ISO 27001 Certificate
SOC 1 Type I Certificate
SOC 2 Type II Certificate
PCI DSS
HIPAA
RGPD
Internal validation & live display
Multiple badges & continuous verification
Faster underwriting decisions
ISOSOC2 Type 1SOC2 Type 2PCI DSSHIPAAGDPR

DiDi Global Inc. is a leading mobility technology platform. It offers a wide range of app-based services across Asia Pacific, Latin America, and other global markets, including ride hailing, taxi hailing, designated driving, hitch and other forms of shared mobility as well as certain energy and vehicle services, food delivery, and intra-city freight services. DiDi provides car owners, drivers, and delivery partners with flexible work and income opportunities. It is committed to collaborating with policymakers, the taxi industry, the automobile industry, and the communities to solve the world’s transportation, environmental, and employment challenges through the use of AI technology and localized smart transportation innovations. DiDi strives to create better life experiences and greater social value, by building a safe, inclusive, and sustainable transportation and local services ecosystem for cities of the future.

DiDi A.I CyberSecurity Scoring

DiDi

Company Details

Linkedin ID:

didiglobal

Employees number:

29,134

Number of followers:

320,963

NAICS:

5112

Industry Type:

Software Development

Homepage:

didiglobal.com

IP Addresses:

0

Company ID:

DID_1472078

Scan Status:

In-progress

AI scoreDiDi Risk Score (AI oriented)

Between 750 and 799

https://images.rankiteo.com/companyimages/didiglobal.jpeg
DiDi Software Development
Updated:
  • Powered by our proprietary A.I cyber incident model
  • Insurance preferes TPRM score to calculate premium
globalscoreDiDi Global Score (TPRM)

XXXX

https://images.rankiteo.com/companyimages/didiglobal.jpeg
DiDi Software Development
  • Instant access to detailed risk factors
  • Benchmark vs. industry & size peers
  • Vulnerabilities
  • Findings

DiDi Company CyberSecurity News & History

Past Incidents
1
Attack Types
1
EntityTypeSeverityImpactSeenBlog DetailsIncident DetailsView
DiDi Global IncBreach6026/2021
Rankiteo Explanation :
Attack limited on finance or reputation

Description: DiDi Global faced a **$740 million settlement** in a class-action lawsuit for allegedly defrauding investors by concealing a **Chinese government order** to delay its June 2021 IPO until cybersecurity and privacy concerns were resolved. The company proceeded with the IPO, raising **$4.4 billion**, but shortly after, China’s **Cyberspace Administration** banned new customer registrations and removed the **DiDi Travel app** from app stores. The regulator later imposed a **$1.2 billion fine** (July 2022) for data security violations. The incident triggered a **sharp decline in DiDi’s stock value**, eroding investor trust and leading to significant financial losses, including a **second-quarter loss** tied to the settlement provision. The case highlights regulatory non-compliance in cybersecurity, resulting in **reputational damage, financial penalties, and legal repercussions**, undermining the company’s market position and operational stability.

DiDi Global Inc
Breach
Severity: 60
Impact: 2
Seen: 6/2021
Blog:
Rankiteo Explanation
Attack limited on finance or reputation

Description: DiDi Global faced a **$740 million settlement** in a class-action lawsuit for allegedly defrauding investors by concealing a **Chinese government order** to delay its June 2021 IPO until cybersecurity and privacy concerns were resolved. The company proceeded with the IPO, raising **$4.4 billion**, but shortly after, China’s **Cyberspace Administration** banned new customer registrations and removed the **DiDi Travel app** from app stores. The regulator later imposed a **$1.2 billion fine** (July 2022) for data security violations. The incident triggered a **sharp decline in DiDi’s stock value**, eroding investor trust and leading to significant financial losses, including a **second-quarter loss** tied to the settlement provision. The case highlights regulatory non-compliance in cybersecurity, resulting in **reputational damage, financial penalties, and legal repercussions**, undermining the company’s market position and operational stability.

Ailogo

DiDi Company Scoring based on AI Models

Cyber Incidents Likelihood 3 - 6 - 9 months

🔒
Incident Predictions locked
Access Monitoring Plan

A.I Risk Score Likelihood 3 - 6 - 9 months

🔒
A.I. Risk Score Predictions locked
Access Monitoring Plan
statics

Underwriter Stats for DiDi

Incidents vs Software Development Industry Average (This Year)

No incidents recorded for DiDi in 2025.

Incidents vs All-Companies Average (This Year)

No incidents recorded for DiDi in 2025.

Incident Types DiDi vs Software Development Industry Avg (This Year)

No incidents recorded for DiDi in 2025.

Incident History — DiDi (X = Date, Y = Severity)

DiDi cyber incidents detection timeline including parent company and subsidiaries

DiDi Company Subsidiaries

SubsidiaryImage

DiDi Global Inc. is a leading mobility technology platform. It offers a wide range of app-based services across Asia Pacific, Latin America, and other global markets, including ride hailing, taxi hailing, designated driving, hitch and other forms of shared mobility as well as certain energy and vehicle services, food delivery, and intra-city freight services. DiDi provides car owners, drivers, and delivery partners with flexible work and income opportunities. It is committed to collaborating with policymakers, the taxi industry, the automobile industry, and the communities to solve the world’s transportation, environmental, and employment challenges through the use of AI technology and localized smart transportation innovations. DiDi strives to create better life experiences and greater social value, by building a safe, inclusive, and sustainable transportation and local services ecosystem for cities of the future.

Loading...
similarCompanies

DiDi Similar Companies

Red Hat

Red Hat is the world’s leading provider of enterprise open source solutions, using a community-powered approach to deliver high-performing Linux, hybrid cloud, edge, and Kubernetes technologies. We hire creative, passionate people who are ready to contribute their ideas, help solve complex problems

Shopee

Shopee is the leading e-commerce platform in Southeast Asia and Taiwan. It is a platform tailored for the region, providing customers with an easy, secure and fast online shopping experience through strong payment and logistical support. Shopee aims to continually enhance its platform and become th

Thomson Reuters

Thomson Reuters is the world’s leading provider of news and information-based tools to professionals. Our worldwide network of journalists and specialist editors keep customers up to speed on global developments, with a particular focus on legal, regulatory and tax changes. Our customers operat

Bosch

The Bosch Group is a leading global supplier of technology and services. It employs roughly 417,900 associates worldwide (as of December 31, 2024). According to preliminary figures, the company generated sales of 90.5 billion euros in 2024. Its operations are divided into four business sectors: Mobi

UKG is the Workforce Operating Platform that puts workforce understanding to work. With the world's largest collection of workforce insights, and people-first AI, our ability to reveal unseen ways to build trust, amplify productivity, and empower talent, is unmatched. It's this expertise that equips

Broadcom Software

Broadcom Software modernizes, optimizes, and protects the world’s most complex hybrid environments. We are a global software leader delivering a comprehensive portfolio of industry-leading business-critical software enabling scalability, agility and security for the largest global companies in the w

Alibaba Group

🌍Alibaba Group is on a mission to make it easy to do business anywhere! Guided by our passion and imagination, we’re leading the way in AI, cloud computing and e-commerce. We aim to build the future infrastructure of commerce, and we aspire to be a good company that lasts for 102 years.

Tencent

Tencent is a world-leading internet and technology company that develops innovative products and services to improve the quality of life of people around the world. Founded in 1998 with its headquarters in Shenzhen, China, Tencent's guiding principle is to use technology for good. Our communication

[24]7.ai

[24]7.ai™ customer engagement solutions use conversational artificial intelligence to understand customer intent, enabling companies to create personalized, predictive, and effortless customer experiences across all channels; attract and retain customers; boost agent productivity and satisfaction; a

newsone

DiDi CyberSecurity News

November 29, 2023 08:00 AM
Didi Says App Glitch Was Software Issue, Not Cyberattack

(Yicai) Nov. 29 -- Didi Chuxing Technology said the glitch this week that interfered with the Chinese ride-hailing giant's app was down to a...

April 29, 2023 07:00 AM
Didi zooms past big fine and Covid-19 to narrow losses in 2022

Revenue declined 19 per cent to 140.8 billion yuan in 2022 from 173.8 billion yuan in the previous year, as users in China took fewer rides...

April 11, 2023 07:00 AM
China Launches Cybersecurity Review Against Micron

The Cyberspace Administration of China (CAC) in a brief statement on March 31, 2023 stated that it has launched a cybersecurity review of Micron's products...

January 16, 2023 08:00 AM
Chinese ride-hailing giant Didi Chuxing gets go-ahead for new user registrations

The Cyber Security Review Office gave Didi the green light to resume new user registrations several months after concluding its...

January 16, 2023 08:00 AM
Didi Wins Approval to Restart New User Registration for Ride-Hailing Service

Move comes a year and a half after ride-hailing giant was targeted in a cybersecurity probe by Chinese authorities.

August 05, 2022 07:00 AM
The CAC is Coming: Didi Chuxing Fined a Record-breaking USD 1.2 Billion for Breach of Data Protection Regulations

Didi Chuxing (Didi) was fined RMB 8.026 billion (approx. USD 1.2 billion) on 21 July 2022, more than a year after the Cyberspace Administration of China (CAC)...

August 02, 2022 07:00 AM
Didi Cybersecurity Review - Which Laws did Didi Break?

Which regulations did Didi break? According to the CAC's announcement released on July 21, 2022 the investigation found that Didi had violated...

July 28, 2022 07:00 AM
Cyberspace Administration of China Issues Statement on Didi’s $1.2B Fines for Cybersecurity Law Violations

The statement revealed more details regarding CAC's basis for its penalty decision. It stated that Didi committed 16 offenses, which appeared to...

July 25, 2022 07:00 AM
China imposes $1.7bn fine on DiDi app for data breach incidents

Chinese ride-hailing firm Didi Global has been fined 8 billion yuan (AU$1.7 billion) by the Cyberspace Administration of China (CAC).

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

DiDi CyberSecurity History Information

Official Website of DiDi

The official website of DiDi is http://www.didiglobal.com.

DiDi’s AI-Generated Cybersecurity Score

According to Rankiteo, DiDi’s AI-generated cybersecurity score is 758, reflecting their Fair security posture.

How many security badges does DiDi’ have ?

According to Rankiteo, DiDi currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.

Does DiDi have SOC 2 Type 1 certification ?

According to Rankiteo, DiDi is not certified under SOC 2 Type 1.

Does DiDi have SOC 2 Type 2 certification ?

According to Rankiteo, DiDi does not hold a SOC 2 Type 2 certification.

Does DiDi comply with GDPR ?

According to Rankiteo, DiDi is not listed as GDPR compliant.

Does DiDi have PCI DSS certification ?

According to Rankiteo, DiDi does not currently maintain PCI DSS compliance.

Does DiDi comply with HIPAA ?

According to Rankiteo, DiDi is not compliant with HIPAA regulations.

Does DiDi have ISO 27001 certification ?

According to Rankiteo,DiDi is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.

Industry Classification of DiDi

DiDi operates primarily in the Software Development industry.

Number of Employees at DiDi

DiDi employs approximately 29,134 people worldwide.

Subsidiaries Owned by DiDi

DiDi presently has no subsidiaries across any sectors.

DiDi’s LinkedIn Followers

DiDi’s official LinkedIn profile has approximately 320,963 followers.

NAICS Classification of DiDi

DiDi is classified under the NAICS code 5112, which corresponds to Software Publishers.

DiDi’s Presence on Crunchbase

No, DiDi does not have a profile on Crunchbase.

DiDi’s Presence on LinkedIn

Yes, DiDi maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/didiglobal.

Cybersecurity Incidents Involving DiDi

As of December 11, 2025, Rankiteo reports that DiDi has experienced 1 cybersecurity incidents.

Number of Peer and Competitor Companies

DiDi has an estimated 27,532 peer or competitor companies worldwide.

What types of cybersecurity incidents have occurred at DiDi ?

Incident Types: The types of cybersecurity incidents that have occurred include Breach.

What was the total financial impact of these incidents on DiDi ?

Total Financial Loss: The total financial loss from these incidents is estimated to be $740 billion.

How does DiDi detect and respond to cybersecurity incidents ?

Detection and Response: The company detects and responds to cybersecurity incidents through an remediation measures with negotiation of $740 million settlement, remediation measures with compliance with cac orders, and communication strategy with public disclosure of settlement, communication strategy with legal filings in u.s. district court..

Incident Details

Can you provide details on each incident ?

Incident : Regulatory Non-Compliance

Title: DiDi Global's $740 Million Settlement Over Concealed Cybersecurity and Privacy Concerns in 2021 IPO

Description: DiDi Global agreed to a $740 million settlement in a class-action lawsuit accusing the company of defrauding investors by concealing a Chinese government order to delay its June 2021 IPO until cybersecurity and privacy concerns were resolved. The company faced regulatory penalties, including a $1.2 billion fine from China’s Cyberspace Administration, a ban on new customer registrations, and the removal of its app from stores. The settlement, pending judicial approval, follows DiDi’s disclosure of setting aside funds for the accord, resulting in a second-quarter loss.

Date Publicly Disclosed: 2021-07

Type: Regulatory Non-Compliance

Threat Actor: Chinese Government (Cyberspace Administration of China - CAC)

Motivation: Regulatory EnforcementData Privacy ComplianceInvestor Protection

What are the most common types of attacks the company has faced ?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident ?

Incident : Regulatory Non-Compliance DID3292232091125

Financial Loss: $740 million (settlement) + $1.2 billion (regulatory fine)

Operational Impact: Ban on new customer registrationsApp removal from smartphone storesSecond-quarter financial loss

Brand Reputation Impact: Significant (share price tumble, regulatory scrutiny, investor distrust)

Legal Liabilities: $740 million settlement + $1.2 billion fine

What is the average financial loss per incident ?

Average Financial Loss: The average financial loss per incident is $740.00 billion.

Which entities were affected by each incident ?

Incident : Regulatory Non-Compliance DID3292232091125

Entity Name: DiDi Global Inc.

Entity Type: Public Company (Ride-Hailing/Transportation)

Industry: Technology/Transportation

Location: China (Headquarters in Beijing)

Size: Large (Valued at ~$67.5 billion during IPO)

Response to the Incidents

What measures were taken in response to each incident ?

Incident : Regulatory Non-Compliance DID3292232091125

Remediation Measures: Negotiation of $740 million settlementCompliance with CAC orders

Communication Strategy: Public disclosure of settlementLegal filings in U.S. District Court

Data Breach Information

What measures does the company take to prevent data exfiltration ?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Negotiation of $740 million settlement, Compliance with CAC orders, .

Regulatory Compliance

Were there any regulatory violations and fines imposed for each incident ?

Incident : Regulatory Non-Compliance DID3292232091125

Regulations Violated: Chinese Cybersecurity Laws, Privacy Regulations, U.S. Securities Laws (alleged investor fraud),

Fines Imposed: $1.2 billion (CAC) + $740 million (settlement)

Legal Actions: Class-action lawsuit (In re DiDi Global Inc Securities Litigation), CAC regulatory penalties,

Regulatory Notifications: CAC ban on new registrationsApp removal from stores

How does the company ensure compliance with regulatory requirements ?

Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through Class-action lawsuit (In re DiDi Global Inc Securities Litigation), CAC regulatory penalties, .

References

Where can I find more information about each incident ?

Incident : Regulatory Non-Compliance DID3292232091125

Source: Reuters

Where can stakeholders find additional resources on cybersecurity best practices ?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Reuters.

Investigation Status

What is the current status of the investigation for each incident ?

Incident : Regulatory Non-Compliance DID3292232091125

Investigation Status: Settlement pending judicial approval (as of mid-October 2023)

How does the company communicate the status of incident investigations to stakeholders ?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Public Disclosure Of Settlement and Legal Filings In U.S. District Court.

Post-Incident Analysis

What were the root causes and corrective actions taken for each incident ?

Incident : Regulatory Non-Compliance DID3292232091125

Root Causes: Failure To Disclose Regulatory Orders To Investors, Non-Compliance With Chinese Cybersecurity/Privacy Laws,

Corrective Actions: Settlement Agreement, Compliance Overhaul (Implied),

What corrective actions has the company taken based on post-incident analysis ?

Corrective Actions Taken: The company has taken the following corrective actions based on post-incident analysis: Settlement Agreement, Compliance Overhaul (Implied), .

Additional Questions

General Information

Who was the attacking group in the last incident ?

Last Attacking Group: The attacking group in the last incident was an Chinese Government (Cyberspace Administration of China - CAC).

Incident Details

What was the most recent incident publicly disclosed ?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2021-07.

Impact of the Incidents

What was the highest financial loss from an incident ?

Highest Financial Loss: The highest financial loss from an incident was $740 million (settlement) + $1.2 billion (regulatory fine).

Regulatory Compliance

What was the highest fine imposed for a regulatory violation ?

Highest Fine Imposed: The highest fine imposed for a regulatory violation was $1.2 billion (CAC) + $740 million (settlement).

What was the most significant legal action taken for a regulatory violation ?

Most Significant Legal Action: The most significant legal action taken for a regulatory violation was Class-action lawsuit (In re DiDi Global Inc Securities Litigation), CAC regulatory penalties, .

References

What is the most recent source of information about an incident ?

Most Recent Source: The most recent source of information about an incident is Reuters.

Investigation Status

What is the current status of the most recent investigation ?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Settlement pending judicial approval (as of mid-October 2023).

cve

Latest Global CVEs (Not Company-Specific)

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.

Risk Information
cvss4
Base: 6.9
Severity: LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 9.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Description

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent querying, however, validation based on the first keyword (e.g., SELECT) and a forbidden-keyword list does not block file-writing constructs such as INTO OUTFILE / INTO DUMPFILE. As a result, an attacker who can influence the tool input (e.g., via prompt injection through a public agent endpoint) may write arbitrary files to the DB server if the MySQL/MariaDB account has the FILE privilege and server configuration permits writes to a useful location (e.g., a web-accessible directory). This issue is fixed in version 2.8.12.

Risk Information
cvss3
Base: 8.2
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Description

Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race conditions may arise from concurrent requests using the ApiClient class. This could cause a status code or response header from one request’s response to influence another request’s response. This issue is fixed in version 20.0.1.

Risk Information
cvss3
Base: 8.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Description

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.11.0 through 4.11.2 and 4.12.0, simultaneous requests on the same client may result in improper lookups in the TokenRequestCache for the request results. This issue is fixed in versions 4.11.2 and 4.12.1.

Risk Information
cvss3
Base: 5.4
Severity: HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=didiglobal' -H 'apikey: YOUR_API_KEY_HERE'

What Do We Measure ?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge