Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
DJI

DJI Vendor Cyber Rating & Cyber Score

dji.com

DJI is the global leader in developing and manufacturing innovative drone and camera technology for commercial and recreational use. DJI was founded and is run by people with a passion for remote-controlled helicopters and experts in flight-control technology and camera stabilization. The company is dedicated to making aerial technology accessible, reliable and easy to use for creators, innovators and businesses around the world. DJI has expanded its expertise and innovative technology to enterprises, government agencies and different industries around the world. DJI Enterprise was formed in order to help businesses realize the potential of aerial technology in their operations. DJI has expanded its enterprise solutions to include


DJI A.I CyberSecurity Scoring

DJI
Company Information
Website:http://www.dji.com
Employees number:5,314
Number of followers:362,446
NAICS:
Industry Type:Consumer Electronics
Homepage:dji.com
DJI Risk Score (AI oriented)
Between 750 and 799
logo
DJIConsumer Electronics
Updated:
11/09/2026
756/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
DJI Global Score (TPRM)
xxxx
logo
DJIConsumer Electronics
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

DJIFair
Current Score
756Baa (FAIR)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
756Before Incident
AUGUST 2026
756Before Incident
JULY 2026
755Before Incident
JUNE 2026
754Before Incident
MAY 2026
758Before Incident
Vulnerability
06 May 2026DJI
DJI: AI Developer Discovers Major Data Breach in Vacuum Robots

Major Security Flaw in DJI Vacuum Robots Exposed by AI Developer

753After Incident
CRITICAL-5
DJI1778063654
AI Developer Uncovers Major Security Flaw in DJI Vacuum Robots A French AI manager, Sammy Azdoufal, inadvertently exposed a critical security vulnerability in DJI’s Romo vacuum robots while attempting to customize his own device. Using an AI-generated app to connect his vacuum to a PlayStation gamepad, Azdoufal discovered he could access unencrypted data from approximately 7,000 other Romo units worldwide including live camera feeds, floor plans, and private user information. Azdoufal, who works at a vacation rental company, emphasized that his actions were not malicious but revealed a severe lapse in DJI’s data protection. All sensitive data was stored on servers without encryption, making it easily accessible to anyone with the right tools. Had cybercriminals exploited the flaw, the consequences for users and DJI could have been severe. After reporting the issue to DJI, the company initially downplayed the risk, claiming developers were already aware of the vulnerability. However, the flaw was patched only after Azdoufal’s disclosure. Despite DJI’s assurances, Azdoufal demonstrated that live video feeds from his own device remained unencrypted, contradicting the company’s claims. While access to other users’ devices has since been blocked, Azdoufal’s app originally designed for personal use still functions as intended, allowing him to control his vacuum via a gamepad. The program’s code and instructions have been made publicly available on GitHub. The incident highlights the growing risks of smart home devices collecting and mishandling sensitive data.
INCIDENT DETAILS -
TYPE
Data Exposure
IMPACT
Data Compromised: Live camera feeds, floor plans, private user informationSystems Affected: DJI Romo vacuum robots (approximately 7,000 units)Brand Reputation Impact: SevereIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Live camera feeds, floor plans, private user informationNumber Of Records Exposed: Approximately 7,000 units' dataSensitivity Of Data: HighData Encryption: None (unencrypted)Personally Identifiable Information: Yes
APRIL 2026
758Before Incident
MARCH 2026
757Before Incident
FEBRUARY 2026
757Before Incident
JANUARY 2026
756Before Incident
DECEMBER 2025
756Before Incident
NOVEMBER 2025
755Before Incident
OCTOBER 2025
754Before Incident
SEPTEMBER 2025
778Before Incident
Cyber Attack
01 Sep 2025DJI
Telefónica, JPMorgan Chase, Google and DJI: ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More

Google Play Strengthens Security in 2025, Multi-Stage Phishing Campaign, Critical Flaws in BMC FootPrints, SnappyClient C2 Framework, LiveChat Phishing, GitHub Secrets Exposure, The Gentlemen RaaS, WhatsApp Alphanumeric Passwords, Malicious Packagist Themes, DJI API Flaw, CVE Exploitation Trends, Teams Phishing, EU CSAM Rules, Emerging Threats

753After Incident
CRITICAL-25
DJIJPMTELGOO1789086449
Google Play Strengthens Security in 2025, Blocking Millions of Malicious Apps and Accounts In 2025, Google removed 1.75 million policy-violating Android apps from the Play Store a decline from 2.36 million in 2024 while banning 80,000 developer accounts, down from 158,000 the previous year. The company also blocked 255,000 apps from accessing excessive user data and conducted 10,000 safety checks on published apps, leveraging generative AI to enhance detection. Google’s Play Protect, now scanning 350 billion apps daily, identified 27 million malicious apps sideloaded outside the Play Store. Its expanded fraud protection covered 2.8 billion devices across 185 markets, blocking 266 million installation attempts from 872,000 high-risk apps. Additionally, Google introduced Scam Detection for phone calls on Pixel devices in 12 countries, including the U.S., U.K., and India, to combat fraudulent activity. --- Multi-Stage Phishing Campaign Bypasses Security Filters with Legitimate Infrastructure A sophisticated phishing-as-a-service (PhaaS) toolkit, dubbed Kratos, was used in an unsuccessful attack impersonating JPMorgan Chase. The campaign employed a multi-chain redirect tactic, leveraging Cisco’s infrastructure and trusted services like Nylas to evade security filters. Attackers implemented a Cloudflare-based "human validation" step to ensure only real users reached the credential-harvesting page. --- Critical Flaws in BMC FootPrints ITSM Enable Pre-Auth Remote Code Execution Four vulnerabilities (CVE-2025-71257–71260) in BMC FootPrints, a widely used IT service management (ITSM) solution, were disclosed in September 2025. The flaws could be chained to achieve pre-authentication remote code execution (RCE). The attack begins with an authentication bypass (CVE-2025-71257), extracting a guest session token to exploit an unsanitized Java deserialization sink (CVE-2025-71260). Attackers could also abuse SSRF flaws (CVE-2025-71258, CVE-2025-71259) to leak internal data. --- SnappyClient: A Stealthy C2 Framework Targeting Cryptocurrency Theft A new C++-based command-and-control (C2) framework, SnappyClient, was discovered in December 2025. Distributed via a fake Telefónica website, it employs evasion techniques like AMSI bypass, Heaven’s Gate, direct system calls, and transacted hollowing. The malware steals data from browsers, extensions, and applications, with suspected ties to HijackLoader based on code similarities. --- LiveChat Abused in Phishing Campaign to Harvest Sensitive Data A phishing campaign leveraged LiveChat’s messaging platform to trick users into entering credentials, credit card details, and MFA codes. Attackers sent refund-themed emails, redirecting victims to a LiveChat-hosted link where they engaged in real-time chat impersonating trusted brands. --- GitHub Sees Surge in Hard-Coded Secrets, Including AI Service Credentials In 2025, 28.65 million new secrets were exposed in public GitHub commits a 34% increase from 2024 and a 152% rise since 2021. AI service secrets surged by 81% year-over-year, reaching 1.28 million. Additionally, 24,088 unique secrets were found in MCP-related configuration files, including 2,117 valid credentials. --- The Gentlemen: A New RaaS Operation with Fabricated Claims A nascent Ransomware-as-a-Service (RaaS) group, The Gentlemen, emerged in mid-2025 following a payment dispute with Qilin ransomware operators. The group, consisting of ~20 members, has targeted 94 organizations but has yet to provide credible proof of successful attacks. Researchers noted fabricated data samples on their leak site. --- WhatsApp Introduces Alphanumeric Passwords to Counter SIM Swap Attacks WhatsApp began testing alphanumeric passwords (6–20 characters, with at least one letter and number) to strengthen account security. The measure aims to prevent unauthorized access even if attackers perform a SIM swap to intercept 2FA codes. --- Malicious Packagist Themes Inject Ads and Redirect Users to Gambling Sites Six trojanized Packagist packages, posing as OphimCMS themes, were found distributing malicious JavaScript disguised as jQuery libraries. The malware exfiltrates URLs, injects ads, and redirects mobile users to gambling and adult content sites operated by Funnull. --- DJI Exposes Device Data via Unauthenticated API Access A security flaw in DJI’s backend allowed attackers to access device data including 7,000 Romo smart vacuums and 3,000 portable power stations by simply providing a serial number. The issue was patched after disclosure. --- Only 1% of 2025 CVEs Were Exploited in the Wild A VulnCheck report found that just 1% of disclosed CVEs in 2025 were actively exploited, with network edge devices accounting for a third of all exploited vulnerabilities. Exploit activity by state-sponsored groups decreased by 13% compared to 2024. --- Teams Phishing Campaigns Impersonate IT Staff for Remote Access Threat actors increasingly abuse Microsoft Teams to impersonate internal IT departments, tricking users into launching Quick Assist for remote access. The goal is to deploy malware, exfiltrate data, or move laterally within networks. --- EU Extends Voluntary CSAM Detection Rules Until 2027 The European Union extended a temporary exemption allowing online platforms to voluntarily detect child sexual abuse material (CSAM) until August 2027, pending a long-term legal framework. --- Emerging Threats: AOT Malware, CursorJack, and HijackLoader’s Evolving Tactics - AOT-compiled malware evades analysis by stripping .NET metadata, forcing reliance on native-level tooling. - CursorJack abuses Model Context Protocol (MCP) deep links for arbitrary command execution. - HijackLoader now delivers an updated ACRStealer variant, spreading via pirated games from PiviGames.
INCIDENT DETAILS -
TYPE
Malware DistributionPhishingVulnerability ExploitationData BreachRansomwareFraudCredential Harvesting
MOTIVATION
Financial GainData TheftEspionageFraudRansomware Extortion
IMPACT
User CredentialsCredit Card DetailsMFA CodesBrowser DataAI Service SecretsDevice DataAndroid AppsBMC FootPrints ITSMGitHub RepositoriesLiveChat PlatformDJI BackendMicrosoft TeamsMalicious App DistributionUnauthorized Remote AccessData ExfiltrationService DisruptionGoogle PlayJPMorgan ChaseBMCLiveChatDJIMicrosoft Teams
DATA BREACH
CredentialsPayment InformationBrowser DataAI Service SecretsDevice Data28.65 million GitHub secrets24,088 MCP-related secretsHighConfiguration FilesJavaScript

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for DJI ?
?
What was DJI's A.I Rankiteo Cyber Score in August 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was DJI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was DJI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was DJI's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on DJI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with DJI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view DJI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?