The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Transportation
Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.
Explore Other Sectors
Transportation Threat Reports
ISO 15118-2 EV Charging Protocol Vulnerability: Man-in-the-Middle Risk in 2025
In October 2025, a critical vulnerability (CVE-2025-12357) impacting the ISO 15118-2 standard for electric vehicle (EV) chargers was disclosed. The flaw centers on improper restriction of communication channels, specifically enabling attackers to exploit the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements. This manipulation facilitates man-in-the-middle attacks between EVs and compliant chargers, with attacks feasible wirelessly and in close proximity via electromagnetic induction. The vulnerability jeopardizes authentication and data exchange during the EV charging process but has not yet been publicly exploited. The incident highlights escalating risks across connected infrastructure, especially as EV adoption surges globally. As regulators, manufacturers, and utility providers converge on charging protocols, the need for mandatory end-to-end encryption is increasingly urgent to safeguard against evolving threat actors targeting critical transportation sectors.
8 months ago
Kill Chain
NSA-Linked Cyberattack Highlights Risks to China’s National Time Service Center (2023–2024)
Between March 2022 and June 2024, China’s National Time Service Center reportedly fell victim to a sophisticated cyber-espionage campaign allegedly orchestrated by the U.S. National Security Agency (NSA). Attackers initially compromised employee mobile devices via a text-messaging service vulnerability, leading to credential theft and enabling unauthorized access to the Center’s internal systems by April 2023. From August 2023 onward, the NSA purportedly leveraged a suite of 42 advanced cyber tools to target sensitive infrastructure, using VPNs and forged certificates to evade detection and bypass defenses. The attack put critical services at risk, with potential consequences including network disruption, financial system instability, and interruptions to vital communications and national defense functions. This incident underscores escalating nation-state cyber competition, especially over foundational infrastructure. The methods used—mobile device exploitation, lateral movement, and evasion through encrypted channels—reflect trending Tactics, Techniques, and Procedures (TTPs) in state-sponsored attacks, raising concerns for governments and critical sectors worldwide about supply chain and timing-related risks.
8 months ago
Kill Chain
Spain Shuts Down GXC Team: Crime-as-a-Service Powerhouse Busted in 2025
In May 2025, Spanish authorities dismantled the "GXC Team" cybercrime syndicate, arresting its alleged leader, a 25-year-old Brazilian known as "GoogleXcoder." Operating as a Crime-as-a-Service (CaaS) provider, the group developed and sold AI-powered phishing kits, multiple Android malware strains, and social engineering voice-scam tools, primarily via Telegram and Russian-speaking hacker forums. Their phishing operations targeted financial, transport, and e-commerce institutions in Spain, Slovakia, the UK, the US, and Brazil, facilitating large-scale credential theft through more than 250 spoofed sites. Law enforcement recovered stolen cryptocurrency, seized electronic evidence, and shut down illicit channels. The investigation, enabled by forensic analysis of devices and crypto transactions, remains ongoing, with further arrests anticipated. This incident highlights the rise of CaaS platforms using automation, AI, and malware-as-a-service approaches to accelerate phishing and fraud at scale. The GXC Team case underscores the evolving sophistication and reach of these criminal ventures, which now target numerous sectors globally and leverage encrypted communications to obfuscate operations.
8 months ago
Kill Chain
The ShinyHunters Salesforce Extortion Spree: Lessons for Modern SaaS Security
In May 2025, the ShinyHunters/Scattered LAPSUS$ Hunters cybercrime coalition initiated a coordinated data extortion campaign against numerous Fortune 500 companies, exploiting voice phishing tactics to compromise Salesforce portals. Attackers tricked privileged users into connecting malicious applications, leading to the theft of over a billion customer records across companies such as Toyota, FedEx, Disney/Hulu, and UPS. Following the attacks, ShinyHunters launched a public shaming and extortion blog, threatening to publish the stolen data unless victims surrendered to ransom demands. Multiple related incidents included attacks on Red Hat's GitLab servers and Discord via a third-party support contractor, impacting sensitive business and PII data. Law enforcement action traced the threats to a blend of established groups, operating globally and leveraging emerging zero-day exploits. This breach underscores the increasing sophistication and scale of identity-driven and extortion-centered cyberattacks targeting cloud SaaS platforms. It coincides with a resurgence in social engineering, as threat actors exploit both technical vulnerabilities and human factors. The event highlights the urgency for robust controls around SaaS access, third-party risk, and east-west data movement visibility.
8 months ago
Kill Chain
Storm-1175 Exploits GoAnywhere Zero-Day to Orchestrate Ransomware Attacks in 2024
In September 2024, Microsoft Threat Intelligence announced that Storm-1175, a financially motivated ransomware affiliate, exploited a critical zero-day vulnerability (CVE-2025-10035) in Fortra's GoAnywhere MFT file transfer solution. Attackers gained remote code execution, established persistence via remote monitoring tools and web shells, performed lateral movement using legitimate Windows utilities, and exfiltrated data with Rclone before deploying Medusa ransomware in targeted organizations. Impacted sectors included transportation, education, retail, insurance, and manufacturing. The initial compromises began on September 11, days before the vulnerability was publicly disclosed or patched, giving attackers a significant advantage and facilitating stealthy, high-impact breaches due to delayed vendor transparency. This incident highlights the escalating sophistication of ransomware operations leveraging zero-day exploits and legitimate IT tools to evade detection, resulting in substantial business disruption and data loss. Growing regulatory scrutiny and industry concern underscore the urgent need for rapid threat intelligence sharing, proactive zero trust measures, and improved vendor communication in light of similar recent attacks.
8 months ago
Kill Chain
ParkMobile 2021 Data Breach: Lessons from a 22 Million User Exposure
In March 2021, ParkMobile, a widely used parking payment platform, suffered a significant data breach that exposed sensitive information of nearly 22 million users. Threat actors exploited a vulnerability in the company’s third-party software, exfiltrating a 4.5 GB dataset containing names, email addresses, phone numbers, license plate data, mailing addresses, usernames, bcrypt-hashed passwords, and vehicle information. The full database was later leaked on a popular hacking forum, fueling risks of identity theft and fraud. Legal proceedings culminated in late 2024, with ParkMobile settling a class action lawsuit by offering $1 in-app credits per user. The breach highlights persistent challenges around protecting personal data, enforcing regulatory standards, and responding to data leaks in the mobility and payments sector. It emphasizes the urgent need for encrypted communications, strong segmentation, and robust threat detection as organizations confront increasingly sophisticated attack methods and legal repercussions.
8 months ago
Kill Chain
Renault and Dacia UK 2025: Customer Data Breach Highlights Supply Chain Risks
In October 2025, Renault and Dacia UK notified customers of a data breach resulting from a cyberattack at an undisclosed third-party provider. The breach exposed sensitive information including full names, gender, phone numbers, email and postal addresses, as well as vehicle identification and registration numbers. While no financial data was compromised, this incident potentially increases the risk of phishing, scams, and targeted social engineering. Renault confirmed that the third-party provider contained the incident and regulatory authorities, including the UK’s Information Commissioner's Office, were notified as part of standard response. This event highlights the persistent risks posed by supply chain vulnerabilities, where companies are exposed through third-party relationships. As cyberattackers increasingly target vendors to bypass primary defenses, organizations must intensify scrutiny of their supply chains and enhance segmentation, monitoring, and incident response to align with evolving regulatory and threat landscapes.
8 months ago
Kill Chain
RTX Ransomware Attack Disrupts Major European Airports in 2025
In September 2025, RTX Corporation (formerly Raytheon Technologies) experienced a significant ransomware attack targeting its Collins Aerospace Multi-User System Environment (MUSE) passenger processing platform. The ransomware—suspected to be from the Hardbit or Loki ransomware families—caused widespread operational disruptions, leading to flight cancellations and delays at major European airports including London Heathrow, Brussels, Cork, Dublin, and Berlin. The attack was detected on September 19th, prompting RTX to initiate a full incident response, notify authorities, and deploy technical mitigations across affected customer networks. Law enforcement arrested a UK-based suspect linked to the attack, underscoring the event’s criminal intent and sophistication. This incident highlights a rising trend of ransomware groups targeting critical infrastructure and supply chain applications, often by leveraging commodity Ransomware-as-a-Service (RaaS) tools. It also signals a shift in attacker behavior towards less sophisticated malware, which can still yield significant operational disruption due to integrated, shared technology platforms in aviation and other sectors.
8 months ago
Kill Chain
How a Single Weak Password Caused the Collapse of KNP Logistics
In August 2023, KNP Logistics Group—one of the UK’s oldest haulage companies—fell victim to a catastrophic ransomware attack after cybercriminals exploited a weak, reused password to gain initial access. The attackers leveraged this compromised credential to breach internal systems, move laterally, and deploy ransomware, severely encrypting business-critical data. Operations halted, hundreds of employees were affected, and the incident ultimately forced the 158-year-old business into administration, marking a rare instance where a cyberattack directly led to company collapse. This breach exemplifies a growing wave of highly disruptive ransomware attacks exploiting basic identity and password hygiene gaps. As threat actors increasingly target legacy industries and critical infrastructure with credential-based intrusions, the risk to business continuity is escalating—pressing organizations to reevaluate access controls and cyber resilience.
8 months ago
Kill Chain
Ransomware Attack Disrupts Major European Airports via Collins Aerospace in 2025
In September 2025, a major ransomware attack on Collins Aerospace, a critical provider of check-in and boarding systems, triggered widespread disruptions at several major European airports, including Heathrow, Brussels, and Berlin Brandenburg. The hackers targeted the Multi-User System Environment (MUSE) platform, which airlines rely on to coordinate check-in desks and gate assignments. As a result, more than 100 flights were delayed or cancelled, and thousands of passengers faced manual check-in procedures while airports scrambled to contain the operational fallout. Law enforcement and cybersecurity agencies are actively investigating, prioritizing the restoration of affected systems and mitigation of further impact. This incident underlines the escalating risk posed by ransomware targeting supply chain infrastructure and the aviation sector’s reliance on shared IT systems. It also reflects a broader trend of cybercriminals exploiting third-party service dependencies, bringing renewed urgency to layered defense strategies and zero-trust adoption for business-critical environments.
8 months ago
Kill Chain
Airport Check-In Disruption: 2024 Supply-Chain Breach at Heathrow
In June 2024, a major disruption struck multiple European airports, including London Heathrow, after a cyberattack targeted a third-party provider responsible for check-in kiosk software. The supply-chain attack led to widespread check-in outages, flight delays, and cancellations, impacting thousands of travelers over the weekend. Initial investigation suggests that attackers compromised the software vendor’s infrastructure—potentially with ransomware or through lateral movement via third-party access—causing operational downtime for airlines and airport operators relying on their services. The incident highlights growing dependency risks stemming from the use of specialized external IT vendors in critical national infrastructure, especially in aviation. This event underscores the accelerating trend of supply-chain attacks, where threat actors exploit weaker links outside direct company control. With aviation systems under heightened scrutiny and ransomware groups often targeting critical operations, organizations across sectors must reevaluate third-party security, segmentation, and visibility to mitigate cascading impacts from vendor compromises.
8 months ago
Kill Chain
Teen Hackers Arrested for Scattered Spider Cyber Attack on TfL in 2024
In August 2024, Transport for London (TfL) experienced a cyber attack attributed to teen members of the Scattered Spider hacking group, known for leveraging social engineering and identity compromise. Attackers allegedly gained access to internal systems, disrupting service operations and putting critical transport and passenger information at risk. U.K. authorities arrested Thalha Jubair (19) and Owen Flowers (18) in September 2024 for their involvement, underlining the rapid evolution of cybercriminal tactics and the challenge of securing public infrastructure. This incident is a prime example of increasingly sophisticated attacks leveraging compromised credentials and insider tactics, even involving younger threat actors. It highlights both the threat to public services and the urgency for robust Zero Trust controls amid a landscape of rising identity-driven intrusions.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports