Company Details
rheinmetall
13,148
405,989
336414
rheinmetall.com
0
RHE_3248244
In-progress

Rheinmetall Company CyberSecurity Posture
rheinmetall.comAs an integrated technology group, the listed company Rheinmetall AG, headquartered in Düsseldorf, stands for a company that is as strong in substance as it is successful internationally, and that is active in various markets with an innovative range of products and services. Rheinmetall is a leading international systems supplier in the defence industry and at the same time a driver of forward-looking technological and industrial innovations in the civilian markets. The focus on sustainability is an integral part of Rheinmetall's strategy. The company aims to achieve CO2 neutrality by 2035. Through our work in various fields, we at Rheinmetall take on responsibility in a dramatically changing world. With our technologies, products and systems, we create the indispensable basis for peace, freedom and sustainable development: security. Find more Information about your career opportunities here: https://www.rheinmetall.com/en/rheinmetall_ag/career_1/index.php IMPRINT AND DATA PROTECTION https://www.rheinmetall.com/en/rheinmetall_ag/service/imprint/index.php
Company Details
rheinmetall
13,148
405,989
336414
rheinmetall.com
0
RHE_3248244
In-progress
Between 750 and 799

Rheinmetall Global Score (TPRM)XXXX

Description: An extensive cyberattack on the arms company Rheinmetall was mostly unharmed. Previously unidentified attackers targeted the company's IT systems in an attempt to collapse them. Only the organization website, which an outside service provider runs, was momentarily down, according to a group representative. There is no evidence that a potential leak may have an impact on the internal Rheinmetall IT system. As the business is providing, among other things, armored personnel carriers to Ukraine to stave off the Russian onslaught, experts predict that Rheinmetall is the target of Russian hackers who are on the Internet.
Description: Hackers have assaulted Rheinmetall, a producer of munitions and vehicles. Only civilian business, according to the corporation, is impacted. On its leak-site, the BlackBasta ransomware organisation has already taken responsibility for the attack. The business claimed that the attack had no impact on the arms division's output, but the German media is reporting that the attack was not confined to a single subsidiary. Given that the investigation was still in progress, they were unable to disclose information regarding the attack's severity.


No incidents recorded for Rheinmetall in 2025.
No incidents recorded for Rheinmetall in 2025.
No incidents recorded for Rheinmetall in 2025.
Rheinmetall cyber incidents detection timeline including parent company and subsidiaries

As an integrated technology group, the listed company Rheinmetall AG, headquartered in Düsseldorf, stands for a company that is as strong in substance as it is successful internationally, and that is active in various markets with an innovative range of products and services. Rheinmetall is a leading international systems supplier in the defence industry and at the same time a driver of forward-looking technological and industrial innovations in the civilian markets. The focus on sustainability is an integral part of Rheinmetall's strategy. The company aims to achieve CO2 neutrality by 2035. Through our work in various fields, we at Rheinmetall take on responsibility in a dramatically changing world. With our technologies, products and systems, we create the indispensable basis for peace, freedom and sustainable development: security. Find more Information about your career opportunities here: https://www.rheinmetall.com/en/rheinmetall_ag/career_1/index.php IMPRINT AND DATA PROTECTION https://www.rheinmetall.com/en/rheinmetall_ag/service/imprint/index.php

At BAE Systems, we help our customers to stay a step ahead when protecting people and national security, critical infrastructure and vital information. We provide some of the world’s most advanced, technology-led defence, aerospace and security solutions and employ a skilled workforce of 107,000 peo
As a leading defence and security company, we offer solutions that range from the depths of the oceans to high in the sky, on land and in cyberspace, to keep people and society safe. Empowered by our 22,000 talented people, we constantly push the boundaries of technology to create a safer, more sus

We protect the security, independence and interests of the United Kingdom at home and abroad. We work with our allies and partners whenever possible. Our aim is to ensure that the UK’s Armed Forces have the training, equipment and support necessary for their work, and that we keep within budget.

The freedom to explore. The promise to deliver. General Atomics, based in San Diego, CA, develops advanced technology solutions for government and commercial applications. Privately owned and vertically integrated, we have the freedom to invest in the most innovative technologies, and the resource

The Indian Army is the largest branch of the Indian Armed Forces and is responsible for land-based military operations. Its primary mission is the National Security and Defense of India from external aggression and threats, and maintaining peace and security within its borders. It also conducts huma

Leidos is a Fortune 500® innovation company rapidly addressing the world’s most vexing challenges in national security and health. The company's global workforce of 48,000 collaborates to create smarter technology solutions for customers in heavily regulated industries. Headquartered in Reston, Virg

The Republic of Korea Air Force (ROKAF; Korean: 대한민국 공군; Hanja: 大韓民國 空軍; Revised Romanization: Daehanminguk Gong-gun), also known as the ROK Air Force, is the aerial warfare service branch of South Korea, operating under the South Korean Ministry of National Defense. The ROKAF has about 450 combat

Leonardo is a global security company that realises multi-domain technological capabilities in AD&S. With over 53,000 employees worldwide, the company has a significant industrial presence in Italy, the UK, Poland, and the US. It also has a commercial presence in 150 countries through subsidiaries

From Gulfstream business jets and combat vehicles to nuclear-powered submarines and communications systems, people around the world depend on our products and services for their safety and security. General Dynamics is headquartered in Reston, Virginia, and employs over 100,000 people in 43 countri
.png)
CrowdStrike Holdings, Inc. (NASDAQ: CRWD) heads into Monday's session near record territory, with investors weighing fresh partnerships,...
Under the contract, the companies will deliver 21 tracked armoured vehicles, including five Rheinmetall Lynx KF-41 models equipped with the...
Asia's leading tri-service defense and internal security exhibition will take place from 10–13 November 2025 at the IMPACT Exhibition and...
American Rheinmetall and GM Defense presented the HX3 Common Tactical Truck at AUSA 2025, a modular platform for the U.S. Army's logistics...
Latvia's State Defence Corporation has signed a Memorandum of Understanding with German arms and ammunition giant Rheinmetall to jointly...
Sabotage, data theft and espionage are affecting more and more companies in Germany, costing them billions in damages every year and...
"Nimbus Manticore" is back at it, this time with improved variants of its flagship malware and targets that are outside its usual focus...
FTI Consulting appoints André Reichow-Prehn as Senior Managing Director in German Cybersecurity practice. Former Unit 42 Managing Partner...
American Rheinmetall will invest $31.7 million and create 450 new jobs with an expansion of its Michigan operations.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Rheinmetall is http://www.rheinmetall.com/career.
According to Rankiteo, Rheinmetall’s AI-generated cybersecurity score is 782, reflecting their Fair security posture.
According to Rankiteo, Rheinmetall currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Rheinmetall is not certified under SOC 2 Type 1.
According to Rankiteo, Rheinmetall does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Rheinmetall is not listed as GDPR compliant.
According to Rankiteo, Rheinmetall does not currently maintain PCI DSS compliance.
According to Rankiteo, Rheinmetall is not compliant with HIPAA regulations.
According to Rankiteo,Rheinmetall is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Rheinmetall operates primarily in the Defense and Space Manufacturing industry.
Rheinmetall employs approximately 13,148 people worldwide.
Rheinmetall presently has no subsidiaries across any sectors.
Rheinmetall’s official LinkedIn profile has approximately 405,989 followers.
Rheinmetall is classified under the NAICS code 336414, which corresponds to Guided Missile and Space Vehicle Manufacturing.
Yes, Rheinmetall has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/rheinmetall.
Yes, Rheinmetall maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/rheinmetall.
As of December 11, 2025, Rankiteo reports that Rheinmetall has experienced 2 cybersecurity incidents.
Rheinmetall has an estimated 2,330 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware and Cyber Attack.
Title: Rheinmetall Cyber Attack
Description: Hackers have assaulted Rheinmetall, a producer of munitions and vehicles. Only civilian business, according to the corporation, is impacted. The attack had no impact on the arms division's output, but the German media is reporting that the attack was not confined to a single subsidiary.
Type: Ransomware
Threat Actor: BlackBasta ransomware organisation
Title: Cyberattack on Rheinmetall
Description: An extensive cyberattack on the arms company Rheinmetall was mostly unharmed. Previously unidentified attackers targeted the company's IT systems in an attempt to collapse them. Only the organization website, which an outside service provider runs, was momentarily down. There is no evidence that a potential leak may have an impact on the internal Rheinmetall IT system. As the business is providing, among other things, armored personnel carriers to Ukraine to stave off the Russian onslaught, experts predict that Rheinmetall is the target of Russian hackers who are on the Internet.
Type: Cyberattack
Threat Actor: Russian hackers
Motivation: Political
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Systems Affected: Organization website
Downtime: ['Momentary downtime of the website']

Entity Name: Rheinmetall
Entity Type: Corporation
Industry: Munitions, Vehicles

Ransomware Strain: BlackBasta

Investigation Status: Ongoing
Last Attacking Group: The attacking group in the last incident were an BlackBasta ransomware organisation and Russian hackers.
Most Significant System Affected: The most significant system affected in an incident was Organization website.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.