Company Details
thales
67,535
1,780,450
336414
thalesgroup.com
207
THA_7781503
Completed

Thales Company CyberSecurity Posture
thalesgroup.comThales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion. The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies. Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.
Company Details
thales
67,535
1,780,450
336414
thalesgroup.com
207
THA_7781503
Completed
Between 700 and 749

Thales Global Score (TPRM)XXXX

Description: Imperva disclosed a security incident that impacts customers of its cloud web application firewall (WAF), formerly known as Incapsula. The company learned from a third party of a data exposure that impacts a subset of customers of their Cloud WAF product. Exposed data included customer email addresses, along with hashed and salted passwords, for a subset of customers. For a small number of users, API keys and customer-provided SSL certificates were also exposed. Imperva said the security incident only affected customers of its cloud WAF, and not other products.
Description: The florists associated with Incapsula now known as Imperva, suffered a ransomware attack in the Valentine's week of 2016 which resulted in a huge loss of revenue. ALl of the 34 floristes of Inperva were truck by targeted distributed denial-of-service (DDoS) attacks while one of the website crashed after its content delivery network (CDN) interpreted the attack traffic as legitimate user sessions and routed the traffic through the origin server. One of them also received a ransom demand for restoring the access to the website, however, Imperva immediately helped them get their business online and restore all the access.
Description: Hackers claim to have stolen data from France's Thales and was threatening to publish it. The extortion and ransomware group had plans on the dark web to release the data on Nov. 7. It had not received any direct ransom notification. The hackers have not provided proof they have obtained any Thales data.
Description: In a significant cybersecurity incident, Thales Group, a prominent player in the aerospace, defense, and security sectors, faced a direct attack on its satellite communication systems. This compromise led to a breach of sensitive communication channels between ground operations and several commercial satellites. The attackers managed to inject malicious code to disrupt the integrity of critical data being relayed for navigation and observation purposes. The profound implications of this event put essential space-based services used by governments and corporations at risk, threatening national security interests and economic stability across multiple regions.
Description: In 2022, the French defense and technology firm **Thales Group** fell victim to a **ransomware attack** executed by the **LockBit 3.0** group. The assault specifically targeted the company’s **advanced technology and defense services**, exposing critical vulnerabilities in systems supporting external services for the **maritime sector**. While the full extent of data compromise or operational disruption remains undisclosed, the attack underscored the severe risks ransomware poses to organizations operating in high-stakes industries like defense and aerospace.The breach raised concerns about potential **intellectual property theft**, **disruption of defense-related operations**, and **compromise of sensitive client data**, including government and military entities. Given Thales’ role in providing mission-critical infrastructure—such as **satellite communications, naval systems, and cybersecurity solutions for global defense partners**—the attack carried implications beyond financial loss, threatening **national security and geopolitical stability**. The incident also highlighted the growing trend of cybercriminal groups targeting **strategic industries** to maximize leverage, whether through data exfiltration, operational sabotage, or ransom demands.Though Thales confirmed containment measures, the attack reinforced the urgency for **enhanced cyber resilience** in sectors where digital breaches can have **cascading effects on supply chains, allied nations, and civilian safety**. The involvement of **LockBit 3.0**, a prolific ransomware-as-a-service (RaaS) operator known for high-profile extortion, further amplified the threat’s severity.
Description: French defense and technology group Thales suffered from a ransomware attack after the hacker group LockBit 3.0 stole some of its data and was threatening to publish it. They had not been directly notified of a ransom demand. Thales has launched an internal inquiry and contacted the ANSSI national cyber security agency but has not yet made a police complaint.


No incidents recorded for Thales in 2025.
No incidents recorded for Thales in 2025.
No incidents recorded for Thales in 2025.
Thales cyber incidents detection timeline including parent company and subsidiaries

Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion. The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies. Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.

V2X is a leading provider of critical mission solutions and support to defense clients globally, formed by the 2022 Merger of Vectrus and Vertex to build on more than 120 combined years of successful mission support. We deliver a comprehensive suite of integrated solutions across the operations and

From Gulfstream business jets and combat vehicles to nuclear-powered submarines and communications systems, people around the world depend on our products and services for their safety and security. General Dynamics is headquartered in Reston, Virginia, and employs over 100,000 people in 43 countri

The mission of the United States Air Force is to fly, fight and win … in air, space and cyberspace. To achieve that mission, the Air Force has a vision of Global Vigilance, Reach and Power. That vision orbits around three core competencies: developing Airmen, technology to war fighting and integr

We are NAVSEA. The Force Behind the Fleet. Join us and become part of a mission-driven team, at one of the best places to work in the federal government. This NAVSEA LinkedIn page is all about connecting with talented individuals ready to make a difference through a rewarding career with us. We shar

Babcock is a FTSE 100 defence company operating in our focus countries of the UK, Australasia, Canada, France and South Africa, with exports to additional markets. Our Purpose, to create a safe and secure world, together, defines our strategy. We support and enhance our customers’ defence and secu

The freedom to explore. The promise to deliver. General Atomics, based in San Diego, CA, develops advanced technology solutions for government and commercial applications. Privately owned and vertically integrated, we have the freedom to invest in the most innovative technologies, and the resource

As an international naval defence player, Naval Group is a partner for countries seeking to maintain control of their maritime sovereignty. Naval Group develops innovative solutions to meet its customers’ requirements. The group is present throughout the entire life cycle of vessels. It designs, pro

We are a close-knit community of big thinkers collaborating to keep the world safe. Our passion, creativity and expertise bring next-level technology solutions to life in autonomous systems, cyber, C4ISR, strike, space, and logistics and modernization for our customers around the globe. On the Nor

We protect the security, independence and interests of the United Kingdom at home and abroad. We work with our allies and partners whenever possible. Our aim is to ensure that the UK’s Armed Forces have the training, equipment and support necessary for their work, and that we keep within budget.
.png)
As the quantum revolution compels us to rethink the foundations of cybersecurity, Thales a high-tech leader in Defense, Aerospace,...
Thales SA: Thales and CEA: an unprecedented partnership to strengthen French post-quantum cybersecurity Company's and CEA's IT security...
The McKenna Institute at the University of New Brunswick, the Joint Economic Development Initiative (JEDI) and Thales announced today (Nov...
Defence company Thales Australia has opened a new cyber Security Operations Centre (SOC) in Canberra to protect Government and Critical...
Thales Australia has announced the opening of a sovereign and protected cyber Security Operations Centre in Canberra.
Black Friday and Cyber Monday can make or break the year for retailers. Sales soar, carts fill, and data pours in. However, the same things...
Netpoleon enhances its cybersecurity portfolio in Australia and New Zealand by integrating Thales and Imperva solutions, boosting data and...
At the European Cyber Week, held in Rennes (France) from 17 to 20 November 2025, Thales announced the launch of the MISTRAL post-quantum...
In line with the UAE's vision to enhance National Cyber Sovereignty, Thales and the UAE Cyber Security Council sign a Memorandum of...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Thales is http://www.thalesgroup.com/.
According to Rankiteo, Thales’s AI-generated cybersecurity score is 733, reflecting their Moderate security posture.
According to Rankiteo, Thales currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Thales is not certified under SOC 2 Type 1.
According to Rankiteo, Thales does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Thales is not listed as GDPR compliant.
According to Rankiteo, Thales does not currently maintain PCI DSS compliance.
According to Rankiteo, Thales is not compliant with HIPAA regulations.
According to Rankiteo,Thales is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Thales operates primarily in the Defense and Space Manufacturing industry.
Thales employs approximately 67,535 people worldwide.
Thales presently has no subsidiaries across any sectors.
Thales’s official LinkedIn profile has approximately 1,780,450 followers.
Thales is classified under the NAICS code 336414, which corresponds to Guided Missile and Space Vehicle Manufacturing.
Yes, Thales has an official profile on Crunchbase, which can be accessed here: https://www.crunchbase.com/organization/thales-group.
Yes, Thales maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/thales.
As of December 11, 2025, Rankiteo reports that Thales has experienced 6 cybersecurity incidents.
Thales has an estimated 2,330 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Data Leak, Ransomware, Cyber Attack and Breach.
Total Financial Loss: The total financial loss from these incidents is estimated to be $0.
Detection and Response: The company detects and responds to cybersecurity incidents through an third party assistance with imperva, and remediation measures with restored access and got the business back online, and incident response plan activated with internal inquiry launched, and third party assistance with contacted the anssi national cyber security agency..
Title: Ransomware and DDoS Attack on Imperva Florists
Description: Incapsula (now Imperva) florists suffered a ransomware attack during Valentine's week of 2016, resulting in significant revenue loss. All 34 florists were hit by targeted DDoS attacks, with one website crashing due to attack traffic being routed through the origin server. One florist received a ransom demand, but Imperva helped restore access and get the business back online.
Date Detected: February 2016
Type: Ransomware
Attack Vector: DDoSRansomware
Motivation: Financial Gain
Title: Data Theft Incident at Thales
Description: Hackers claim to have stolen data from France's Thales and were threatening to publish it. The extortion and ransomware group had plans on the dark web to release the data on Nov. 7. It had not received any direct ransom notification. The hackers have not provided proof they have obtained any Thales data.
Type: Data Breach
Attack Vector: Unknown
Threat Actor: Unknown
Motivation: Extortion
Title: Thales Ransomware Attack
Description: French defense and technology group Thales suffered from a ransomware attack after the hacker group LockBit 3.0 stole some of its data and was threatening to publish it.
Type: Ransomware
Threat Actor: LockBit 3.0
Motivation: Data theft and extortion
Title: Imperva Cloud WAF Data Exposure Incident
Description: Imperva disclosed a security incident that impacts customers of its cloud web application firewall (WAF), formerly known as Incapsula. The company learned from a third party of a data exposure that impacts a subset of customers of their Cloud WAF product. Exposed data included customer email addresses, along with hashed and salted passwords, for a subset of customers. For a small number of users, API keys and customer-provided SSL certificates were also exposed. Imperva said the security incident only affected customers of its cloud WAF, and not other products.
Type: Data Exposure
Title: Cyber Attack on Thales Group's Satellite Communication Systems
Description: Thales Group, a prominent player in the aerospace, defense, and security sectors, faced a direct attack on its satellite communication systems. This compromise led to a breach of sensitive communication channels between ground operations and several commercial satellites. The attackers managed to inject malicious code to disrupt the integrity of critical data being relayed for navigation and observation purposes. The profound implications of this event put essential space-based services used by governments and corporations at risk, threatening national security interests and economic stability across multiple regions.
Type: Cyber Attack
Attack Vector: Malicious Code Injection
Vulnerability Exploited: Satellite Communication Systems
Motivation: National Security DisruptionEconomic Instability
Title: Ransomware Attack on Thales Group by LockBit 3.0
Description: The French defense and technology firm Thales Group suffered a ransomware attack by LockBit 3.0 in 2022. The attack targeted the company's advanced technology and defense services, illustrating the potential dangers ransomware poses to organizations that offer external service to the maritime sector.
Type: ransomware
Threat Actor: LockBit 3.0
Common Attack Types: The most common types of attacks the company has faced is Ransomware.
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through Satellite Communication Systems.

Financial Loss: Significant
Systems Affected: WebsitesCDN
Downtime: Significant
Operational Impact: High
Revenue Loss: Significant

Data Compromised: Some data stolen

Data Compromised: Email addresses, Hashed and salted passwords, Api keys, Customer-provided ssl certificates
Systems Affected: Cloud WAF

Data Compromised: Sensitive Communication Channels
Systems Affected: Satellite Communication Systems
Operational Impact: Disruption of Critical Data Integrity
Average Financial Loss: The average financial loss per incident is $0.00.
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Email Addresses, Hashed And Salted Passwords, Api Keys, Customer-Provided Ssl Certificates, and Sensitive Communication Data.

Entity Name: Imperva Florists
Entity Type: Business
Industry: Floristry
Size: 34 florists

Entity Name: Thales
Entity Type: Organization
Industry: Defense and Security
Location: France

Entity Name: Thales
Entity Type: Defense and Technology Group
Industry: Defense and Technology
Location: France

Entity Name: Imperva
Entity Type: Company
Industry: Cybersecurity
Customers Affected: Subset of customers

Entity Name: Thales Group
Entity Type: Company
Industry: Aerospace, Defense, Security

Entity Name: Thales Group
Entity Type: defense and technology firm
Industry: defense, technology, maritime services
Location: France

Third Party Assistance: Imperva
Remediation Measures: Restored access and got the business back online

Incident Response Plan Activated: Internal inquiry launched
Third Party Assistance: Contacted the ANSSI national cyber security agency
Incident Response Plan: The company's incident response plan is described as Internal inquiry launched.
Third-Party Assistance: The company involves third-party assistance in incident response through Imperva, Contacted the ANSSI national cyber security agency.

Data Exfiltration: Some data stolen

Type of Data Compromised: Email addresses, Hashed and salted passwords, Api keys, Customer-provided ssl certificates
Sensitivity of Data: High
Data Encryption: Hashed and salted passwords
Personally Identifiable Information: email addresses

Type of Data Compromised: Sensitive Communication Data
Sensitivity of Data: High
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Restored access and got the business back online.

Ransom Demanded: Yes

Ransomware Strain: LockBit 3.0

Investigation Status: Internal inquiry launched

Entry Point: Satellite Communication Systems
High Value Targets: Commercial Satellites
Data Sold on Dark Web: Commercial Satellites
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Imperva, Contacted the ANSSI national cyber security agency.
Last Ransom Demanded: The amount of the last ransom demanded was Yes.
Last Attacking Group: The attacking group in the last incident were an Unknown, LockBit 3.0 and LockBit 3.0.
Most Recent Incident Detected: The most recent incident detected was on February 2016.
Highest Financial Loss: The highest financial loss from an incident was Significant.
Most Significant Data Compromised: The most significant data compromised in an incident were Some data stolen, email addresses, hashed and salted passwords, API keys, customer-provided SSL certificates, and Sensitive Communication Channels.
Most Significant System Affected: The most significant system affected in an incident was WebsitesCDN and Cloud WAF and .
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Imperva, Contacted the ANSSI national cyber security agency.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were customer-provided SSL certificates, API keys, Sensitive Communication Channels, hashed and salted passwords, Some data stolen and email addresses.
Highest Ransom Demanded: The highest ransom demanded in a ransomware incident was Yes.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Internal inquiry launched.
Most Recent Entry Point: The most recent entry point used by an initial access broker was an Satellite Communication Systems.
.png)
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.
Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.
The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.