✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Transportation
Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.
Explore Other Sectors
Transportation Threat Reports
Hackers Weaponize Remote Access: Cargo Freight Hijacking Hits Supply Chain
In early 2024, cybercriminals orchestrated a sophisticated supply-chain attack targeting the logistics sector by weaponizing remote monitoring and management (RMM) tools to seize control over freight operations. Exploiting weak access controls and leveraging legitimate remote-access software, attackers infiltrated trucking company systems and issued unauthorized commands, redirecting and physically stealing cargo from moving supply chains. This intrusion resulted in significant operational disruption, untraceable cargo losses, and highlighted severe gaps in network segmentation and east-west traffic security. This attack marks a rise in real-world impacts from IT compromise, illustrating how digital breaches are now driving tangible disruptions across critical infrastructure. The incident underscores escalating regulatory scrutiny and the urgency of advanced security controls to mitigate supply-chain and identity-driven threats.
6 months ago
Kill Chain
Freight Brokers Targeted: Hackers Use RMM Tools in Supply Chain Heist (2024)
In 2024, cybercriminals executed a targeted supply chain attack against freight brokerages and trucking carriers by exploiting phishing emails and malicious links. Attackers used remote monitoring and management (RMM) tools to infiltrate corporate systems, taking control of freight scheduling and logistics platforms. This allowed the threat actors to manipulate cargo shipments, redirect valuable freight, and orchestrate the theft of physical goods. The attack revealed significant gaps in internal segmentation, endpoint security, and east-west visibility, resulting in financial loss, disrupted operations, and reputational impact across the logistics sector. This incident highlights an emerging trend in the weaponization of legitimate IT tools like RMMs for high-value supply chain attacks. As threat actors innovate with living-off-the-land techniques, organizations with critical logistics functions face heightened scrutiny from regulators and renewed urgency to close visibility and segmentation gaps.
6 months ago
Kill Chain
Cybercriminals Infiltrate Logistics & Freight Networks with Malicious Remote Monitoring Tools
In June 2025, cybercriminals aligned with organized crime groups targeted logistics and freight organizations using malicious Remote Monitoring and Management (RMM) tools to infiltrate operational networks. Attackers gained entry via phishing campaigns that tricked employees into deploying unauthorized RMM software, providing persistent remote access for data exfiltration and, in some cases, facilitating theft of high-value cargo. The breach’s impact manifested in compromised shipment scheduling, disrupted fleet operations, and direct financial loss due to fraudulent transactions and stolen cargo. This incident underscores the growing trend of attackers exploiting legitimate IT tools for financial crime, particularly across critical supply chain infrastructure. The prevalence of infostealer malware and stealthy remote-access attacks highlights the urgency for logistics companies to strengthen segmentation, adopt zero trust models, and improve anomaly detection.
6 months ago
Kill Chain
Siemens 2025: Missing Authentication Flaw in TeleControl Server Threatens Industrial Security
In October 2025, Siemens disclosed a critical authentication vulnerability (CVE-2025-40765) affecting TeleControl Server Basic V3.1 (versions before V3.1.2.3). The flaw, rated CVSS 9.3/10, allows remote, unauthenticated attackers to obtain user password hashes and perform authenticated actions on the database service. The vulnerability exposes critical manufacturing infrastructure worldwide, potentially enabling attackers to manipulate or disrupt automated industrial processes by escalating privileges. Siemens and CISA provided immediate mitigations, including patching and network access controls. This incident highlights the persistent risks from missing authentication controls in OT/ICS applications, at a time when remote exploitation targeting critical infrastructure is rapidly rising. The disclosure underscores the importance of timely patch management and network segmentation for industrial environments facing evolving cyber threats.
6 months ago
Kill Chain
Critical Siemens RUGGEDCOM ROS Vulnerabilities Expose Industrial Control Systems in 2025
In October 2025, Siemens disclosed several critical vulnerabilities in its RUGGEDCOM ROS industrial control system devices used globally in critical manufacturing sectors. The flaws include the use of weak cryptographic algorithms, improper handling of exceptional conditions, and protection mechanism failures, making affected devices susceptible to man-in-the-middle attacks, denial-of-service, and potential unauthorized access until device reboot. Exploitation is possible remotely with low complexity, allowing attackers to compromise encrypted communications or persist on non-management interfaces. This incident is especially relevant as supply chains and critical infrastructure increasingly adopt ICS/OT devices that, if not properly secured, expose entire operations to disruption. The persistence of cryptographic weaknesses and the growing sophistication of adversaries underscore the urgent need for robust, up-to-date security controls across the ICS ecosystem.
6 months ago
Kill Chain
Veeder-Root TLS4B Vulnerabilities Expose Energy Sector to Remote Attacks in 2025
In October 2025, critical vulnerabilities were disclosed in the Veeder-Root TLS4B Automatic Tank Gauge System, widely deployed across the global energy sector. Security researcher Pedro Umbelino reported a severe command injection flaw (CVE-2025-58428) in the SOAP-based web service, enabling attackers with valid credentials to execute system-level commands, gain shell access, and potentially move laterally within targeted networks. A second vulnerability (CVE-2025-55067) affects time handling, potentially enabling attackers to cause authentication failures and denial of service by exploiting the Unix epoch rollover issue. Both vulnerabilities are remotely exploitable and threaten operational continuity, device functionality, and network integrity. This incident highlights the growing exposure of industrial control systems to sophisticated, remotely exploitable vulnerabilities. With the energy sector’s increasing reliance on interconnected OT devices, attackers are targeting control interfaces and authentication flaws to achieve deeper network access, reinforcing the urgent need for proactive risk assessments and robust segmentation strategies.
6 months ago
Kill Chain
ISO 15118-2 EV Charging Protocol Vulnerability: Man-in-the-Middle Risk in 2025
In October 2025, a critical vulnerability (CVE-2025-12357) impacting the ISO 15118-2 standard for electric vehicle (EV) chargers was disclosed. The flaw centers on improper restriction of communication channels, specifically enabling attackers to exploit the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements. This manipulation facilitates man-in-the-middle attacks between EVs and compliant chargers, with attacks feasible wirelessly and in close proximity via electromagnetic induction. The vulnerability jeopardizes authentication and data exchange during the EV charging process but has not yet been publicly exploited. The incident highlights escalating risks across connected infrastructure, especially as EV adoption surges globally. As regulators, manufacturers, and utility providers converge on charging protocols, the need for mandatory end-to-end encryption is increasingly urgent to safeguard against evolving threat actors targeting critical transportation sectors.
6 months ago
Kill Chain
NSA-Linked Cyberattack Highlights Risks to China’s National Time Service Center (2023–2024)
Between March 2022 and June 2024, China’s National Time Service Center reportedly fell victim to a sophisticated cyber-espionage campaign allegedly orchestrated by the U.S. National Security Agency (NSA). Attackers initially compromised employee mobile devices via a text-messaging service vulnerability, leading to credential theft and enabling unauthorized access to the Center’s internal systems by April 2023. From August 2023 onward, the NSA purportedly leveraged a suite of 42 advanced cyber tools to target sensitive infrastructure, using VPNs and forged certificates to evade detection and bypass defenses. The attack put critical services at risk, with potential consequences including network disruption, financial system instability, and interruptions to vital communications and national defense functions. This incident underscores escalating nation-state cyber competition, especially over foundational infrastructure. The methods used—mobile device exploitation, lateral movement, and evasion through encrypted channels—reflect trending Tactics, Techniques, and Procedures (TTPs) in state-sponsored attacks, raising concerns for governments and critical sectors worldwide about supply chain and timing-related risks.
6 months ago
Kill Chain
Spain Shuts Down GXC Team: Crime-as-a-Service Powerhouse Busted in 2025
In May 2025, Spanish authorities dismantled the "GXC Team" cybercrime syndicate, arresting its alleged leader, a 25-year-old Brazilian known as "GoogleXcoder." Operating as a Crime-as-a-Service (CaaS) provider, the group developed and sold AI-powered phishing kits, multiple Android malware strains, and social engineering voice-scam tools, primarily via Telegram and Russian-speaking hacker forums. Their phishing operations targeted financial, transport, and e-commerce institutions in Spain, Slovakia, the UK, the US, and Brazil, facilitating large-scale credential theft through more than 250 spoofed sites. Law enforcement recovered stolen cryptocurrency, seized electronic evidence, and shut down illicit channels. The investigation, enabled by forensic analysis of devices and crypto transactions, remains ongoing, with further arrests anticipated. This incident highlights the rise of CaaS platforms using automation, AI, and malware-as-a-service approaches to accelerate phishing and fraud at scale. The GXC Team case underscores the evolving sophistication and reach of these criminal ventures, which now target numerous sectors globally and leverage encrypted communications to obfuscate operations.
6 months ago
Kill Chain
The ShinyHunters Salesforce Extortion Spree: Lessons for Modern SaaS Security
In May 2025, the ShinyHunters/Scattered LAPSUS$ Hunters cybercrime coalition initiated a coordinated data extortion campaign against numerous Fortune 500 companies, exploiting voice phishing tactics to compromise Salesforce portals. Attackers tricked privileged users into connecting malicious applications, leading to the theft of over a billion customer records across companies such as Toyota, FedEx, Disney/Hulu, and UPS. Following the attacks, ShinyHunters launched a public shaming and extortion blog, threatening to publish the stolen data unless victims surrendered to ransom demands. Multiple related incidents included attacks on Red Hat's GitLab servers and Discord via a third-party support contractor, impacting sensitive business and PII data. Law enforcement action traced the threats to a blend of established groups, operating globally and leveraging emerging zero-day exploits. This breach underscores the increasing sophistication and scale of identity-driven and extortion-centered cyberattacks targeting cloud SaaS platforms. It coincides with a resurgence in social engineering, as threat actors exploit both technical vulnerabilities and human factors. The event highlights the urgency for robust controls around SaaS access, third-party risk, and east-west data movement visibility.
6 months ago
Kill Chain
Storm-1175 Exploits GoAnywhere Zero-Day to Orchestrate Ransomware Attacks in 2024
In September 2024, Microsoft Threat Intelligence announced that Storm-1175, a financially motivated ransomware affiliate, exploited a critical zero-day vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT file transfer solution. Attackers gained remote code execution, established persistence via remote monitoring tools and web shells, performed lateral movement using legitimate Windows utilities, and exfiltrated data with Rclone before deploying Medusa ransomware in targeted organizations. Impacted sectors included transportation, education, retail, insurance, and manufacturing. The initial compromises began on September 11, days before the vulnerability was publicly disclosed or patched, giving attackers a significant advantage and facilitating stealthy, high-impact breaches due to delayed vendor transparency. This incident highlights the escalating sophistication of ransomware operations leveraging zero-day exploits and legitimate IT tools to evade detection, resulting in substantial business disruption and data loss. Growing regulatory scrutiny and industry concern underscore the urgent need for rapid threat intelligence sharing, proactive zero trust measures, and improved vendor communication in light of similar recent attacks.
6 months ago
Kill Chain
ParkMobile 2021 Data Breach: Lessons from a 22 Million User Exposure
In March 2021, ParkMobile, a widely used parking payment platform, suffered a significant data breach that exposed sensitive information of nearly 22 million users. Threat actors exploited a vulnerability in the company’s third-party software, exfiltrating a 4.5 GB dataset containing names, email addresses, phone numbers, license plate data, mailing addresses, usernames, bcrypt-hashed passwords, and vehicle information. The full database was later leaked on a popular hacking forum, fueling risks of identity theft and fraud. Legal proceedings culminated in late 2024, with ParkMobile settling a class action lawsuit by offering $1 in-app credits per user. The breach highlights persistent challenges around protecting personal data, enforcing regulatory standards, and responding to data leaks in the mobility and payments sector. It emphasizes the urgent need for encrypted communications, strong segmentation, and robust threat detection as organizations confront increasingly sophisticated attack methods and legal repercussions.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports