🚚 Transportation & Logistics¶
Airlines, shipping, ports, rail, logistics, supply chain · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed
Victims L30D5▼ −2
Prior 30D7
Active actor L90DQilin · 5
Active actor L90DAkira · 5
Active actor L90DUnknown · 3
Today — 12 Sep 2026¶
No industry-tagged items in today's briefing — see recent activity below.
Last 14 days¶
Recent victim claims¶
Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.
September 2026
Sep 04
Manchester Airports Group
FulcrumSec
8.8M traveller records (email, phone, vehicle reg, postcodes) published Sep 4 after MAG refused ransom; FulcrumSec extracted 86GB compressed / 550GB uncompressed from MAG's Iterable marketing platform using API credentials embedded in publicly visible website JavaScript — no network intrusion required; covers Manchester, London Stansted, and East Midlands airports; parking, lounge, Fast Track, Wi-Fi data; payment-card data not accessed; MAG disclosed Aug 27, FulcrumSec claimed Sep 1, data published Sep 4; UK ICO notified · Sources: https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/ · https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/
August 2026
Aug 27
Manchester Airports Group
Unknown
Cyberattack disclosed Aug 27 on Manchester, Stansted, and East Midlands airports; 8.7M customer records exposed including WiFi registrations, email addresses, phone numbers, vehicle registrations, parking/lounge bookings; payment data and passwords not stored on affected system; ransom demanded but not paid; actor unattributed · Sources: https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943 · https://cybernews.com/security/manchester-airport-cyber-attack-9-million-wifi-data-breach/
Aug 23
Difor
Qilin
Chilean distribution/retail company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-ransomware-group-strikes-chilean-company-difor/
Aug 22
Agunsa
Qilin
Qilin ransomware DLS claim August 2026; Agunsa is a major Chilean port and logistics services company; data scope unconfirmed · Sources: https://www.galaxywarden.com/blog/breach/agunsa-qilin-2026-08
Aug 21
JC Sales
Akira
Akira ransomware DLS claim August 21 2026; JC Sales is a full-service wholesaler based in Los Angeles; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 13
CF Supply
Akira
Akira DLS claim August 13, 2026; industrial supply distributor; scope unconfirmed. · Sources: https://www.ransomware.live/group/akira
Aug 04
North Carolina Ports (Wilmington, Morehead City, Charlotte Inland Port)
Unknown
Cyberattack detected Aug 4; ports operating manually with IT systems partially offline; NC DOIT, USCG, and external forensics engaged; no exfiltration confirmed · Sources: https://therecord.media/cyberattack-north-carolina-ports
July 2026
Jul 29
CEVA Logistics
Unknown
Cyberattack on 8 European warehouses (Jul 29 attack, Aug 1 notification); customer data (names, addresses, phones, emails, order data) exposed for clients including Valve/Steam, Ajax, banks, and retailers; Dutch DPA investigating; no ransomware deployed · Sources: https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
Jul 25
Yourway Transportation
Moneymessage
DLS posting July 25 2026 by Moneymessage. US transportation company. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 20
L&A Transport
Akira
US trucking company; Akira DLS claim July 20, 2026; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 15
Nihon Kotsu Co., Ltd.
AiLock
Malware attack July 11 disrupted taxi dispatch, hire-car reservation, and internal IT systems for Japan's largest taxi and limousine operator; no confirmed data exfiltration as of Jul 15 but investigation ongoing. Claimed on AiLock DLS July 15. · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/
Jul 15
Panasonic Avionics Corporation
Coinbasecartel
US-based Panasonic subsidiary supplying in-flight entertainment and connectivity systems to commercial airlines; Coinbasecartel DLS claim Jul 15, 2026; claimed data includes employee records, user accounts, third-party credentials, external attack surface; no encryption confirmed — data-theft-first extortion model; 🟥 unverified · Sources: https://ransomware.live/id/UGFuYXNvbmljQWVyb0Bjb2luYmFzZWNhcnRlbA== · https://www.breachsense.com/breaches/panasonic-avionics-data-breach/
Jul 14
Asimar (Asian Marine Service PCL)
DragonForce
Thailand's leading shipyard claimed on DragonForce DLS July 14; data type and volume unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 11
Bronken's Distributing
Qilin
Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 11
Nihon Kotsu
Unattributed
Japan's largest taxi and chauffeur operator; malware infection via unauthorised external access detected July 11; taxi dispatch, hire car web order/reservation management, and internal IT systems shut down for containment; no data exfiltration confirmed as of July 14; no group has claimed responsibility · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/ https://www.scworld.com/brief/japans-largest-taxi-operator-suffers-cyberattack-disrupts-services
Jul 03
Carvalima Transportes
INC Ransom
road transport and logistics company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 01
FAC Logistique
The Gentlemen
French logistics company; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]
June 2026
Jun 30
May Trucking Company
Embargo
family-owned interstate carrier founded 1945, headquartered in Brooks, Oregon; operates dry-van truckload, intermodal, and refrigerated freight services across the continental US; Embargo DLS claim June 30, 2026 (07:59 UTC); 1 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/d3d3Lm1heXRydWNraW5nLmNvbUBlbWJhcmdv · https://www.redpacketsecurity.com/embargo-ransomware-victim-www-maytrucking-com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 29
Axionlog
Qilin
Qilin DLS claim June 29, 2026; sector and data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 28
TransCore
Qilin
nationwide electronic toll collection and intelligent transportation systems provider (~$420M revenue, 2,068 employees; ST Engineering subsidiary; serves 8 of 10 largest US tolling agencies and provides traffic management systems worldwide); Qilin DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 24
JIT-EX LLC
Akira
regional and local truckload carrier (dedicated fleets, crossdock, transloading, storage trailer services); ~40GB claimed; includes employee SSNs, W-9 forms, driver's license documents, passport copies, and credit card details · https://www.redpacketsecurity.com/akira-ransomware-victim-jit-ex/ · https://www.ransomware.live/group/akira · Sources: [RedPacket Security] · [ransomware.live]
Jun 24
Transvill SRL
Nova
national and international road transport and cargo logistics; DLS claim June 24, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.redpacketsecurity.com/nova-ransomware-victim-transvill-com-pe/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 23
FTL-Fast Transit Line
Nova
Belgian logistics company; DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-targets-ftl-fast-transit-line/ · https://www.ransomware.live/group/nova · Sources: [DeXpose] · [ransomware.live]
Jun 23
Flughafen Wien AG
APT73
Austria's largest airport; APT73/Bashe DLS claim June 23, 2026; group alleges 500,000+ emails and 4,473 files exfiltrated including cargo manifests and weapons-transport records; airport confirmed targeted attack but stated incident was limited and did not affect flight operations; published documents described as outdated fragments posing no operational risk; no widespread encryption occurred — 🟥 unverified: airport disputes scope · https://www.dexpose.io/apt73-bashe-targets-vienna-airport-in-ransomware-attack/ · https://aviation.direct/erpressergruppe-bashe-mutmasslicher-cyberangriffs-auf-die-flughafen-wien-ag/ · Sources: [DeXpose] · [Aviation.Direct]
Jun 22
HDS Corp
Icarus
HD Supply Holdings; Icarus DLS claim June 22, 2026; exfiltrated compressed Salesforce data claimed via Klue supply chain OAuth token compromise; 🟥 unverified — no HD Supply public confirmation · https://www.dexpose.io/icarus-ransomware-attack-on-hds-corp/ · https://www.ransomware.live/group/icarus · Sources: [DeXpose] · [ransomware.live]
May 2026
May 06
Keretapi Tanah Melayu Berhad
The Gentlemen
Malaysia's national railway company; The Gentlemen DLS claim May 6, 2026; 3,858 employees and 8,428 users exposed; 21 third-party employee credentials and 143 external attack surface vulnerabilities identified; estimated attack date May 3, 2026; rail operations unaffected · https://www.dexpose.io/the-gentlemen-ransomware-group-targets-keretapi-tanah-melayu-berhad/ · https://www.ransomware.live/id/S2VyZXRhcGkgVGFuYWhAdGhlZ2VudGxlbWVu · Sources: [DeXpose] · [ransomware.live]