✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Logistics/Procurement
Breach intelligence, attack campaigns, and threat reports targeting the Logistics/Procurement sector.
Explore Other Sectors
Logistics/Procurement Threat Reports
How Insider Threats and Malware Breached Rotterdam and Antwerp Ports
Between September 2020 and April 2021, a Dutch national infiltrated IT systems across major European ports, including Rotterdam and Antwerp, by leveraging insider access at a logistics firm. Employees inserted USB sticks laden with malware, providing the hacker with persistent access to sensitive server infrastructure. Through remote access tools, the attacker intercepted data in transit, exfiltrated critical databases, and enabled large-scale smuggling operations—including the undetected import of 210 kg of cocaine—while also attempting extortion and resale of malware. This incident highlights the evolving intersection of cybercrime with organized crime, particularly how threat actors exploit insider vectors to orchestrate large-scale physical and digital breaches. The case underscores urgent regulatory and cyber defense challenges facing port operators and logistics networks globally.
6 months ago
Kill Chain
Jaguar Land Rover Hit by Devastating 2025 Ransomware Attack: Supply Chains & Data at Risk
In September 2025, Jaguar Land Rover (JLR) suffered a devastating ransomware and extortion attack attributed to the Scattered Lapsus$ Hunters collective, a group comprising threat actors from Lapsus$, Scattered Spider, and ShinyHunters. The attackers breached JLR’s systems, forcing the automaker to halt production and send staff home. The resulting multi-week operational disruption led to a 43% drop in wholesale volumes in the third quarter, significant delays in fulfilling orders, and the confirmed theft of sensitive data. The financial toll exceeded £196 million ($220 million), prompting emergency UK government intervention to support JLR’s supply chain recovery. This incident underscores the evolving risk faced by global manufacturers from sophisticated, identity-centric ransomware actors employing both operational disruption and data theft for extortion. It highlights a broader trend of targeted attacks against critical supply chains, compounding economic impacts and regulatory scrutiny across industries.
6 months ago
Kill Chain
Kimsuky Leverages QR Phishing to Spread Android Malware in Fake Delivery App Campaign (2025)
In June 2025, the North Korean threat group Kimsuky launched a sophisticated phishing campaign using QR codes that directed victims to malicious websites impersonating South Korean logistics giant CJ Logistics. Unsuspecting users who scanned the QR codes and interacted with fake prompts were tricked into downloading and executing the DocSwap Android malware. The malware enabled unauthorized access to sensitive device data and communications, potentially allowing attackers to conduct surveillance and lateral movement within enterprise environments. The incident highlights the versatility of Kimsuky’s tactics and the growing risk to mobile users targeted via supply-chain or delivery-themed phishing. Kimsuky's campaign reflects a broader industry-wide uptick in mobile phishing and social engineering attacks that leverage QR codes and trusted brands. This case demonstrates how advanced persistent threat actors are pivoting to circumvent traditional detection, pushing organizations to adopt holistic mobile and endpoint security strategies.
6 months ago
Kill Chain
Phantom Stealer Phishing: 2025 Attack Hits Russian Finance via ISO Emails
In late 2025, an active phishing campaign dubbed "Operation MoneyMount-ISO" began targeting the Russian financial sector and related industries, with threat actors distributing phishing emails containing malicious ISO disk image attachments. Once opened, these ISO files delivered the Phantom Stealer malware, enabling attackers to exfiltrate sensitive data from finance, accounting, procurement, legal, and payroll departments. The malware operated covertly, seeking credentials and financial information, leading to notable data exposure risks and potential regulatory disruptions for victim organizations. This campaign highlights the increasing sophistication of phishing operations leveraging disk image formats for initial access and the persistent targeting of high-value sectors with advanced infostealer malware. Financial and critical infrastructure organizations face heightened pressure to improve detection and segmentation as threat actors continually refine their social engineering tactics.
6 months ago
Kill Chain
Askul Hit by RansomHouse: 740,000 Customer Records Stolen in 2023 Ransomware Attack
In October 2023, Japanese e-commerce giant Askul Corporation suffered a ransomware attack attributed to the RansomHouse group. Attackers infiltrated Askul's systems, exfiltrating approximately 740,000 customer records containing sensitive personal and contact details before deploying ransomware to encrypt internal data. The breach forced Askul to temporarily suspend some business operations while it investigated the extent of the compromise. The attackers reportedly demanded a ransom in exchange for not releasing the stolen data, putting immense pressure on both customer trust and company reputation. This incident highlights the ongoing threat posed by sophisticated ransomware groups targeting large enterprises, especially in the retail and e-commerce sectors. The scale and impact underscore the necessity for organizations to strengthen data protection, incident response, and segmentation controls, as ransomware actors increasingly focus on data theft before encryption to maximize leverage.
6 months ago
Kill Chain
GrayBravo's CastleLoader: 2025’s Multicluster MaaS Campaign Hits the Logistics Sector
In early to late 2025, the threat actor known as GrayBravo (formerly TAG-150) orchestrated multiple large-scale cyberattacks leveraging CastleLoader, a sophisticated malware loader distributed under a malware-as-a-service (MaaS) model. Four coordinated threat clusters exploited CastleLoader to compromise organizations—particularly in logistics—via phishing, malvertising, and credential harvesting. Attackers used fraudulent accounts on freight-matching platforms to enhance deception, delivering a range of information stealers and remote access trojans, including CastleRAT, RedLine Stealer, and NetSupport RAT. Multi-tiered infrastructure supported resilient operations and facilitated rapid malware deployment, leading to significant business and security disruption for targeted sectors. This incident illustrates an escalating threat trend: advanced MaaS tooling like CastleLoader rapidly proliferates across the cybercrime ecosystem, enabling both seasoned and novice criminals to launch complex, high-impact attacks. The campaign underscores attackers’ increasing industry expertise, adaptation to detection, and exploitation of legitimate business platforms to maximize credibility and impact.
6 months ago
Kill Chain
Broadside Mirai Variant Disrupts Maritime Logistics Sector in 2024
In early 2024, a novel Mirai variant dubbed 'Broadside' was discovered targeting maritime logistics organizations by exploiting a critical command injection flaw in exposed DVR systems. Attackers leveraged this vulnerability to gain persistent access, hijack the devices, and enable lateral movement across internal shipping infrastructure. Once compromised, infected endpoints became part of a botnet, amplifying the campaign’s impact and potentially threatening the operational continuity of global maritime logistics firms. The incident underscores growing risks faced by critical infrastructure sectors as IoT-targeting malware evolves. Mirai and its variants continue to adapt, now seeking less-conventional, specialized equipment in sectors previously overlooked, further complicating defense and regulatory compliance for logistics organizations worldwide.
6 months ago
Kill Chain
Brightpick ICS Flaws Expose Critical Automation Functions and Credentials Globally
In November 2025, vulnerabilities were discovered in Brightpick AI's Mission Control and Internal Logic Control, software used for warehouse automation globally. Security researcher Souvik Kandar disclosed that all product versions lacked authentication for critical functions and exposed sensitive credentials via unencrypted channels, including WebSocket traffic accessible without prior authentication. If exploited, attackers could manipulate robot controls or intercept sensitive information, posing operational and confidentiality risks to organizations in sectors such as manufacturing, healthcare, and logistics. Brightpick AI had not issued a response or patch at the time of the initial disclosure. This incident stands out due to its impact on operational technology and industrial control systems, highlighting the widespread risk of exposed critical functions and hardcoded credentials in automation platforms. With growing connectivity in ICS environments, such vulnerabilities reflect an urgent need for organizations to bolster segmentation, credential management, and network security controls.
6 months ago
Kill Chain
Hackers Weaponize Remote Access: Cargo Freight Hijacking Hits Supply Chain
In early 2024, cybercriminals orchestrated a sophisticated supply-chain attack targeting the logistics sector by weaponizing remote monitoring and management (RMM) tools to seize control over freight operations. Exploiting weak access controls and leveraging legitimate remote-access software, attackers infiltrated trucking company systems and issued unauthorized commands, redirecting and physically stealing cargo from moving supply chains. This intrusion resulted in significant operational disruption, untraceable cargo losses, and highlighted severe gaps in network segmentation and east-west traffic security. This attack marks a rise in real-world impacts from IT compromise, illustrating how digital breaches are now driving tangible disruptions across critical infrastructure. The incident underscores escalating regulatory scrutiny and the urgency of advanced security controls to mitigate supply-chain and identity-driven threats.
6 months ago
Kill Chain
Freight Brokers Targeted: Hackers Use RMM Tools in Supply Chain Heist (2024)
In 2024, cybercriminals executed a targeted supply chain attack against freight brokerages and trucking carriers by exploiting phishing emails and malicious links. Attackers used remote monitoring and management (RMM) tools to infiltrate corporate systems, taking control of freight scheduling and logistics platforms. This allowed the threat actors to manipulate cargo shipments, redirect valuable freight, and orchestrate the theft of physical goods. The attack revealed significant gaps in internal segmentation, endpoint security, and east-west visibility, resulting in financial loss, disrupted operations, and reputational impact across the logistics sector. This incident highlights an emerging trend in the weaponization of legitimate IT tools like RMMs for high-value supply chain attacks. As threat actors innovate with living-off-the-land techniques, organizations with critical logistics functions face heightened scrutiny from regulators and renewed urgency to close visibility and segmentation gaps.
6 months ago
Kill Chain
Cybercriminals Infiltrate Logistics & Freight Networks with Malicious Remote Monitoring Tools
In June 2025, cybercriminals aligned with organized crime groups targeted logistics and freight organizations using malicious Remote Monitoring and Management (RMM) tools to infiltrate operational networks. Attackers gained entry via phishing campaigns that tricked employees into deploying unauthorized RMM software, providing persistent remote access for data exfiltration and, in some cases, facilitating theft of high-value cargo. The breach’s impact manifested in compromised shipment scheduling, disrupted fleet operations, and direct financial loss due to fraudulent transactions and stolen cargo. This incident underscores the growing trend of attackers exploiting legitimate IT tools for financial crime, particularly across critical supply chain infrastructure. The prevalence of infostealer malware and stealthy remote-access attacks highlights the urgency for logistics companies to strengthen segmentation, adopt zero trust models, and improve anomaly detection.
6 months ago
Kill Chain
Ransomware Attack on Asahi Disrupts Brewery Operations and Beer Supply in 2024
In early June 2024, the Japanese beverage giant Asahi Group was hit by a ransomware attack that significantly disrupted its domestic brewery operations. Threat actors targeted the company's IT systems, crippling order processing and distribution networks for several days, which led to product shortages and impacted supply chain partners and customers. Asahi confirmed that while immediate containment steps were taken and an investigation was launched, operational downtime and order backlogs persisted as recovery efforts continued, demonstrating the real-world impact of cyberattacks on manufacturing and logistics. This incident highlights the rising trend of ransomware gangs targeting critical sectors like manufacturing, exploiting supply chain dependencies to maximize business disruption and force rapid ransom demands. With attackers increasingly prioritizing operational technology and just-in-time industries, organizations must revisit segmentation, east-west controls, and rapid incident response capabilities to keep pace.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports