Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Zoho

Zoho Vendor Cyber Rating & Cyber Score

zoho.com

Zoho offers beautifully smart software to help you grow your business. With over 100 million users worldwide, Zoho's 55+ products aid your sales and marketing, support and collaboration, finance, and recruitment needs—letting you focus only on your business. Zoho respects user privacy and does not have an ad-revenue model in any part of its business, including its free products. Zoho Corporation is privately held and profitable, with its headquarters in Chennai, India, and offices across the globe.


Zoho A.I CyberSecurity Scoring

Zoho
Company Information
Website:https://www.zoho.com/
Employees number:29,976
Number of followers:2,510,974
NAICS:5112
Industry Type:Software Development
Homepage:zoho.com
Zoho Risk Score (AI oriented)
Between 750 and 799
logo
ZohoSoftware Development
Updated:
18/06/2026
788/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Zoho Global Score (TPRM)
xxxx
logo
ZohoSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Zoho
ZohoFair
Current Score
788Baa (FAIR)
01000
4 incidents
-10 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
791Before Incident
Vulnerability
18 Jun 2026Zoho
Gravity SMTP, Mailjet, Zoho, Amazon SES and Resend: Hackers Exploit WordPress SMTP Plugin With 100,000+ Installs to Steal Sensitive Data

Critical Gravity SMTP WordPress Plugin Flaw Exploited in Mass Attacks

788After Incident
CRITICAL-3
RESZOHSMTMAIGRA1781785979
Critical Gravity SMTP WordPress Plugin Flaw Exploited in Mass Attacks Threat actors are actively exploiting a critical security vulnerability in the Gravity SMTP WordPress plugin, tracked as CVE-2026-4020 (CVSS 5.3), to extract sensitive configuration data from over 100,000 websites. The flaw, affecting all versions up to and including 2.1.4, stems from an improperly secured REST API endpoint (`/wp-json/gravitysmtp/v1/tests/mock-data`) that lacks authentication checks. Unauthenticated attackers can retrieve a 365 KB JSON system report by appending the query parameter `?page=gravitysmtp-settings`, exposing details such as PHP versions, active plugins, database configurations, and API credentials for third-party email services including Amazon SES, Google, Mailjet, Zoho, and Resend. Compromised OAuth tokens and API keys enable attackers to hijack email functionality, impersonate domains, or conduct further reconnaissance-driven attacks. The vulnerability was responsibly disclosed on March 30, 2026, after the vendor released a patched version (2.1.5) on March 17, 2026. Despite its moderate CVSS score, exploitation has surged, with Wordfence blocking over 17 million attack attempts. The most intense activity occurred between June 7–11, 2026, peaking at 4 million blocked requests on June 7 alone. The attack requires only a single unauthenticated HTTP GET request, making it trivial to exploit at scale. Wordfence deployed firewall protections for premium users on May 5, 2026, and extended coverage to free users on June 4, 2026, after observing real-world exploitation exceeding initial severity assessments. Key indicators of compromise (IOCs) include the targeted endpoint (`/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings`) and multiple malicious IP addresses, such as 45.148.10.95 (linked to over 642,000 blocked attempts). Since the flaw does not modify files or inject payloads, evidence of compromise may only appear in web server access logs. Administrators are advised to update to Gravity SMTP 2.1.5 or later and rotate exposed API keys and OAuth tokens immediately. The incident highlights how low-severity vulnerabilities can escalate into high-impact threats when sensitive data is exposed on widely used platforms like WordPress.
INCIDENT DETAILS -
TYPE
Data Exposure
MOTIVATION
Data Exfiltration, Reconnaissance, Email Hijacking
IMPACT
Data Compromised: PHP versions, active plugins, database configurations, API credentials (Amazon SES, Google, Mailjet, Zoho, Resend), OAuth tokensSystems Affected: WordPress websites using Gravity SMTP plugin (versions ≤ 2.1.4)Operational Impact: Potential email service disruption, domain impersonationBrand Reputation Impact: High (due to sensitive data exposure)Identity Theft Risk: High (if PII was exposed via compromised email services)
DATA BREACH
Type Of Data Compromised: Configuration data, API credentials, OAuth tokensSensitivity Of Data: High (API keys, database configs, email service credentials)Data Exfiltration: Yes (365 KB JSON system report)File Types Exposed: JSONPersonally Identifiable Information: Potential (if email services contained PII)
MAY 2026
791Before Incident
APRIL 2026
790Before Incident
MARCH 2026
790Before Incident
FEBRUARY 2026
789Before Incident
JANUARY 2026
788Before Incident
DECEMBER 2025
800Before Incident
Cyber Attack
01 Dec 2025Zoho
Wondershare and Zoho: APT37 Uses Facebook, Telegram, and Trojanzied Installer in New Targeted Cyberattack

APT37 Leverages Facebook, Telegram, and Tampered PDFelement Installer in Targeted Cyber Espionage Campaign

786After Incident
CRITICAL-14
ZOHWON1776076134
APT37 Leverages Facebook, Telegram, and Tampered PDFelement Installer in Targeted Cyber Espionage Campaign North Korea-linked threat group APT37 has launched a sophisticated cyber espionage campaign, abusing Facebook, Telegram, and a trojanized Wondershare PDFelement installer to infiltrate defense-related targets and exfiltrate sensitive data. The operation demonstrates the group’s evolving social engineering tactics and evasion techniques, bypassing traditional signature-based defenses. ### Attack Flow and Tactics The campaign begins with Facebook friend requests from two accounts impersonating individuals in Pyongyang and Pyeongtaek, North Korea, used to identify and vet targets. After establishing trust via one-on-one Messenger chats, the attackers shift conversations to Telegram, claiming to share encrypted military documents that require a "dedicated PDF viewer." Victims receive a password-protected ZIP file (e.g., m.zip) containing: - A fake PDF viewer executable (a modified Wondershare PDFelement installer) - Military-themed decoy PDFs - A Korean-language instructions file with North Korean spelling variations (e.g., "콤퓨터," "프로그람") The tampered installer, named Wondershare_PDFelement_Installer(PDF_Security).exe, mimics the legitimate version but lacks a valid Wondershare digital signature, serving as a key indicator of compromise (IoC). While the installer appears functional, its entry point is hijacked shellcode injected into a code cave redirects execution to malicious routines before resuming normal installation. ### Malicious Execution Chain 1. Shellcode Execution: The injected code resolves APIs via PEB-based hash routines, launches dism.exe in a suspended state, and injects a decrypted payload into its memory using VirtualAllocEx, WriteProcessMemory, and CreateRemoteThread. 2. C2 Communication: The shellcode retrieves a second-stage payload from a Japanese real estate website (disguised as a .jpg file). The response is XOR-encrypted, requiring two decryption passes first validating the payload with a standard x86 function prologue (55 8B), then reconstructing a PE image in memory with stripped MZ/PE headers. 3. RokRAT Backdoor Deployment: The final payload, resembling APT37’s RokRAT malware, conducts system reconnaissance, captures screenshots, and exfiltrates files (DOC, XLS, PDF, HWP, M4A, AMR). It abuses Zoho WorkDrive’s OAuth2 APIs for command-and-control (C2), blending with legitimate traffic using hardcoded client IDs, secrets, and refresh tokens. ### Attribution and Evasion Techniques The campaign aligns with APT37’s known tradecraft, including: - North Korean-language decoys and spelling patterns - Abuse of Zoho WorkDrive for C2 (previously observed in 2025) - Fileless execution and multi-stage XOR encryption - Process injection into signed binaries (dism.exe) to evade detection The group’s tactics tampered installers, cloud-based C2, and image-disguised payloads highlight the limitations of signature-based defenses, emphasizing the need for behavior-based EDR monitoring parent-child process chains, unsigned binaries, and anomalous dism.exe activity. The operation underscores APT37’s continued focus on defense and military targets, leveraging social engineering, legitimate platforms, and stealthy malware delivery to maintain persistence and exfiltrate sensitive data.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Espionage
IMPACT
Data Compromised: Sensitive military documents, system reconnaissance data, screenshots, files (DOC, XLS, PDF, HWP, M4A, AMR)Operational Impact: Data exfiltration, potential compromise of defense-related information
DATA BREACH
Military documentsSystem reconnaissance dataScreenshotsFiles (DOC, XLS, PDF, HWP, M4A, AMR)Sensitivity Of Data: HighDOCXLSPDFHWPM4AAMR
NOVEMBER 2025
800Before Incident
OCTOBER 2025
812Before Incident
Cyber Attack
01 Oct 2025Zoho
Zoho: Hackers Exploit Hidden Microsoft 365 Mailbox Rules to Steal Sensitive Business Emails

Cybercriminals Exploit Microsoft 365 Mailbox Rules for Stealthy Email Theft and Fraud

799After Incident
CRITICAL-13
ZOH1776249079
Cybercriminals Exploit Microsoft 365 Mailbox Rules for Stealthy Email Theft and Fraud Attackers are increasingly leveraging Microsoft 365 mailbox rules to silently exfiltrate emails, suppress security alerts, and maintain persistent access in business email compromise (BEC) campaigns targeting enterprises worldwide. Unlike traditional malware-based attacks, this tactic abuses legitimate Outlook features such as auto-forwarding and message filtering to operate undetected. After gaining initial access via phishing, password spraying, or compromised OAuth tokens, threat actors create malicious mailbox rules to manipulate email flow. These rules automatically delete, forward, or redirect messages to hidden folders like Archive or RSS Subscriptions, allowing attackers to intercept financial communications, block security warnings, or hijack transaction threads without raising suspicion. Victims remain unaware as their inboxes are silently filtered in the background. Security telemetry from Q4 2025 revealed that 10% of compromised Microsoft 365 accounts had malicious mailbox rules created within seconds of a breach, with some deployed in as little as five seconds. Attackers often disguise these rules with innocuous names (e.g., “.”, “..”, or “;”), reflecting automation and confidence that administrators won’t inspect them. Even after password resets, these rules persist unless manually removed, enabling prolonged data theft or fraud. In one case, attackers set up a rule to move emails containing “Payment Receipt” to a hidden folder, then used the same subject line in a phishing campaign to divert verification messages including those from Zoho into an RSS Subscriptions folder. This allowed them to hijack a vendor payment thread, redirecting funds to attacker-controlled accounts without maintaining access to the original mailbox. The tactic has been automated at scale, with tools like ATOLS enabling attackers to deploy malicious rules across multiple accounts in seconds using stolen session tokens or PowerShell scripts. Researchers demonstrated how attackers could exploit Microsoft Graph to create rules immediately upon login, bypassing the need for credentials once tokens are compromised. To mitigate risks, Microsoft 365 administrators are advised to disable external auto-forwarding, enforce multi-factor authentication (MFA) and conditional access policies, and monitor new mailbox rules and OAuth consent changes particularly those with mail-read or write permissions. Without proactive audits, these seemingly harmless productivity tools can serve as invisible backdoors for BEC and espionage.
INCIDENT DETAILS -
TYPE
Business Email Compromise (BEC)
MOTIVATION
Financial fraudData theftEspionage
IMPACT
Data Compromised: Emails containing financial communications, security alerts, and transaction threadsSystems Affected: Microsoft 365 accountsOperational Impact: Persistent unauthorized access to email communicationsRevenue Loss: Potential diversion of funds to attacker-controlled accountsPayment Information Risk: High (payment redirection)
DATA BREACH
Type Of Data Compromised: Emails (financial communications, security alerts, transaction threads)Sensitivity Of Data: High (financial and operational data)Data Exfiltration: Yes (silent email forwarding/redirection)
SEPTEMBER 2025
812Before Incident
AUGUST 2025
812Before Incident
JULY 2025
812Before Incident
MARCH 2025
812Before Incident
Vulnerability
01 Mar 2025Zoho
Zoho

Zoho ADSelfService Plus Authentication Bypass Vulnerability

811After Incident
CRITICAL-1
ZOH411030525
Zoho patched a high-severity vulnerability in its ADSelfService Plus software, resulting in potential risks before remediation. The flaw allowed attackers to bypass authentication, accessing sensitive enrollment data for password management and single sign-on services. This could have led to account takeovers and weakened organizational security. Zoho addressed the issue promptly with a software update, urging users to apply the patch. Although the flaw had a CVSSv3.1 score of 8.1, there were no customer data breaches reported. This incident highlights the importance of maintaining rigorous security measures, such as multi-factor authentication, to safeguard against identity management system compromises.
INCIDENT DETAILS -
TYPE
Vulnerability Exploit
MOTIVATION
Account Takeover, Access Sensitive Data
IMPACT
Systems Affected: ADSelfService Plus softwareOperational Impact: Weakened organizational security

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Zoho ?
?
What was Zoho's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Zoho's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Zoho's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Zoho's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Zoho's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Zoho's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Zoho's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Zoho's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Zoho's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Zoho's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Zoho's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Zoho's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Zoho ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Zoho's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?