✨ No need to do from scratch. Deploy a Validated Containment Architecture built for your AI platform. →Deploy a Validated Containment Architecture for your AI platform. →A Validated Containment Architecture for your AI platform. →Validated Containment Architectures are here. →Contain Threats NowExplore✨
Logistics/Procurement
Breach intelligence, attack campaigns, and threat reports targeting the Logistics/Procurement sector.
Explore Other Sectors
Logistics/Procurement Threat Reports
Cyberattack Disrupts North Carolina Ports Operations in August 2026
In early August 2026, the North Carolina Ports Authority experienced a cyberattack that disrupted IT systems across the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. The incident, detected on August 4, led to a system-wide outage, causing operational delays and affecting cargo handling. The authority activated its cybersecurity contingency plan, initiating recovery efforts on August 5. While operations began returning to normal by August 7, residual delays persisted as system restoration continued. The specific nature of the attack, the threat actor involved, and whether sensitive data was compromised remain undisclosed. This incident underscores the escalating cyber threats targeting critical infrastructure, particularly in the maritime sector. Ports are increasingly becoming focal points for cyberattacks, highlighting the need for robust cybersecurity measures and contingency planning to mitigate operational disruptions and safeguard sensitive data.
2 days ago
Kill Chain
Cyberattack Disrupts Operations at North Carolina Ports in 2026
In early August 2026, a cyberattack targeted the North Carolina State Ports Authority, disrupting gate operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. The breach led to delays in gate openings and necessitated a shift to manual processing as the authority worked to contain the intrusion. The U.S. Coast Guard, along with other state and federal agencies, is actively investigating the incident to determine the nature and extent of the attack. This incident underscores the escalating cyber threats facing critical infrastructure sectors, including maritime transportation. The attack on North Carolina's ports highlights the urgent need for enhanced cybersecurity measures and collaboration among federal and state agencies to protect essential services from sophisticated cyber adversaries.
3 days ago
Kill Chain
OnTrac Data Breach 2026: What You Need to Know
In March 2026, OnTrac, a prominent U.S. parcel delivery company, detected unauthorized access to its corporate network. The breach, occurring between March 20 and 22, potentially exposed customer personal information, including names. The company has not disclosed the full extent of the data compromised. In response, OnTrac engaged third-party cybersecurity experts to assess the breach and implemented measures to secure the affected data. Additionally, they are offering impacted customers a 12-month complimentary credit monitoring and identity protection service through CyberScout. This incident underscores the escalating threat landscape facing logistics and delivery services, highlighting the critical need for robust cybersecurity measures. As cyberattacks on supply chain entities become more frequent, organizations must prioritize the protection of sensitive customer data to maintain trust and compliance with regulatory standards.
2 weeks ago
Kill Chain
Nichirei Cyberattack: A Wake-Up Call for Supply Chain Security
In July 2026, Nichirei Corporation, a leading Japanese frozen food and logistics company, experienced a significant cyberattack attributed to the RansomHouse group. The attack disrupted operations across approximately 140 distribution centers, affecting major clients like Kentucky Fried Chicken Japan, which faced ingredient shortages and operational challenges. The breach led to system failures, particularly in refrigerated warehouse and frozen food shipping services, causing widespread supply chain disruptions. Nichirei collaborated with external cybersecurity firms and authorities to investigate and mitigate the incident, aiming to fully resume operations by the end of the week. This incident underscores the escalating threat of ransomware attacks targeting critical supply chains, highlighting the need for robust cybersecurity measures and incident response strategies. Organizations must prioritize securing their digital infrastructures to prevent similar disruptions and protect sensitive data from malicious actors.
2 weeks ago
Kill Chain
CyberAv3ngers' 2026 Attacks on U.S. Critical Infrastructure: A Wake-Up Call for OT Security
In early 2026, the Iranian-affiliated cyber group CyberAv3ngers, linked to the Islamic Revolutionary Guard Corps (IRGC), launched a series of cyberattacks targeting U.S. critical infrastructure sectors, including water, energy, and local government facilities. The attackers exploited internet-exposed Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), such as CompactLogix and Micro850 models, to gain unauthorized access, manipulate data displayed on human-machine interfaces (HMIs), and disrupt operations. These incidents resulted in operational disruptions and financial losses for the affected organizations. ([risidata.com](https://www.risidata.com/Database/Detail/iran-cyberav3ngers-plc-us-infrastructure-2026?utm_source=openai)) This campaign underscores the escalating cyber threat posed by state-sponsored actors targeting industrial control systems (ICS) and operational technology (OT) environments. Organizations must prioritize securing internet-facing OT devices, implement robust access controls, and maintain up-to-date patch management to mitigate such risks.
1 month ago
Kill Chain
Phantom Stealer: The Rise of Fileless Malware Targeting Financial Institutions
In June 2026, a sophisticated phishing campaign targeted banks and high-value organizations, deploying Phantom Stealer—a fileless malware designed to evade traditional endpoint defenses. The attack began with phishing emails containing seemingly legitimate business documents. Upon opening, a heavily obfuscated batch file initiated a multistage infection chain, injecting Phantom Stealer into the Windows Explorer process. Operating entirely in memory, the malware silently exfiltrated browser credentials, session cookies, and financial data through multiple channels, including Telegram, Discord, FTP, and SMTP. This incident underscores the evolving tactics of cybercriminals, highlighting the increasing use of fileless malware and advanced evasion techniques. Organizations must enhance their security posture by adopting behavior-based detection systems and educating employees on recognizing sophisticated phishing attempts to mitigate such threats.
1 month ago
Kill Chain
Critical Vulnerability in Universal Robots' PolyScope 5: CVE-2026-8153
In May 2026, a critical command injection vulnerability (CVE-2026-8153) was discovered in the Dashboard Server interface of Universal Robots' PolyScope 5 software. This flaw allowed unauthenticated attackers with network access to execute arbitrary commands on the robot's operating system, potentially leading to full system compromise. Universal Robots promptly addressed the issue by releasing version 5.25.1, which patches the vulnerability. Organizations utilizing affected versions are strongly advised to update immediately to mitigate potential risks. This incident underscores the growing cybersecurity challenges in operational technology (OT) environments, particularly as industrial systems become more interconnected. The exploitation of such vulnerabilities can lead to significant operational disruptions and safety hazards, highlighting the need for robust security measures and timely software updates in critical infrastructure.
2 months ago
Kill Chain
Cyber-Enabled Cargo Theft: A $725 Million Wake-Up Call for the Transportation Industry
In 2025, cybercriminals orchestrated a series of sophisticated attacks targeting the transportation and logistics sectors, resulting in approximately $725 million in cargo theft losses across North America. These threat actors employed phishing emails, spoofed websites, and compromised carrier accounts to infiltrate freight brokers and carriers. Once inside, they posted fraudulent listings on load boards, deceiving legitimate carriers into transporting shipments to unauthorized destinations controlled by the criminals. This method allowed entire truckloads of goods, including pharmaceuticals and consumer products, to be rerouted and stolen without physical hijacking. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260430?utm_source=openai)) The surge in cyber-enabled cargo theft underscores the evolving tactics of organized crime, blending traditional theft with advanced cyber techniques. This trend highlights the urgent need for enhanced cybersecurity measures within the transportation industry to protect against such multifaceted threats.
2 months ago
Kill Chain
Surge in Cyber-Enabled Cargo Theft: A 2025 Analysis
In 2025, cargo theft losses in the United States and Canada surged by 60%, reaching an estimated $725 million. This increase is attributed to cybercriminals employing sophisticated tactics such as phishing, impersonation, and system compromises to hijack goods during transit. By infiltrating supply chain systems, these actors rerouted shipments, leading to significant financial and operational disruptions for businesses. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260430?utm_source=openai)) The FBI's April 30, 2026, public service announcement underscores the evolving nature of cargo theft, emphasizing the integration of cyber techniques into traditional theft methods. This trend highlights the urgent need for enhanced cybersecurity measures within the transportation and logistics sectors to mitigate the risks posed by these advanced threats. ([ic3.gov](https://www.ic3.gov/PSA/2026/PSA260430?utm_source=openai))
3 months ago
Kill Chain
FBI Reports 60% Increase in Cyber-Enabled Cargo Thefts in 2025
In 2025, the FBI reported a 60% increase in cyber-enabled cargo thefts across the U.S. and Canada, totaling nearly $725 million in losses. Threat actors infiltrated freight brokers and carriers through phishing emails and fake web links, gaining unauthorized access to systems. They then posted fraudulent listings on online load boards, impersonated legitimate companies, and diverted high-value shipments for resale. The Diesel Vortex group, active since September 2025, targeted freight and logistics operators in the U.S. and Europe, compromising numerous platforms and stealing credentials. This surge underscores the evolving tactics of cybercriminals who exploit digital vulnerabilities to execute physical thefts. The transportation and logistics sectors must enhance cybersecurity measures to protect against such sophisticated attacks.
3 months ago
Kill Chain
Understanding the TeamPCP Supply Chain Attack of March 2026
In March 2026, the threat actor group TeamPCP executed a sophisticated supply chain attack, compromising widely used developer tools including Aqua Security's Trivy, Checkmarx's KICS, and the LiteLLM Python package. By exploiting stolen credentials, they injected credential-stealing malware into these tools, leading to the exfiltration of sensitive data such as API keys, cloud service credentials, and source code from numerous organizations. The attack unfolded rapidly over a span of five days, with each compromised tool serving as a vector to infiltrate the next, demonstrating the cascading risks inherent in supply chain vulnerabilities. This incident underscores the critical importance of securing the software supply chain, especially as attackers increasingly target trusted development tools to gain unauthorized access. Organizations must implement robust security measures, including regular credential rotation, stringent access controls, and continuous monitoring of CI/CD pipelines, to mitigate the risks associated with such attacks.
3 months ago
Kill Chain
Mazda's 2025 Data Breach: A Wake-Up Call for Supply Chain Security
In December 2025, Mazda Motor Corporation identified unauthorized access to a warehouse management system associated with parts procured from Thailand. The breach exposed 692 records containing user IDs, full names, email addresses, company names, and business partner IDs. No customer data was involved. Mazda promptly reported the incident to Japan's Personal Information Protection Commission and implemented enhanced security measures, including reducing internet exposure, applying security patches, increasing monitoring for suspicious activity, and introducing stricter access policies. This incident underscores the persistent threat of cyberattacks targeting supply chain systems. Organizations must remain vigilant, as such breaches can lead to phishing attacks and scams targeting exposed individuals. Implementing robust security protocols and continuous monitoring is essential to mitigate these risks.
4 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports