Xerox A.I CyberSecurity Scoring
Xerox
Company Information
Website:http://www.xerox.com
Employees number:54,786
Number of followers:957,005
NAICS:5416
Industry Type:Business Consulting and Services
Homepage:xerox.com
Xerox Risk Score (AI oriented)
Between 550 and 599
XeroxBusiness Consulting and Services
Updated:
19/06/2026
19/06/2026
578/1000
Very Poor
Ca
Xerox Global Score (TPRM)
xxxx
XeroxBusiness Consulting and Services
Score locked

XeroxVery Poor
Current Score
578Ca (VERY POOR)
01000
3 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
584
JULY 2026
581
JUNE 2026
577
MAY 2026
575
APRIL 2026
572
MARCH 2026
567
FEBRUARY 2026
563
JANUARY 2026
557
DECEMBER 2025
551
NOVEMBER 2025
549
OCTOBER 2025
544
SEPTEMBER 2025
539
JANUARY 2024
565
Ransomware
01 Jan 2024 • Xerox
Xerox and Texas State Bar: INC Ransomware Uses Double Extortion and Printer Ransom Notes to Pressure Victims
INC Ransomware Emerges as a Dominant Threat, Targeting 800+ Victims Since 2023
394
CRITICAL-171
XERTEX1781864792
INC Ransomware Emerges as a Dominant Threat, Targeting 800+ Victims Since 2023
INC ransomware has rapidly evolved into one of the most active ransomware families of 2026, compromising over 800 organizations since 2023. The group has capitalized on disruptions among competitors, expanding its affiliate network while refining its tactics, techniques, and procedures (TTPs).
### Technical Sophistication & Attack Methods
INC’s toolset has undergone significant modernization, with both Windows and Linux/ESXi encryptors rewritten in Rust for cross-platform efficiency and obfuscation. Key features include:
- Hybrid cryptography using Curve25519-derived keys and AES/Salsa20 for file encryption, appending a .INC extension and a distinct footer signature.
- Operator-driven execution, with command-line arguments for granular control, threadpool scaling (CPU cores × 4), and adjustable encryption speeds (fast, medium, slow).
- Linux/ESXi-specific routines that enumerate and shut down VMs via `vim-cmd`, maximizing disruption in virtualized environments.
Initial access vectors include spear-phishing, purchased credentials, and exploitation of public-facing vulnerabilities (e.g., Citrix, Fortinet CVEs, SimpleHelp RMM flaws). Lateral movement relies on native tools (RDP, PsExec), Angry IP Scanner, and commercial RMM solutions.
### Double Extortion & Psychological Pressure
INC employs double extortion, exfiltrating data via 7-Zip and rclone before encryption. The group’s pressure tactics include:
- Automated network printing of ransom notes, ensuring physical visibility of demands.
- Dual-site infrastructure: a private negotiation portal and a public leak site for publishing stolen data.
- Credential dumping from Veeam backups using a modified `Veeam-Get-Creds.ps1` script, targeting salted DPAPI encryption to disable recovery options.
### Victimology & Sector Targeting
INC primarily targets U.S.-based organizations (65%+ of victims), with notable breaches including NHS Scotland, Xerox, and the Texas State Bar. Preferred sectors include:
- Legal services
- Manufacturing
- Technology
- Healthcare
- Construction
### Ecosystem Proliferation
Following a 2024 source-code leak, INC’s techniques have spread to related ransomware families like Lynx and Sinobi, amplifying its impact across the threat landscape.
### Indicators of Compromise (IOCs)
Acronis Threat Research Unit (TRU) has identified multiple Windows (PE64) and Linux (ELF64) samples, including:
- Windows hashes: `31800380c359143ae82c4f9011eee653dd22443d...`
- Linux hashes: `589d9480fbfec2d8e61638eb0b537183d0f99774...`
The group’s evolution underscores its adaptability, combining technical refinement with aggressive extortion tactics to maximize impact.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2023
637
Breach
10 Dec 2023 • Xerox
Xerox Corporation
Xerox Corporation Data Breach
558
CRITICAL-79
XER336072725
The Maine Office of the Attorney General reported that Xerox Corporation experienced a data breach on December 10, 2023, due to an external system breach (hacking), affecting 181 individuals in total, including 1 resident. The breached information included personal details such as Social Security numbers, and the company is providing 24 months of identity and credit monitoring services through Experian.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2023
748
Ransomware
01 Nov 2023 • Xerox
Yamaha Motor and Xerox Business Solutions: INC ransomware opsec fail allowed data recovery for 12 US orgs
INC Ransomware Gang’s Security Failure Exposes Stolen Data from 12 U.S. Organizations
635
CRITICAL-113
YAMXER1769102615
INC Ransomware Gang’s Security Failure Exposes Stolen Data from 12 U.S. Organizations
In a significant operational security lapse, researchers at Cyber Centaurs, a digital forensics and incident response firm, uncovered data exfiltrated by the INC ransomware gang from 12 U.S. organizations across healthcare, manufacturing, technology, and service sectors. The discovery stemmed from an investigation into a ransomware attack on a U.S. client in November 2023, where the RainINC variant was deployed via the PerfLogs directory a Windows-created folder increasingly abused by threat actors for staging.
During the forensic analysis, researchers identified remnants of the legitimate backup tool Restic, which the INC gang had used in previous attacks but not in the current incident. This led to a shift in focus toward the gang’s infrastructure, where hardcoded credentials, PowerShell scripts (including a Base64-encoded ‘new.ps1’ file), and backup commands revealed a pattern of long-term data retention. The gang had reused Restic-based storage repositories across multiple campaigns, leaving encrypted victim data accessible even after ransom negotiations concluded.
Cyber Centaurs developed a non-destructive enumeration process to validate their hypothesis, confirming the presence of stolen data from unrelated organizations none of which were their clients. After decrypting the backups, the team preserved copies and coordinated with law enforcement to verify ownership and ensure proper handling.
The investigation also exposed the gang’s broader toolkit, which included cleanup utilities, remote access software, and network scanners. To aid defenders, Cyber Centaurs released YARA and Sigma rules to detect Restic or its renamed variants in suspicious locations, potentially flagging early-stage ransomware activity.
INC ransomware, a ransomware-as-a-service (RaaS) operation active since mid-2023, has targeted high-profile victims, including Yamaha Motor, Xerox Business Solutions, Scotland’s NHS, McLaren Health Care, and the Texas State Bar. This breach highlights the risks of reused attacker infrastructure and the potential for recovering stolen data even after an attack concludes.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Xerox ??
What was Xerox's A.I Rankiteo Cyber Score in July 2026 ??
What was Xerox's A.I Rankiteo Cyber Score in June 2026 ??
What was Xerox's A.I Rankiteo Cyber Score in May 2026 ??
What was Xerox's A.I Rankiteo Cyber Score in April 2026 ??
What was Xerox's A.I Rankiteo Cyber Score in March 2026 ??
What was Xerox's A.I Rankiteo Cyber Score in February 2026 ??
What was Xerox's A.I Rankiteo Cyber Score in January 2026 ??
What was Xerox's A.I Rankiteo Cyber Score in December 2025 ??
What was Xerox's A.I Rankiteo Cyber Score in November 2025 ??
What was Xerox's A.I Rankiteo Cyber Score in October 2025 ??
What was Xerox's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Xerox's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Xerox ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Xerox's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?