Company Details
bbva
119,358
1,277,310
52211
bbva.com
202
BBV_2673420
Completed

BBVA Company CyberSecurity Posture
bbva.comAt BBVA we are leading the transformation of banking worldwide, united in pursuing our goal of bringing the age of opportunity to everyone. Firmly focused on the future, our on-going digital transformation is already producing disruptive innovations that power our vision of banking. Every one of our 121,486 employees, from branch staff to senior leaders, plays an essential role in giving our 71.5 million customers the cutting edge banking solutions that they deserve. Building on 166 years of history we know the importance of constant development, which is why we place so much confidence in the collaborative working environment that enables our people to grow and excel. If you would like to learn about the culture and opportunities on offer at a company that is leading the way for 21st century banking, head to the ‘Life’ tab to find out more.
Company Details
bbva
119,358
1,277,310
52211
bbva.com
202
BBV_2673420
Completed
Between 800 and 849

BBVA Global Score (TPRM)XXXX



No incidents recorded for BBVA in 2025.
No incidents recorded for BBVA in 2025.
No incidents recorded for BBVA in 2025.
BBVA cyber incidents detection timeline including parent company and subsidiaries

At BBVA we are leading the transformation of banking worldwide, united in pursuing our goal of bringing the age of opportunity to everyone. Firmly focused on the future, our on-going digital transformation is already producing disruptive innovations that power our vision of banking. Every one of our 121,486 employees, from branch staff to senior leaders, plays an essential role in giving our 71.5 million customers the cutting edge banking solutions that they deserve. Building on 166 years of history we know the importance of constant development, which is why we place so much confidence in the collaborative working environment that enables our people to grow and excel. If you would like to learn about the culture and opportunities on offer at a company that is leading the way for 21st century banking, head to the ‘Life’ tab to find out more.


Akbank was founded as a local bank in Adana in January 1948. Established originally with the core objective to provide funding to local cotton producers, the Bank opened its first branch in the Sirkeci district of Istanbul on July 14, 1950. In 1954, after relocating its Head Office to Istanbul, the

Utkarsh Small Finance Bank Limited (USFBL), incorporated on April 30, 2016, is engaged in providing banking and financial services with a focus on the underserved and unserved sections of the country. The Bank’s lending activities are primarily focussed in rural and semi-urban locations of the count
Widely known for customer centricity, Canara Bank was founded by Shri Ammembal Subba Rao Pai, a great visionary and philanthropist, in July 1906, at Mangalore, then a small port in Karnataka. The Bank has gone through the various phases of its growth trajectory over hundred years of its existence. G

Somos el banco peruano que desde hace más de 130 años viene liderando el sistema financiero a nivel nacional. A lo largo de todo este tiempo hemos contribuido con el desarrollo económico de nuestro país, transformando planes en realidad. Todo esto es posible gracias al equipo de profesionales de p
ANZ has a proud heritage of more than 180 years. Our purpose is to shape a world where people and communities thrive. That is why we strive to create a balanced, sustainable economy in which everyone can take part and build a better life. We employ more than 50,000 people and have our global headq

O Bradesco é um dos líderes do setor financeiro privado e um dos maiores empregadores na categoria. Além disso, apresenta o melhor índice de eficiência entre os bancos de varejo. Nossa missão é fornecer soluções, produtos e serviços financeiros e de seguros com agilidade e competência, principal

Welcome to Huntington. Huntington Bancshares Incorporated is a $210 billion asset regional bank holding company headquartered in Columbus, Ohio. Founded in 1866, The Huntington National Bank and its affiliates provide consumers, small and middle-market businesses, corporations, municipalities, and

For over 200 years, BNP Paribas Fortis has helped drive the growth and prosperity of Belgium’s economy and communities. The mission of our 12,000 colleagues is clear: be the trusted financial partner for four million individual customers, businesses and organisations. We do this by offering advice a
We are a universal bank with a 200-year history of supporting and growing the Nordic economies – enabling dreams and aspirations for a greater good. Every day, we work to support our customers’ financial development, delivering best-in-class omnichannel customer experiences and driving sustainable c
.png)
Indra eyes a cybersecurity alliance with Leonardo, BBVA gains ground in its bid for Sabadell, and top Spanish stocks face fresh analyst moves and executive...
by Alberto Sagrado Amador, Clara Calonge Briega, Héctor Reguera, Javier Morillas, and Juan Luis Aranda on 06 OCT 2025 in Amazon AppStream 2.0,...
This breach exposed 570GB of data from 28000 repositories, affecting 800+ organizations. Crimson Collective leaked Customer Engagement...
A powerful ally · AI-driven risk analysis is more accurate. · AI reduces fraud by up to 90 percent with mechanisms such as user authentication:...
BBVA's AI strategy fuses cloud infrastructure, personalized fintech, and governance to dominate global banking through trusted,...
BBVA has merged its two existing group companies Beeva, specialising in cloud computing and big data, and i4S, which focuses on cybersecurity, into BBVA Next...
Garanti BBVA, one of Türkiye's leading banks with its investments in technology, has once again earned Tier IV Certification of Operational Sustainability –...
BBVA has set a target of reaching 20000 tech employees in 2025, with 1100 new hires in advanced technical roles up for grabs.
Spanish bank BBVA has completed the migration of its data platform to Amazon Web Services (AWS) across its European operations.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of BBVA is https://www.bbva.com/es/empleo/.
According to Rankiteo, BBVA’s AI-generated cybersecurity score is 827, reflecting their Good security posture.
According to Rankiteo, BBVA currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, BBVA is not certified under SOC 2 Type 1.
According to Rankiteo, BBVA does not hold a SOC 2 Type 2 certification.
According to Rankiteo, BBVA is not listed as GDPR compliant.
According to Rankiteo, BBVA does not currently maintain PCI DSS compliance.
According to Rankiteo, BBVA is not compliant with HIPAA regulations.
According to Rankiteo,BBVA is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
BBVA operates primarily in the Banking industry.
BBVA employs approximately 119,358 people worldwide.
BBVA presently has no subsidiaries across any sectors.
BBVA’s official LinkedIn profile has approximately 1,277,310 followers.
BBVA is classified under the NAICS code 52211, which corresponds to Commercial Banking.
No, BBVA does not have a profile on Crunchbase.
Yes, BBVA maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/bbva.
As of December 11, 2025, Rankiteo reports that BBVA has not experienced any cybersecurity incidents.
BBVA has an estimated 6,988 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, BBVA has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.