Skip to content

🚚 Transportation & Logistics

Airlines, shipping, ports, rail, logistics, supply chain · a shareable slice of the daily brief for stakeholders who only care about this industry · RSS feed

Victims L30D5▼ −2
Prior 30D7
Active actor L90DQilin · 5
Active actor L90DAkira · 5
Active actor L90DUnknown · 3

Today — 12 Sep 2026

No industry-tagged items in today's briefing — see recent activity below.

Last 14 days

Manchester Airports Group data actually published Sep 8 after MAG refused FulcrumSec's ransom demand — confirms the 8.8M-person scope first reported Sep 4.HighTransportation & LogisticsRoughly 550GB went up, including car-park, lounge and Fast Track booking records and in-terminal Wi-Fi sign-ups across Manchester, Stansted and East Midlands; MAG has confirmed operations were unaffected. No new tracker entry (already logged Sep 4) — this is confirmation the threat was executed, not a new incident. SecurityWeek
Manchester Airports Group / FulcrumSec — 8.8M traveller records published after ransom refusal; API credentials left in public JavaScriptCriticalTransportation & LogisticsFulcrumSec published roughly 550GB of uncompressed data (86GB compressed) on September 4 after Manchester Airports Group (MAG) declined to pay its ransom demand. The exfiltrated dataset covers parking bookings, lounge access, Fast Track purchases, and Wi-Fi sign-ups at three UK airports (Manchester, London Stansted, East Midlands), and contains email addresses, phone numbers, vehicle registrations, and postcodes for approximately 8.8 million people. Payment-card data was not accessed. Root cause: FulcrumSec extracted 86GB from MAG's Iterable marketing-automation platform using API credentials the group found embedded in publicly accessible JavaScript code on each airport's website — no network intrusion required. MAG disclosed the incident on August 27; FulcrumSec claimed responsibility September 1 and published September 4. UK ICO and relevant authorities have been notified. SecurityWeek · BleepingComputer · Infosecurity Magazine
FulcrumSec — MAG data published Sep 4; credential-in-JavaScript MO is repeatable at scaleHighTransportation & LogisticsFulcrumSec's attack against Manchester Airports Group required no network intrusion: the group harvested Iterable API credentials from publicly accessible JavaScript code. This MO — harvesting keys from frontend JS or CDN-hosted bundles — requires no exploit, is undetectable by traditional network monitoring, and applies to any organisation whose marketing/analytics platform is configured with client-side credentials. FulcrumSec is now confirmed as a distinct extortion actor with at least one major publication. BleepingComputer · SecurityAffairs
The FulcrumSec/MAG attack is the proof-of-concept that credential harvesting from public JavaScript is now a mass-scale extortion vector against large consumer-data platforms — no intrusion required, audit trails are minimal, and the liability is proportional to data volume, not attack sophistication.CriticalTransportation & LogisticsManchester Airports Group's Iterable API keys were embedded in publicly visible JavaScript — a configuration error that requires no exploit to weaponise, no network footprint to generate, and no EDR to evade. The result was 8.8 million records and the full extortion cycle in one operation. The attack pattern scales: any organisation with a marketing-automation or customer-data platform configured with client-side credentials is a structural equivalent target. For a PE portfolio holder, the risk is not in whether the company ran a secure network — it is in whether its customer-data platforms were audited for exposed credentials at the application layer. BleepingComputer · SecurityWeek

Recent victim claims

Newest first, mapped to this industry from the victim database. Most are leak-site claims — verify before acting.

September 2026

Sep 04 Manchester Airports Group FulcrumSec Ransomware · transportation/airports · UK 8.8M traveller records (email, phone, vehicle reg, postcodes) published Sep 4 after MAG refused ransom; FulcrumSec extracted 86GB compressed / 550GB uncompressed from MAG's Iterable marketing platform using API credentials embedded in publicly visible website JavaScript — no network intrusion required; covers Manchester, London Stansted, and East Midlands airports; parking, lounge, Fast Track, Wi-Fi data; payment-card data not accessed; MAG disclosed Aug 27, FulcrumSec claimed Sep 1, data published Sep 4; UK ICO notified · Sources: https://www.securityweek.com/manchester-airports-group-data-on-8-8-million-people-leaked-after-ransom-refusal/ · https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/

August 2026

Aug 27 Manchester Airports Group Unknown Ransomware · Transportation / Aviation · UK Cyberattack disclosed Aug 27 on Manchester, Stansted, and East Midlands airports; 8.7M customer records exposed including WiFi registrations, email addresses, phone numbers, vehicle registrations, parking/lounge bookings; payment data and passwords not stored on affected system; ransom demanded but not paid; actor unattributed · Sources: https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943 · https://cybernews.com/security/manchester-airport-cyber-attack-9-million-wifi-data-breach/
Aug 23 Difor Qilin Ransomware · Distribution · Chile Chilean distribution/retail company; Qilin DLS claim Aug 23 threatening data exposure · Sources: https://www.dexpose.io/qilin-ransomware-group-strikes-chilean-company-difor/
Aug 22 Agunsa Qilin Ransomware · Logistics / Port Services · Chile Qilin ransomware DLS claim August 2026; Agunsa is a major Chilean port and logistics services company; data scope unconfirmed · Sources: https://www.galaxywarden.com/blog/breach/agunsa-qilin-2026-08
Aug 21 JC Sales Akira Ransomware · Wholesale Distribution · USA Akira ransomware DLS claim August 21 2026; JC Sales is a full-service wholesaler based in Los Angeles; data scope unconfirmed · Sources: https://www.ransomware.live/
Aug 13 CF Supply Akira Ransomware · Distribution · US Akira DLS claim August 13, 2026; industrial supply distributor; scope unconfirmed. · Sources: https://www.ransomware.live/group/akira
Aug 04 North Carolina Ports (Wilmington, Morehead City, Charlotte Inland Port) Unknown Ransomware · Transportation / Critical Infrastructure · US Cyberattack detected Aug 4; ports operating manually with IT systems partially offline; NC DOIT, USCG, and external forensics engaged; no exfiltration confirmed · Sources: https://therecord.media/cyberattack-north-carolina-ports

July 2026

Jul 29 CEVA Logistics Unknown Ransomware · Logistics/Transportation · NLD Cyberattack on 8 European warehouses (Jul 29 attack, Aug 1 notification); customer data (names, addresses, phones, emails, order data) exposed for clients including Valve/Steam, Ajax, banks, and retailers; Dutch DPA investigating; no ransomware deployed · Sources: https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/
Jul 25 Yourway Transportation Moneymessage Ransomware · Logistics/Transportation · US DLS posting July 25 2026 by Moneymessage. US transportation company. Data scope unconfirmed. · Sources: https://www.ransomware.live/
Jul 20 L&A Transport Akira Ransomware · transportation · US US trucking company; Akira DLS claim July 20, 2026; data scope and impact unconfirmed; 🟥 unverified · Sources: DeXpose
Jul 15 Nihon Kotsu Co., Ltd. AiLock Ransomware · Transportation/Logistics · Japan Malware attack July 11 disrupted taxi dispatch, hire-car reservation, and internal IT systems for Japan's largest taxi and limousine operator; no confirmed data exfiltration as of Jul 15 but investigation ongoing. Claimed on AiLock DLS July 15. · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/
Jul 15 Panasonic Avionics Corporation Coinbasecartel Ransomware · technology (aviation / in-flight entertainment) · US US-based Panasonic subsidiary supplying in-flight entertainment and connectivity systems to commercial airlines; Coinbasecartel DLS claim Jul 15, 2026; claimed data includes employee records, user accounts, third-party credentials, external attack surface; no encryption confirmed — data-theft-first extortion model; 🟥 unverified · Sources: https://ransomware.live/id/UGFuYXNvbmljQWVyb0Bjb2luYmFzZWNhcnRlbA== · https://www.breachsense.com/breaches/panasonic-avionics-data-breach/
Jul 14 Asimar (Asian Marine Service PCL) DragonForce Ransomware · maritime · Thailand Thailand's leading shipyard claimed on DragonForce DLS July 14; data type and volume unconfirmed · Sources: https://www.ransomware.live/group/dragonforce
Jul 11 Bronken's Distributing Qilin Ransomware · distribution · wholesale/US Qilin DLS claim July 11, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jul 11 Nihon Kotsu Unattributed Breach · transportation · JP Japan's largest taxi and chauffeur operator; malware infection via unauthorised external access detected July 11; taxi dispatch, hire car web order/reservation management, and internal IT systems shut down for containment; no data exfiltration confirmed as of July 14; no group has claimed responsibility · Sources: https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-systems-after-cyberattack/ https://www.scworld.com/brief/japans-largest-taxi-operator-suffers-cyberattack-disrupts-services
Jul 03 Carvalima Transportes INC Ransom Ransomware · transportation-logistics · Portugal road transport and logistics company; INC Ransom DLS claim July 3, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/incransom · Sources: [ransomware.live]
Jul 01 FAC Logistique The Gentlemen Ransomware · logistics · France French logistics company; The Gentlemen DLS claim July 1, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.breachsense.com/breaches/2026/july/ · Sources: [Breachsense]

June 2026

Jun 30 May Trucking Company Embargo Ransomware · logistics · transportation/US family-owned interstate carrier founded 1945, headquartered in Brooks, Oregon; operates dry-van truckload, intermodal, and refrigerated freight services across the continental US; Embargo DLS claim June 30, 2026 (07:59 UTC); 1 TB exfiltrated claimed; data scope and impact unconfirmed; 🟥 unverified — no victim statement · https://www.ransomware.live/id/d3d3Lm1heXRydWNraW5nLmNvbUBlbWJhcmdv · https://www.redpacketsecurity.com/embargo-ransomware-victim-www-maytrucking-com/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 29 Axionlog Qilin Ransomware · logistics · supply chain/unknown region Qilin DLS claim June 29, 2026; sector and data scope unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 28 TransCore Qilin Ransomware · transportation technology · ITS/US nationwide electronic toll collection and intelligent transportation systems provider (~$420M revenue, 2,068 employees; ST Engineering subsidiary; serves 8 of 10 largest US tolling agencies and provides traffic management systems worldwide); Qilin DLS claim June 28, 2026; data scope and impact unconfirmed; 🟥 unverified · https://www.ransomware.live/group/qilin · Sources: [ransomware.live]
Jun 24 JIT-EX LLC Akira Ransomware · transportation · trucking-logistics/US regional and local truckload carrier (dedicated fleets, crossdock, transloading, storage trailer services); ~40GB claimed; includes employee SSNs, W-9 forms, driver's license documents, passport copies, and credit card details · https://www.redpacketsecurity.com/akira-ransomware-victim-jit-ex/ · https://www.ransomware.live/group/akira · Sources: [RedPacket Security] · [ransomware.live]
Jun 24 Transvill SRL Nova Ransomware · transportation-logistics · Peru national and international road transport and cargo logistics; DLS claim June 24, 2026; data scope and impact unconfirmed · https://www.ransomware.live/ · https://www.redpacketsecurity.com/nova-ransomware-victim-transvill-com-pe/ · Sources: [ransomware.live] · [RedPacket Security]
Jun 23 Leo International Akira Ransomware · supply chain · PVF/HVAC/plumbing products/US https://www.ransomware.live/group/akira · Sources: [ransomware.live]
Jun 23 FTL-Fast Transit Line Nova Ransomware · transportation-logistics · Belgium Belgian logistics company; DLS claim June 23, 2026; data scope and impact unconfirmed · https://www.dexpose.io/nova-ransomware-targets-ftl-fast-transit-line/ · https://www.ransomware.live/group/nova · Sources: [DeXpose] · [ransomware.live]
Jun 23 Flughafen Wien AG APT73 Ransomware · aviation · transportation/Austria Austria's largest airport; APT73/Bashe DLS claim June 23, 2026; group alleges 500,000+ emails and 4,473 files exfiltrated including cargo manifests and weapons-transport records; airport confirmed targeted attack but stated incident was limited and did not affect flight operations; published documents described as outdated fragments posing no operational risk; no widespread encryption occurred — 🟥 unverified: airport disputes scope · https://www.dexpose.io/apt73-bashe-targets-vienna-airport-in-ransomware-attack/ · https://aviation.direct/erpressergruppe-bashe-mutmasslicher-cyberangriffs-auf-die-flughafen-wien-ag/ · Sources: [DeXpose] · [Aviation.Direct]
Jun 22 HDS Corp Icarus Ransomware · wholesale distribution · US HD Supply Holdings; Icarus DLS claim June 22, 2026; exfiltrated compressed Salesforce data claimed via Klue supply chain OAuth token compromise; 🟥 unverified — no HD Supply public confirmation · https://www.dexpose.io/icarus-ransomware-attack-on-hds-corp/ · https://www.ransomware.live/group/icarus · Sources: [DeXpose] · [ransomware.live]
Jun 10 Port Air Express Akira Ransomware · logistics · — Sources: ransomware.live DLS
Jun 09 GDL Transport WorldLeaks Ransomware · logistics · Sweden Sources: ransomware.live DLS
Jun 08 Shipping Association of NY and NJ Qilin Ransomware · maritime-logistics · US Sources: ransomware.live DLS
Jun 08 Aegle Aviation RansomHouse Ransomware · aviation · India Sources: ransomware.live DLS
Jun 05 Avcon Jet Qilin Ransomware · aviation · Austria Sources: ransomware.live DLS

May 2026

May 06 Keretapi Tanah Melayu Berhad The Gentlemen Ransomware · transportation · railway/Malaysia Malaysia's national railway company; The Gentlemen DLS claim May 6, 2026; 3,858 employees and 8,428 users exposed; 21 third-party employee credentials and 143 external attack surface vulnerabilities identified; estimated attack date May 3, 2026; rail operations unaffected · https://www.dexpose.io/the-gentlemen-ransomware-group-targets-keretapi-tanah-melayu-berhad/ · https://www.ransomware.live/id/S2VyZXRhcGkgVGFuYWhAdGhlZ2VudGxlbWVu · Sources: [DeXpose] · [ransomware.live]

← All industries · Victim database →