DHL A.I CyberSecurity Scoring
DHL
Company Information
Website:http://www.dhl.com
Employees number:224,682
Number of followers:2,770,958
NAICS:47
Industry Type:Transportation, Logistics, Supply Chain and Storage
Homepage:dhl.com
DHL Risk Score (AI oriented)
Between 750 and 799
DHLTransportation, Logistics, Supply Chain and Storage
Updated:
18/06/2026
18/06/2026
794/1000
Fair
Baa
DHL Global Score (TPRM)
xxxx
DHLTransportation, Logistics, Supply Chain and Storage
Score locked

DHLFair
Current Score
794Baa (FAIR)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
795
JULY 2026
794
JUNE 2026
794
MAY 2026
793
APRIL 2026
802
Cyber Attack
28 Apr 2026 • DHL
DHL: New DHL Phishing Scam Uses 11-Step Attack Chain to Steal Passwords
Phishing Campaign Impersonates DHL to Steal Credentials via Fake OTP Scheme
820
HIGH-18
DHL1777415025
Phishing Campaign Impersonates DHL to Steal Credentials via Fake OTP Scheme
Researchers at Forcepoint’s X-Labs uncovered a sophisticated phishing campaign leveraging the DHL brand to harvest login credentials through an 11-step attack chain. The operation begins with a spoofed email bearing the subject line “DHL EXPRESS WAYBILL CONFIRMATION REQUIRED,” falsely prompting recipients to verify a shipment. While the display name appears as DHL EXPRESS, the sender domain cupelva.com reveals the deception, though the email bypasses some security filters by passing DKIM authentication for the attacker’s domain.
Victims who click the embedded link are directed to a fake parcel verification page hosted at perfectgoc.com, where a locally generated six-digit "OTP" is displayed via JavaScript. Unlike legitimate two-factor authentication, this step does not involve SMS or email delivery; instead, users are instructed to input the on-screen code, creating a false sense of security. A deliberate two-second delay mimics real processing, further enhancing the illusion. Forcepoint researchers emphasized that this tactic targeting individuals without geographic or organizational focus relies on psychological manipulation rather than technical complexity to lower victims’ defenses.
The attack employs URL-based identity injection to pre-fill the victim’s email address on a counterfeit DHL login portal, increasing perceived legitimacy. Once credentials are entered, the phishing kit exfiltrates additional telemetry data, including the user’s public IP, device type, OS, browser version, and geolocation (city/country). This data is temporarily stored in the browser’s local storage before being transmitted.
For data exfiltration, the attackers use EmailJS, a legitimate service that enables direct browser-to-email transfers, eliminating the need for dedicated command-and-control infrastructure. Stolen information is sent to the attacker-controlled mailbox [email protected]. Upon completion, victims are redirected to DHL’s authentic website, reducing suspicion by simulating a successful login.
Forcepoint noted the campaign’s effectiveness stems from its focus on social engineering over malware, with mitigation requiring the blocking of weaponized URLs and monitoring of the attacker’s mailbox.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
801
FEBRUARY 2026
801
JANUARY 2026
801
DECEMBER 2025
800
NOVEMBER 2025
800
OCTOBER 2025
799
SEPTEMBER 2025
798
MAY 2025
826
Breach
01 May 2025 • DHL
Fortinet, Samsung, Foxconn, Oracle and DHL: 74,000 Fortinet firewall credentials exposed in FortiBleed data leak
Russian Cybercriminal Group Exposes 74,000 Fortinet Firewall Credentials in Massive Leak
795
CRITICAL-31
SAMFOXORAFORDHL1781785487
Russian Cybercriminal Group Exposes 74,000 Fortinet Firewall Credentials in Massive Leak
A Russian-speaking cybercriminal group inadvertently exposed credentials from nearly 74,000 Fortinet firewalls and VPN gateways worldwide after leaving the data unsecured on a server. The breach, discovered by security researcher Volodymyr “Bob” Diachenko over the past weekend, was confirmed by other researchers, including Kevin Beaumont, who verified the authenticity of the leaked login details.
The compromised data, dubbed FortiBleed, includes configuration files containing sensitive information visible only from the devices themselves. The group obtained the credentials through automated large-scale harvesting, intercepting SSL VPN authentication hashes, cracking them using a 45-GPU cluster via Hashtopolis, and leveraging the passwords to infiltrate Active Directory environments. Researchers at Hudson Rock identified 73,932 unique firewall URLs across 194 countries, with many devices exposing their FortiGate Management Interface to the internet.
While Fortinet previously addressed password storage vulnerabilities in early 2025 by adopting PBKDF2 with randomized salt, many devices still use the older, weaker SHA-256 with salt method, making them susceptible to brute-force attacks. The leaked data appears to include both recently harvested credentials and older collections from prior breaches.
The breach impacts high-profile organizations, including Samsung, Siemens, Foxconn, Oracle, Accenture, DHL, Infosys, and Fortinet, as well as government agencies and critical infrastructure sectors. Notably, four organizations spanning Japan, Taiwan/Vietnam, Iraq, and Turkey were fully compromised, with a Turkish NATO defense contractor suffering exfiltration of classified defense documents.
Fortinet attributes the leak to exploited vulnerabilities and brute-force attacks, though the exact timeline of data collection remains unclear. Organizations using Fortinet devices are advised to assume compromise if their domains or IPs appear in the exposed dataset, requiring credential rotation, MFA enforcement, and system upgrades to mitigate further risks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for DHL ??
What was DHL's A.I Rankiteo Cyber Score in July 2026 ??
What was DHL's A.I Rankiteo Cyber Score in June 2026 ??
What was DHL's A.I Rankiteo Cyber Score in May 2026 ??
What was DHL's A.I Rankiteo Cyber Score in April 2026 ??
What was DHL's A.I Rankiteo Cyber Score in March 2026 ??
What was DHL's A.I Rankiteo Cyber Score in February 2026 ??
What was DHL's A.I Rankiteo Cyber Score in January 2026 ??
What was DHL's A.I Rankiteo Cyber Score in December 2025 ??
What was DHL's A.I Rankiteo Cyber Score in November 2025 ??
What was DHL's A.I Rankiteo Cyber Score in October 2025 ??
What was DHL's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on DHL's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with DHL ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view DHL's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?