Comparison Overview

Jewel-Osco

VS

ICA Gruppen

Jewel-Osco

150 Pierce Road, Itasca, 60143, US
Last Update: 2026-04-02
Between 750 and 799

Proudly serving our customers in the Chicagoland area since 1899, Jewel-Osco provides friendly service, quality products and great value. Jewel-Osco operates 188 stores throughout the Chicagoland area, Indiana and Iowa, which is part of a 2,200+ store operation that employs approximately 290,000 people nationwide. All of our stores, no matter what banner they operate under, were founded around the philosophy of offering customers the products they wanted to buy at a fair price, with lots of tender, loving care. We still open our doors every day with that in mind.

NAICS: 43
NAICS Definition: Retail Trade
Employees: 11,682
Subsidiaries: 1
12-month incidents
0
Known data breaches
3
Attack type number
2

ICA Gruppen

Kolonnvägen 20 , Solna, A, SE, 17193
Last Update: 2026-04-02
Between 750 and 799

ICA Gruppen´s core business is retail. The Group includes ICA Sweden which mainly conduct grocery retail, ICA Real Estate which owns and manages properties, ICA Bank which offers financial services and insurances, Apotek Hjärtat which conducts pharmacy operations. Guidelines: Comments in our channels that are offensive or abusive in nature will be removed.

NAICS: 43
NAICS Definition: Retail Trade
Employees: 18,170
Subsidiaries: 5
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/jewel-osco.jpeg
Jewel-Osco
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/ica.jpeg
ICA Gruppen
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Jewel-Osco
100%
Compliance Rate
0/4 Standards Verified
ICA Gruppen
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Retail Industry Average (This Year)

No incidents recorded for Jewel-Osco in 2026.

Incidents vs Retail Industry Average (This Year)

No incidents recorded for ICA Gruppen in 2026.

Incident History — Jewel-Osco (X = Date, Y = Severity)

Jewel-Osco cyber incidents detection timeline including parent company and subsidiaries

Incident History — ICA Gruppen (X = Date, Y = Severity)

ICA Gruppen cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/jewel-osco.jpeg
Jewel-Osco
Incidents

Date Detected: 12/2023
Type:Breach
Attack Vector: Credential Theft (Fraudulent Website)
Blog: Blog

Date Detected: 12/2022
Type:Breach
Blog: Blog

Date Detected: 8/2014
Type:Cyber Attack
Motivation: Criminal (Potential Theft of Payment Card Data)
Blog: Blog
https://images.rankiteo.com/companyimages/ica.jpeg
ICA Gruppen
Incidents

No Incident

FAQ

ICA Gruppen company demonstrates a stronger AI Cybersecurity Score compared to Jewel-Osco company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Jewel-Osco company has historically faced a number of disclosed cyber incidents, whereas ICA Gruppen company has not reported any.

In the current year, ICA Gruppen company and Jewel-Osco company have not reported any cyber incidents.

Neither ICA Gruppen company nor Jewel-Osco company has reported experiencing a ransomware attack publicly.

Jewel-Osco company has disclosed at least one data breach, while the other ICA Gruppen company has not reported such incidents publicly.

Jewel-Osco company has reported targeted cyberattacks, while ICA Gruppen company has not reported such incidents publicly.

Neither Jewel-Osco company nor ICA Gruppen company has reported experiencing or disclosing vulnerabilities publicly.

Neither Jewel-Osco nor ICA Gruppen holds any compliance certifications.

Neither company holds any compliance certifications.

ICA Gruppen company has more subsidiaries worldwide compared to Jewel-Osco company.

ICA Gruppen company employs more people globally than Jewel-Osco company, reflecting its scale as a Retail.

Neither Jewel-Osco nor ICA Gruppen holds SOC 2 Type 1 certification.

Neither Jewel-Osco nor ICA Gruppen holds SOC 2 Type 2 certification.

Neither Jewel-Osco nor ICA Gruppen holds ISO 27001 certification.

Neither Jewel-Osco nor ICA Gruppen holds PCI DSS certification.

Neither Jewel-Osco nor ICA Gruppen holds HIPAA certification.

Neither Jewel-Osco nor ICA Gruppen holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

Risk Information
cvss2
Base: 5.0
Severity: LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
cvss3
Base: 4.3
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
cvss4
Base: 5.3
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read in VS6ComFile!get_macro_mem_COM. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain a stack-based buffer overflow in VS6ComFile!CSaveData::_conv_AnimationItem. Opening a crafted V7 file may lead to arbitrary code execution on the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6MemInIF!set_temp_type_default. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

V-SFT versions 6.2.10.0 and prior contain an out-of-bounds read vulnerability in VS6ComFile!load_link_inf. Opening a crafted V7 file may lead to information disclosure from the affected product.

Risk Information
cvss3
Base: 7.8
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvss4
Base: 8.4
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X