Company Details
surf-air-mobility
60
3,911
481
surfair.com
0
SUR_1124118
In-progress

Surf Air Mobility Company CyberSecurity Posture
surfair.comTransforming air mobility through software and electrification.
Company Details
surf-air-mobility
60
3,911
481
surfair.com
0
SUR_1124118
In-progress
Between 700 and 749

SAM Global Score (TPRM)XXXX



No incidents recorded for Surf Air Mobility in 2025.
No incidents recorded for Surf Air Mobility in 2025.
No incidents recorded for Surf Air Mobility in 2025.
SAM cyber incidents detection timeline including parent company and subsidiaries

Transforming air mobility through software and electrification.


As a global airline and the UK’s flag carrier, British Airways has been flying its customers to where they need to be for more than 100 years. The airline connects Britain with the world and the world with Britain, operating one of the most extensive international scheduled airline route networks to
How time flies. #18YearsOfIndiGo IndiGo is India’s largest passenger airline. We primarily operate in India’s domestic air travel market as a low-cost carrier with focus on our three pillars – offering low fares, being on-time and delivering a courteous and hassle-free experience. IndiGo has become
Lufthansa is one of the world’s leading airlines, connecting passengers to over 200 destinations across 74 countries from our hubs in Frankfurt and Munich. As an industry pioneer, we are committed to shaping the future of sustainable aviation, investing in next-generation aircraft, cutting-edge tec
Grupo Aeromexico, S.A.B. de C.V. is a holding company whose subsidiaries are engaged in commercial aviation and the promotion of passenger loyalty programs in Mexico. Aeromexico, Mexico’s global airline, operates more than 600 daily flights and has its main hub in Terminal 2 of the Mexico City Inter

People. Passion. Pride. These have driven our team since 1833. Since that time, we have developed to become a critical partner in the global aviation industry, delivering time-critical logistics services at over 300 locations in 65 countries, across six continents. But at the heart of our

Welcome to our LinkedIn page! To learn how we can assist you, please check: http://klmf.ly/ContactCentre. KLM was founded in 1919 and is the oldest airline in the world. With a vast network of European and intercontinental destinations, KLM can offer direct flights to major cities and economic cen

At Saudia Group, we're on a mission to inspire people to go beyond borders. Our purpose is rooted in unlocking human potential and connecting the world in ways never thought possible. We are committed to reshaping the aviation ecosystem in our region and beyond, by embracing innovation and a custome

Delta Air Lines (NYSE: DAL) is the U.S. global airline leader in safety, innovation, reliability and customer experience. Powered by our employees around the world, Delta has for a decade led the airline industry in operational excellence while maintaining our reputation for award-winning customer s

Red. Hot. Spicy. That’s not just our tagline, it’s how we fly. Red reflects the bold spirit we bring to every journey, energetic, passionate, and full of heart. Hot captures the warmth of our service and the vibrant destinations we connect. Spicy is our drive to keep travel exciting through innovati
.png)
LOS ANGELES, December 01, 2025--Surf Air Mobility Inc. (NYSE: SRFM) ("Surf Air Mobility"), a leading regional air mobility platform,...
Dallas, Texas--(Newsfile Corp. - November 13, 2025) - Surf Air Mobility Inc. (NYSE: SRFM): Stonegate Capital Partners updates their coverage...
Surf Air Mobility Inc. (SRFM) delivered earnings and revenue surprises of -4.92% and +4.30%, respectively, for the quarter ended September...
Surf Air Mobility (SRFM) just rolled out a $100 million strategic transaction that combines new equity funding with debt refinancing,...
LOS ANGELES, November 12, 2025--Surf Air Mobility Inc. (NYSE: SRFM) ("the Company", "Surf Air Mobility"), a leading regional air mobility...
Surf Air is giving Palantir 6 million shares as prepayment. Which is a better company to invest in as the two work together?
The consensus estimate for Q3 2025 revenue is $27.88 million, and the earnings are expected to come in at -$0.61 per share.
LOS ANGELES, November 10, 2025--Surf Air Mobility Inc. (NYSE: SRFM) ("Surf Air Mobility", the "Company"), a leading air mobility platform,...
Surf Air Mobility announced in the past a US$100 million transaction combining new equity funding and a US$74 million senior secured...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Surf Air Mobility is http://www.surfair.com.
According to Rankiteo, Surf Air Mobility’s AI-generated cybersecurity score is 748, reflecting their Moderate security posture.
According to Rankiteo, Surf Air Mobility currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Surf Air Mobility is not certified under SOC 2 Type 1.
According to Rankiteo, Surf Air Mobility does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Surf Air Mobility is not listed as GDPR compliant.
According to Rankiteo, Surf Air Mobility does not currently maintain PCI DSS compliance.
According to Rankiteo, Surf Air Mobility is not compliant with HIPAA regulations.
According to Rankiteo,Surf Air Mobility is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Surf Air Mobility operates primarily in the Airlines and Aviation industry.
Surf Air Mobility employs approximately 60 people worldwide.
Surf Air Mobility presently has no subsidiaries across any sectors.
Surf Air Mobility’s official LinkedIn profile has approximately 3,911 followers.
Surf Air Mobility is classified under the NAICS code 481, which corresponds to Air Transportation.
No, Surf Air Mobility does not have a profile on Crunchbase.
Yes, Surf Air Mobility maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/surf-air-mobility.
As of December 11, 2025, Rankiteo reports that Surf Air Mobility has not experienced any cybersecurity incidents.
Surf Air Mobility has an estimated 3,515 peer or competitor companies worldwide.
Total Incidents: According to Rankiteo, Surf Air Mobility has faced 0 incidents in the past.
Incident Types: The types of cybersecurity incidents that have occurred include .
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.
