Rankiteo Logo
Rankiteo

The Rankiteo MCP server is now available.

Discover MCP
!

Top 25 Worst Companies in United States

Identify the lowest-scoring most renowned companies in United States. Understand where critical cyber risk exposure exists in this country. 1459 companies scored.

10,000
Companies in United States
1459
Scored
738.3
Avg Score
1,036
Cyber Incidents
Bottom 25
Shown

United States Cybersecurity Risk Assessment - Lowest-Scoring Companies in 2026

Out of 10,000 companies in United States monitored by Rankiteo, this page highlights the Bottom 25 organizations with the weakest cybersecurity posture. These rankings are based on our proprietary Cyber Resilience Score, which integrates time-decayed incident exposure, sector-sensitive impact analysis, and market-cap-aware baseline and dampening to produce a single, interpretable score between 100 and 1,000.

Companies at the bottom of this ranking carry the heaviest accumulated cyber incident burden - including recent or severe ransomware attacks, data breaches with significant financial losses or records exposed, and repeated disclosure events. Understanding where these risk concentrations exist is essential for supply chain risk management, regulatory compliance, and competitive benchmarking within United States.

The current average score for the most notable companies in United States is 738.3 out of 1,000. Companies shown below score significantly lower than this average, falling far behind a country that generally maintains reasonable security standards.

Risk Highlights

513
Lowest Score
738.3
Country Average
14%
Scoring B or Below
1,036
Recorded Incidents

Score Distribution

Aaa
0 (0.0%)
Aa
0 (0.0%)
A
44 (3.0%)
Baa
956 (65.5%)
Ba
261 (17.9%)
B
111 (7.6%)
Caa
41 (2.8%)
Ca
20 (1.4%)
C
26 (1.8%)
#CompanyLabelScoreBandIncidentsScore Bar
1
Change Healthcarechangehealthcare.com
Computer Systems Design and Related Services100C18
2
Coupangaboutcoupang.com
Software Publishers100C17
3
DaVita Kidney Caredavita.com
Health Care and Social Assistance100C8
4
Chainalysischainalysis.com
Software Publishers174C2
5
23andMe23andme.com
Others203C7
6
AT&Tatt.com
Telecommunications215C22
7
Coinbasecoinbase.com
Finance and Insurance262C10
8
Comcastcomcast.com
Telecommunications316C17
9
Financial Crimes Enforcement Network, US Treasuryfincen.gov
Public Administration333C2
10
Evolve Bank & Trustgetevolved.com
Finance and Insurance336C4
11
BleepingComputerbleepingcomputer.com
Others356C4
12
Crunchbasecrunchbase.com
Software Publishers435C3
13
Flashpointflashpoint.io
Others447C3
14
Edmundsedmunds.com
Others461C5
15
FEMAfema.gov
Public Administration462C6
16
Colonial Pipeline Companycolpipe.com
Oil and Gas Extraction475C6
17
ESOeso.com
Software Publishers480C2
18
Aflacaflac.com
Insurance Carriers and Related Activities487C7
19
American Hospital Associationaha.org
Health Care and Social Assistance487C3
20
Delaware NorthDelawareNorth.com
Traveler Accommodation492C3
21
DISH TVdish.com
Telecommunications498C2
22
Envoy Airenvoyair.com
Air Transportation499C5
23
Alvaria Incalvaria.com
Software Publishers505C3
24
AmerisourceBergenamerisourcebergen.com
Health Care and Social Assistance507C5
25
Flock Safetyflocksafety.com
Other Justice, Public Order, and Safety Activities513C2

How Cyber Risk Scores Are Calculated

Rankiteo's Cyber Resilience Score produces a single value between 100 and 1,000 for each organization, where higher scores indicate lower estimated cyber risk. The framework integrates three principal components that together balance evidence, context, and comparability across industries and company sizes. Learn more in our AI Cyber Score methodology.

Understanding the Risk Bands

Each score maps to a letter-grade band. Companies appearing in this lowest-scoring ranking typically fall in the bottom bands:

  • Aaa (900-1,000): Exceptional cyber resilience - very few companies in a worst list reach this level.
  • Aa (800-899): Very strong security posture with minimal weaknesses.
  • A (700-799): Strong practices with some areas for improvement.
  • Baa (600-699): Adequate protection but notable security configuration gaps exist.
  • Ba (500-599): Below average - multiple risk areas require attention.
  • B (400-499): Weak security with significant exposure across categories.
  • Caa (300-399): Very weak with a high probability of exploitable vulnerabilities.
  • Ca (200-299): Critically poor with severe, widespread security gaps.
  • C (0-199): Extreme risk - immediate remediation is needed across all dimensions.

Why Monitoring Low-Scoring Companies in United States Matters

Cybersecurity risk doesn't exist in isolation. If your organization works with, purchases from, or shares data with companies in United States, their security weaknesses become your risk. Supply chain attacks - where adversaries compromise a less-secure vendor to reach a larger target - have become one of the most common and damaging attack vectors in recent years.

Rankiteo continuously monitors 10,000 companies in United States, keeping these rankings up to date so you always have an accurate, current picture of the country's risk landscape.

Top 25 Worst Companies in United States by Cybersecurity Score (2026) | Rankiteo