incidents (27 attacks), they still exposed 5.9 million individuals’ data. Recent examples include MedRevenu (December 2024, BianLian) and MTI America (September 2025, Sinobi). Sermo, which serves over 1 million verified physicians, facilitates medical discussions, drug ratings, and paid surveys. The breach underscores the persistent threat ransomware poses to healthcare infrastructure and patient privacy.
INCIDENT DETAILS -
TYPE
Ransomware Attack
MOTIVATION
Financial gainData exfiltration
IMPACT
Data Compromised: 700 GBOperational Impact: Disrupted data center operationsBrand Reputation Impact: YesIdentity Theft Risk: Yes (SSN exposure)
DATA BREACH
Social Security numbersPersonally identifiable informationNumber Of Records Exposed: 2,674 individualsSensitivity Of Data: High (SSN, medical discussions)Data Exfiltration: Yes (700 GB)Data Encryption: Yes (ransomware encryption)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Sermo ?
?
What was Sermo's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Sermo's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Sermo's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Sermo's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Sermo's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Sermo's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Sermo's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Sermo's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Sermo's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Sermo's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Sermo's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on Sermo's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Sermo ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Sermo's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?