Transportation & Logistics — Cyber Threat Activity
Transportation and logistics is attacked for what it moves, not only for what it earns. Our log records more than 650 incidents across 69 countries, over 180 in the trailing 180 days, with 68 groups attributed at least one claim: Qilin (68), Cl0p (60), Akira (58), Play (46) and LockBit (39) lead. Three separate threat models converge here. The first is ordinary extortion against carriers, freight forwarders and third-party logistics firms, where a halted dispatch system strands physical cargo and the clock is measured in demurrage. The second is fraud that uses network access as its instrument rather than its objective: the FBI reported cyber-enabled strategic cargo theft surging to nearly $725 million in estimated US and Canadian losses in 2025, executed by compromising broker and carrier accounts, bidding on genuine loads, then re-brokering them with altered paperwork and diverting the shipment. That attack leaves an IT incident and a missing truck, and it is frequently misfiled as one or the other. The third is state espionage. CISA and allied agencies attributed a sustained campaign by Russian military intelligence unit 26165 against Western logistics entities coordinating aid into Ukraine, including the use of internet-exposed cameras near border crossings and rail stations to watch materiel move. Recorded geography is United States-led at 267 claims, then Canada, the United Kingdom, Germany, France and Brazil. Treat these as extortion-site claims rather than confirmed breaches, and note that the cargo-theft and espionage activity above largely does not generate leak-site posts at all, so the count understates the sector's real threat picture by design.
- Recorded incidents: 795
- Incidents, trailing 180 days: 213
- Tracked threat actors: 96
- Malware families: 42
Recent incidents
- Touring Club Suisse 2026-09-20
- Alicotrans 2026-09-14
- RoadEx America 2026-09-14
- Navitrans 2026-09-13
- Capricorn Logistics Pvt. Ltd. 2026-09-12
- Egyptian Airports Company (EAC) 2026-09-12
- Perimetral Oriental de Bogotá S.A.S. 2026-09-11
- Port of Tanjung Pelepas 2026-09-11
- Air Canada 2026-09-09
- Precision Vehicle Logistics 2026-09-07
- Metrea LLC/Commuter Air Technology, Inc. 2026-09-05
- Philippine Ports Authority 2026-09-05
- Mega Velocity 2026-09-05
- Lider Aviacao 2026-09-05
- Star Aviation, Inc 2026-09-03
- Trucka 2026-09-02
- Cartrack Holdings 2026-09-02
- Transportes Montejo S.A.S. 2026-09-01
- Manchester Airports Group 2026-09-01
- Transportes Montejo S.A.S. 2026-09-01
Threat actors targeting Transportation & Logistics
- Qilin 90 incidents
- Cl0p 71 incidents
- Akira 62 incidents
- Play Ransomware 46 incidents
- LockBit 42 incidents
- RansomHub 41 incidents
- The Gentlemen 34 incidents
- DragonForce 30 incidents
- INC Ransom 30 incidents
- Lynx Ransomware 26 incidents
- SafePay 25 incidents
- Hunters International 16 incidents
- BianLian 15 incidents
- KillSec 15 incidents
- NightSpire 14 incidents
- Black Basta 14 incidents
- Medusa Ransomware 14 incidents
- 8Base 10 incidents
- BlackSuit 10 incidents
- Fog Ransomware 10 incidents
- Cactus 9 incidents
- Rhysida 8 incidents
- ShinyHunters 8 incidents
- Krybit 7 incidents
Where these victims are
- United States 301
- Canada 52
- Germany 31
- United Kingdom 26
- France 22
- Brazil 20
- Australia 18
- Italy 18
- Malaysia 14
- Mexico 13
- India 12
- Spain 12
Malware used against Transportation & Logistics
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Agent Tesla Malware
- Cobalt Strike Malware
- Impacket Tool
- Mimikatz Tool
- PsExec Tool
- Sliver Tool
- AADInternals Tool
- AsyncRAT Tool
- Babuk Malware
- LaZagne Tool
- NetSupport Manager Tool
- NETWIRE Malware
Coverage. 94.9% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.