The Containment Era is here. →Explore

Industry Category

Transportation

Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.

131 threat reports
Page 9 of 11

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Higher Education/Acadamia
Hospitality
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wireless

Transportation Threat Reports

Showing 97108 / 131 reports
Scattered Spider Strikes: 2024 Transport for London Cyber Breach
Impact· medium

Scattered Spider Strikes: 2024 Transport for London Cyber Breach

In August 2024, Transport for London (TfL), the body responsible for the UK's capital city transit system, suffered a major cyber incident allegedly orchestrated by members of the Scattered Spider cybercriminal group. Attackers exploited weaknesses in TfL's digital infrastructure to gain unauthorized access, compromising sensitive customer data and disrupting critical services. The breach, which resulted in millions of pounds in damages and regulatory scrutiny, underscored the growing threat that organized cybercriminal gangs pose to public-sector organizations. Two British teenagers have since been arrested and charged, though they have pleaded not guilty in court. This incident highlights the increasing trend of skilled threat actors leveraging sophisticated tactics—such as social engineering and lateral movement—to target essential services. Heightened regulatory pressure and public concern reinforce the urgent need for robust cybersecurity measures across critical infrastructure sectors.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Supply Chain Breach Hits Italian Rail Group via Almaviva: 2.3TB Data Stolen in 2024
Impact· high

Supply Chain Breach Hits Italian Rail Group via Almaviva: 2.3TB Data Stolen in 2024

In early June 2024, a threat actor claimed responsibility for breaching the Italian railway operator FS Italiane Group by targeting its IT services provider, Almaviva, resulting in the exfiltration of 2.3TB of sensitive data. The attackers reportedly gained initial access through compromised internal systems and leveraged this infiltration to move laterally, eventually accessing and downloading a vast trove of corporate documents, contracts, and possibly personal information related to employees and customers. The incident exposed Italy's transportation sector to significant risk of espionage, operational disruption, and data loss, igniting widespread concern among critical infrastructure operators. This breach highlights the mounting threat posed by attacks on trusted IT service providers, which serve as gateways to high-value targets. With the proliferation of supply chain and third-party compromise incidents globally, organizations in critical industries must reassess their lateral movement controls, segmentation, and third-party risk governance.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Iran-Linked Hackers Fuse Cyber Espionage and Kinetic Strikes with Ship AIS Breach
Impact· high

Iran-Linked Hackers Fuse Cyber Espionage and Kinetic Strikes with Ship AIS Breach

In November 2025, state-sponsored hackers tied to Iran conducted a sophisticated cyber operation targeting maritime assets by mapping Automatic Identification System (AIS) data of commercial ships transiting a volatile region. Advanced reconnaissance and cyber infiltration enabled the attackers to gather real-time ship movement and metadata, informing a coordinated missile strike days later. The breach demonstrated tight integration between cyber-enabled intelligence collection and traditional kinetic attacks, raising alarm within global shipping, defense, and infrastructure sectors. The incident highlights a dangerous evolution in the use of cyber capabilities to directly amplify physical-world conflict and disruption. The rapid fusion of cyber warfare with real-world military operations signals a new era of threats that transcend digital boundaries. As geopolitical tensions escalate and critical infrastructure remains vulnerable, robust cyber and operational defenses are imperative for organizations at risk of becoming targets in hybrid war campaigns.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
How Phishing-as-a-Service Scams Exploited USPS and E-Z Pass: The Lighthouse Case
Impact· medium

How Phishing-as-a-Service Scams Exploited USPS and E-Z Pass: The Lighthouse Case

In 2025, Google filed a legal complaint against a China-based cybercriminal group alleged to have developed 'Lighthouse' Phishing-as-a-Service (PaaS) kits. These kits empower low-skilled actors to execute widespread smishing (SMS phishing) and e-commerce scams by providing templates, domain setup tools, and fake websites mimicking trusted brands such as USPS and E-Z Pass. Victims are lured via texts about overdue fees or package deliveries, redirecting them to realistic phishing sites that harvest credentials and financial information. The campaign leveraged legitimate ad platforms and payment methods, increasing its reach and credibility. The incident underscores the rising threat and sophistication of PaaS offerings, which lower the barrier for cybercrime and accelerate the proliferation of phishing campaigns. As threat actors streamline attack automation and mimic reputable organizations, enterprises must adapt with real-time detection, segmented network defenses, and stronger authentication measures.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Critical Vulnerabilities in Railway Braking Systems Expose OT Security Gaps
Impact· medium

Critical Vulnerabilities in Railway Braking Systems Expose OT Security Gaps

In June 2024, security researchers discovered multiple vulnerabilities in the braking systems of modern trains, revealing that low-cost, readily available hardware could be used to exploit weaknesses in operational technology (OT) environments. Attackers demonstrated that by using items such as recycled cans and basic electronics sourced online, they could manipulate communication between the train conductor's controls and the braking systems. The lack of encrypted traffic and segmentation allowed malicious actors to reroute or interrupt braking commands, posing severe safety and operational risks to critical railway infrastructure. This incident underscores a broader trend of cyber-physical risk in OT systems, where traditional safety assumptions are being undermined by the exposure of legacy protocols and weak internal controls. As rail operators increasingly digitize and connect systems, adversaries have more opportunities to exploit gaps in lateral defenses and traffic security.

6 months ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(low)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Google Lawsuit Disrupts Lighthouse: Major Blow to Smishing Operations in 2024
Impact· medium

Google Lawsuit Disrupts Lighthouse: Major Blow to Smishing Operations in 2024

In early 2024, Google initiated legal action against the operators behind Lighthouse, an SMS phishing (smishing) platform used to impersonate legitimate services and lure victims into fraudulent payment schemes, such as fake unpaid road tolls. The suspected operators, commonly referred to as the Smishing Triad and believed to be based in China, leveraged the Lighthouse kit and Telegram groups to execute widespread phishing campaigns. Following Google's lawsuit in the Southern District of New York, Lighthouse's infrastructure, Telegram channels, and several associated domains were taken offline, significantly disrupting the group's activities and signaling a major blow to organized SMS phishing at scale. This incident underscores the growing role of civil litigation and collaboration between technology giants and threat intelligence firms in disrupting cybercriminal ecosystems. As smishing attacks rise in sophistication and frequency worldwide, organizations must ensure layered defenses and readiness for increasingly advanced social engineering threats.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Siemens LOGO! 8 Vulnerabilities Put Global ICS at Risk
Impact· high

Critical Siemens LOGO! 8 Vulnerabilities Put Global ICS at Risk

In November 2025, Siemens disclosed multiple critical vulnerabilities affecting its LOGO! 8 BM Devices, widely deployed in global commercial facilities and transportation systems. Security researchers from Thales Cybersecurity Services Australia identified flaws enabling unauthenticated remote attackers to exploit classic buffer overflow and missing authentication vulnerabilities. These flaws could allow malicious actors to execute arbitrary code, disrupt device operations via denial-of-service, or modify critical device parameters such as IP address and time settings, potentially impacting industrial operations. The incident underscores growing concerns about the security posture of industrial control systems (ICS), as attackers increasingly target remote management features lacking modern authentication. With regulatory scrutiny intensifying and attackers exploiting similar flaws in operational technology, organizations must prioritize ICS security and proactive patch management to reduce exposure.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(high)
Read Report
How Google Disrupted the Lighthouse Phishing-as-a-Service Operation in 2024
Impact· medium

How Google Disrupted the Lighthouse Phishing-as-a-Service Operation in 2024

In early 2024, Google’s Threat Analysis Group identified and disrupted the 'Lighthouse' Phishing-as-a-Service (PhaaS) platform, operated by the Smishing Triad criminal group. Lighthouse enabled large-scale, automated phishing campaigns, leveraging SMS-based lures such as unpaid toll notifications and fraudulent package delivery alerts. Attackers used this kit to collect personal and financial data, facilitating credentials theft across multiple geographies. Google’s intervention included technical disruption, reporting malicious domains, and restricting infrastructure linked to the group, limiting subsequent campaign reach and effectiveness. The Lighthouse case highlights a surge in professionally run phishing platforms offered as a service, making sophisticated cybercrime accessible to less-skilled actors. Organizations face heightened risk from increasingly tailored, high-volume phishing attacks exploiting mobile and digital payment ecosystems, warranting ongoing vigilance and stronger controls.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Google Sues to Dismantle Chinese 'Lighthouse' Phishing Platform Orchestrating US Toll Scams
Impact· medium

Google Sues to Dismantle Chinese 'Lighthouse' Phishing Platform Orchestrating US Toll Scams

In June 2024, Google filed a lawsuit to dismantle the 'Lighthouse' phishing-as-a-service (PhaaS) platform operated out of China. Lighthouse enabled global cybercriminals to launch large-scale SMS phishing campaigns, targeting U.S. residents by impersonating the U.S. Postal Service and E-ZPass toll systems. Attackers used automated infrastructure to send convincing text messages, directing victims to fraudulent sites designed to steal credit card and personal information. The campaign resulted in substantial financial losses for consumers and posed major operational risks to U.S. businesses and government agencies. This incident underscores the growing sophistication and accessibility of phishing-as-a-service offerings. With such turnkey solutions readily available on the dark web, attackers are able to scale campaigns with minimal technical skill, escalating both the frequency and severity of credential theft and fraud worldwide.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(medium)
Read Report
CISA Discloses 2025 ICS Vulnerabilities Affecting Critical Infrastructure
Impact· medium

CISA Discloses 2025 ICS Vulnerabilities Affecting Critical Infrastructure

In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five Industrial Control Systems (ICS) Advisories highlighting significant vulnerabilities impacting multiple vendors: Fuji Electric, Survision, Delta Electronics, Radiometrics, and IDIS. These advisories detail newly identified security issues, including unencrypted communication, improper authentication, and exploitable flaws exposing critical industrial and manufacturing systems to potential attack vectors. While no active exploitation has been publicly reported yet, the disclosed vulnerabilities could allow remote attackers to gain unauthorized access, disrupt operations, or compromise sensitive operational technology environments if left unaddressed. This incident underscores the ongoing and urgent need for proactive vulnerability management and timely patching within ICS environments. With an uptick in vulnerability disclosures and the rising convergence of IT and operational technology, threat actors continue to target unpatched systems in critical infrastructure, amplifying regulatory and business risk for operators in energy, manufacturing, and transportation sectors.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)
Impact· medium

Survision LPR Cameras: Unauthenticated Access Vulnerability (CVE-2025-12108)

In November 2025, a critical vulnerability (CVE-2025-12108) was disclosed in Survision License Plate Recognition (LPR) cameras, affecting all product versions globally. The flaw stems from missing authentication safeguards, allowing threat actors to remotely access device configuration wizards without credentials. This enables full system compromise—enabling attackers to alter settings, exfiltrate data, or use compromised cameras as entry points for broader attacks on commercial infrastructure. Researchers at Microsec identified the issue and notified stakeholders, prompting immediate remediation efforts and a firmware update (v3.5) from Survision. No confirmed active exploitation has been reported so far. With physical security increasingly integrated with digital management systems, unauthenticated access to surveillance infrastructure exposes environments to cyber-physical risks. The urgency of this disclosure reflects a broader industry trend: attackers actively seek exposed IoT and operational tech lacking basic authentication, prompting rising regulatory scrutiny and heightened compliance mandates.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Global Airports at Risk: Radiometrics VizAir 2025 Unauthenticated Access Exposes Critical Infrastructure
Impact· high

Global Airports at Risk: Radiometrics VizAir 2025 Unauthenticated Access Exposes Critical Infrastructure

In November 2025, critical vulnerabilities were publicly disclosed in Radiometrics VizAir, a system widely deployed in global airport transportation infrastructure. The flaws (CVE-2025-61945, CVE-2025-54863, CVE-2025-61956) permit unauthenticated remote attackers to manipulate weather parameters, runway settings, and extract sensitive meteorological data via missing authentication controls and exposed credentials. Exploitation could disrupt airport operations, mislead air traffic control and pilots, and create hazardous flight conditions by disabling vital alerts or injecting false data. The vulnerabilities were reported by a security researcher and were assigned the highest CVSS score of 10.0, reflecting severe risk to operational safety. This incident highlights the escalating risk facing critical infrastructure as attackers increasingly target operational technology systems with low-complexity, high-impact exploits. Given the global reliance on secure flight operations, the breach underscores the urgency for robust authentication, segmentation, and credential management controls across transportation-critical systems.

6 months ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports