The breach isn’t the problem. The spread is. →Free Assessment

Industry Category

Transportation

Breach intelligence, attack campaigns, and threat reports targeting the Transportation sector.

173 threat reports
Page 2 of 15

Explore Other Sectors

Accounting
Aerospace
Aerospace/Aviation
Agriculture
Airlines/Aviation
Animation
Apparel/Fashion
Architecture/Planning
Artificial Intelligence
Artificial Intelligence/Machine Learning
Arts/Crafts
Automotive
Aviation/Aerospace
Banking/Mortgage
Biotechnology/Greentech
Blockchain/Cryptocurrency
Broadcast Media
Broadcasting Media
Broadcasting/Media
Building Materials
Business Supplies/Equipment
Capital Markets/Hedge Fund/Private Equity
Chemical
Chemicals
Civic/Social Organization
Civil Engineering
Cloud Computing
Cloud Computing/SaaS
Cloud Services
Commercial Facilities
Commercial Real Estate
Computer Games
Computer Hardware
Computer Networking
Computer Software/Engineering
Computer/Network Security
Construction
Consulting
Consumer Electronics
Consumer Goods
Consumer Services
Cosmetics
Cosmetics
Critical Manufacturing
Cryptocurrencies
Cryptocurrency
Customer Services
Cybersecurity
Dairy
Dating/Personal Services
Dating/Social Platforms
Defense/Space
Design
E-Learning
Education Management
Electrical/Electronic Manufacturing
Emergency Services
Energy
Energy/Oil/Solar/Greentech
Entertainment/Movie Production
Environmental Services
Events Services
Facilities Services
Farming
Fashion/Apparel
Financial Services
Fine Art
Fishery
Food Production
Food/Beverages
Fortune 500 companies
Franchising
Fundraising
Gambling/Casinos
Gaming
Gaming/Casinos
Government Administration
Government Facilities
Government Relations
Graphic Design/Web Design
Health Care / Life Sciences
Healthcare
Higher Education/Acadamia
Hospitality
Hospitals
Human Resources/HR
Import/Export
Individual/Family Services
Industrial Automation
Information Services
Information Technology/IT
Insurance
International Affairs
International Trade/Development
Internet
Investment Banking/Venture
Investment Management/Hedge Fund/Private Equity
Judiciary
Law Enforcement
Law Practice/Law Firms
Legal Services
Legislative Office
Leisure/Travel
Logistics/Procurement
Luxury Goods/Jewelry
Machinery
Management Consulting
Manufacturing
Maritime
Marketing/Advertising/Sales
Mechanical or Industrial Engineering
Media Production
Medical Equipment
Medical Practice
Military Industry
Mining/Metals
Mobile
Museums/Institutions
Music
Newspapers/Journalism
Non-Profit/Volunteering
Oil/Energy/Solar/Greentech
Online Publishing
Outsourcing/Offshoring
Package/Freight Delivery
Parking
Pharmaceuticals
Philanthropy
Photography
Plastics
Political Organization
Primary/Secondary Education
Professional Services
Professional Training
Public Relations/PR
Public Safety
Publishing Industry
Railroad Manufacture
Real Estate/Mortgage
Recreational Facilities/Services
Religious Institutions
Renewables/Environment
Research Industry
Restaurants
Retail Industry
Robotics
Rural Healthcare
Security/Investigations
Semiconductors
Shipbuilding
Social Media/Internet
Sporting Goods
Sports
Staffing/Recruiting
Supermarkets
Technology
Technology/IT
Telecommunications
Think Tanks
Toys and Games
Transportation
Travel/Tourism
Trucking/Freight
Utilities
Venture Capital/VC
Warehousing
Water and Waste Management
Water and Wastewater
Water and Wastewater Systems
Water and Wastewater Treatment
Water Treatment
Water, Waste, Steam, and Air Conditioning Services
Water/Waste Management
Water/Wastewater
Water/Wastewater Management
Water/Wastewater/Utilities
Wholesale
Wine/Spirits
Wireless
Writing/Editing

Transportation Threat Reports

Showing 13–24 / 173 reports
Massive Identity Verification Breach: 153M Driver's Licenses Compromised at IDScan.net
Impact· CRITICAL

Massive Identity Verification Breach: 153M Driver's Licenses Compromised at IDScan.net

In September 2026, a new identity theft service called Nexus launched on the dark web selling digital scans of over 153 million drivers licenses from the United States and Canada. The breach appears to originate from Louisiana-based identity verification company IDScan.net, which provides services to major clients including Hertz, Target, FedEx, and numerous marijuana dispensaries. The stolen data includes infrared and ultraviolet scans with timestamps indicating continuous exfiltration over more than a year, prompting an FBI investigation by the New Orleans field office. This massive identity document breach represents one of the largest exposures of state-issued identification data in U.S. history, with attackers offering licenses of high-profile government officials including Defense Secretary Pete Hegseth and FBI leadership. The incident highlights critical vulnerabilities in third-party identity verification systems that process over 21 million verifications monthly across 20,000 locations worldwide.

3 weeks ago

Kill Chain

IC
Initial Compromise(low)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
AI-Powered Cyber Campaigns Expose New Threat Landscape in Latin America
Impact· HIGH

AI-Powered Cyber Campaigns Expose New Threat Landscape in Latin America

Two sophisticated AI-enhanced cyber campaigns targeted organizations across Latin America in 2026, demonstrating how threat actors are integrating artificial intelligence into their attack workflows. The first campaign (CL-CRI-1131) targeted Mexican transportation companies and government entities using living-off-the-land techniques and self-hosted NextChat instances for AI assistance. The second campaign (CL-CRI-1163) focused on Brazilian financial institutions, employing custom remote access trojans and Go-based SOCKS5 proxies with AI-generated naming conventions. Both campaigns utilized commercial large language models like ChatGPT and Claude to overcome technical obstacles, generate exploit scripts, and streamline post-exploitation activities. Despite enhanced technical capabilities through AI integration, the attackers exposed their operations through poor operational security, including unsecured staging directories and publicly accessible NextChat interfaces. This represents a significant evolution in regional threat landscapes where diverse threat groups are independently adopting AI to accelerate their attack capabilities while maintaining fundamental security weaknesses that defenders can exploit.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(high)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(medium)
Read Report
Russian APT UAC-0099 Exploits AI Security Tools with GuardBreaker Prompt Injection
Impact· HIGH

Russian APT UAC-0099 Exploits AI Security Tools with GuardBreaker Prompt Injection

In September 2026, ESET researchers disclosed a new technique called GuardBreaker employed by Russia-aligned threat actor UAC-0099 against Ukrainian targets. The attack involved embedding provocative text about nuclear weapons creation into malicious VBS scripts to deliberately trigger AI safety mechanisms and prevent automated analysis. The technique aims to force large language models into refusal states, allowing malware like the MATCHBOIL loader to evade AI-assisted security workflows. This represents a sophisticated evolution in adversarial prompt injection, specifically designed to exploit the safety guardrails of modern AI security tools. This incident highlights the growing threat of AI-targeted evasion techniques as organizations increasingly rely on automated security analysis. With AI copilots and LLM-based scanners becoming standard in security operations, attackers are developing specific countermeasures to blind these systems, creating new vulnerabilities in modern defense strategies.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(low)
I
Impact(medium)
Read Report
Berlin Government Refuses Ransom After Rhysida Steals 5.79TB of Citizen Data
Impact· MEDIUM

Berlin Government Refuses Ransom After Rhysida Steals 5.79TB of Citizen Data

In August 2026, the Rhysida ransomware group successfully infiltrated Berlin's state administrative network, exfiltrating 5.79 terabytes of data including personal information on over 12,000 individuals between August 7-12. The attackers gained initial access through compromised VPN credentials and deployed double extortion tactics, demanding ransom payment while threatening to leak stolen government data. Berlin's leadership, including Governing Mayor Kai Wegner, publicly refused to pay the ransom despite ongoing extortion attempts, maintaining operations while conducting forensic investigation with federal authorities. This incident highlights the continued evolution of ransomware groups targeting critical government infrastructure, particularly as threat actors like Rhysida increasingly focus on high-profile public sector victims to maximize pressure and potential payouts through leaked sensitive citizen data.

3 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
Critical Vulnerabilities Expose All-Line Equipment Fuel-Boss Industrial Control Systems to Remote Attacks
Impact· CRITICAL

Critical Vulnerabilities Expose All-Line Equipment Fuel-Boss Industrial Control Systems to Remote Attacks

All-Line Equipment Company's Fuel-Boss industrial control systems across multiple variants (Standard, Portal, Master/Slave, and Backflush Systems) contain critical vulnerabilities CVE-2018-19518 and CVE-2019-11043 affecting PHP 7.1.5 implementations. These vulnerabilities enable remote code execution through argument injection and buffer overflow attacks, with CVSS scores reaching 8.7-9.4. The systems are deployed worldwide across critical infrastructure sectors including manufacturing, defense, emergency services, and transportation. While fixes are available for Standard and Portal variants, Master/Slave systems remain unpatched and Backflush Systems will not receive updates, leaving significant exposure in operational technology environments. This incident highlights the growing convergence of IT and OT security risks as legacy industrial systems with outdated software components become increasingly connected to enterprise networks and the internet, creating new attack vectors for threat actors targeting critical infrastructure.

4 weeks ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Critical Password Hash Vulnerability Exposes Rockwell Automation Fleet Management Systems
Impact· MEDIUM

Critical Password Hash Vulnerability Exposes Rockwell Automation Fleet Management Systems

Rockwell Automation's OTTO Fleet Manager versions 2.36.2 and earlier contain a critical vulnerability (CVE-2026-75112) involving insufficient computational effort in bcrypt password hashing implementation. This weakness reduces the computational cost for attackers to perform offline brute-force attacks against stored password hashes if they gain access to unencrypted system backups. The vulnerability affects industrial fleet management systems used worldwide in critical manufacturing and transportation sectors, with Rockwell Automation releasing version 2.36.3 to address the issue. This incident highlights the growing threat to industrial control systems and the critical importance of proper cryptographic implementations in operational technology environments, particularly as threat actors increasingly target industrial infrastructure with sophisticated attack techniques.

4 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(low)
Read Report
Manchester Airports Group Breach Exposes 8.9 Million Travelers' Data in Major Aviation Cyber Attack
Impact· MEDIUM

Manchester Airports Group Breach Exposes 8.9 Million Travelers' Data in Major Aviation Cyber Attack

In August 2026, Manchester Airports Group (MAG), the UK's largest airport operator managing Manchester, London Stansted, and East Midlands airports, suffered a significant data breach affecting up to 8.9 million travelers. Attackers accessed customer databases containing Wi-Fi registration details, car park bookings, lounge reservations, and Fast Track services, compromising email addresses, phone numbers, vehicle registration numbers, and postcodes. While payment card data remained secure and airport operations continued uninterrupted, MAG temporarily suspended its online booking management system as a precautionary measure. The aviation industry faces increasing cyber threats targeting critical infrastructure and passenger data, with attackers recognizing airports as high-value targets containing vast amounts of personal information and payment data. This incident highlights the urgent need for enhanced cybersecurity measures across transportation hubs as digital transformation accelerates in the post-pandemic travel recovery.

4 weeks ago

Kill Chain

IC
Initial Compromise(medium)
PE
Privilege Escalation(medium)
LM
Lateral Movement(high)
C&C
Command & Control(medium)
E
Exfiltration(high)
I
Impact(high)
Read Report
First Android Malware Targeting Car Head Units Discovered in MoYu Group Campaign
Impact· LOW

First Android Malware Targeting Car Head Units Discovered in MoYu Group Campaign

In August 2026, Kaspersky researchers discovered JarService, the first documented Android malware specifically targeting automotive head units. The malware, attributed to the MoYu Group behind the notorious BadBox botnet, infected DoFun-manufactured car head units by exploiting vulnerabilities in the TWCore firmware update system. The multistage downloader spreads through legitimate update functionality and ultimately deploys click-fraud malware and reverse-proxy modules to recruit infected vehicles into a botnet for ad fraud purposes. While the infected infotainment systems pose no direct physical safety risks to drivers, this represents a significant expansion of botnet operations into connected vehicle infrastructure. This incident highlights the growing threat surface as cybercriminals increasingly target IoT and connected vehicle ecosystems. With automotive systems becoming more interconnected and the rise of software-defined vehicles, securing update mechanisms and embedded systems has become critical for preventing botnet recruitment and protecting connected infrastructure from exploitation.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(low)
C&C
Command & Control(high)
E
Exfiltration(medium)
I
Impact(high)
Read Report
Critical Bendix EC80 Brake ECU Vulnerabilities Threaten Vehicle Safety Systems
Impact· HIGH

Critical Bendix EC80 Brake ECU Vulnerabilities Threaten Vehicle Safety Systems

In August 2026, CISA disclosed critical vulnerabilities in Bendix EC80 Brake ECU systems used across transportation infrastructure in the United States and Canada. The vulnerabilities include a stack-based buffer overflow (CVE-2026-67560), an out-of-bounds write (CVE-2026-68967), and hard-coded credentials (CVE-2026-71396). Successful exploitation could allow attackers to disable critical safety systems including ABS functions, steering assist, speedometer, automatic traction control, and shifting capabilities, potentially causing catastrophic vehicle safety failures. The vulnerabilities were discovered by Ben Gardiner of NMFTA and affect multiple EC80ESP+ and EC80ESP variants across different firmware versions. This incident highlights the growing threat landscape targeting industrial control systems and critical transportation infrastructure, as nation-state actors and cybercriminals increasingly focus on operational technology vulnerabilities that can cause physical harm and disrupt essential services.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(low)
I
Impact(high)
Read Report
Critical Maritime Security Alert: FURUNO FA-50 AIS Transponder Vulnerabilities Expose Global Fleet
Impact· CRITICAL

Critical Maritime Security Alert: FURUNO FA-50 AIS Transponder Vulnerabilities Expose Global Fleet

Critical vulnerabilities CVE-2026-59769 and CVE-2026-67578 were discovered in FURUNO FA-50 Class B AIS Transponder devices used worldwide in maritime transportation systems. The flaws include hardcoded credentials and missing authentication for critical functions, allowing attackers with network access to alter device settings and configurations. With CVSS scores of 9.1 and 7.5 respectively, these vulnerabilities affect all versions of the discontinued product, leaving thousands of vessels potentially exposed to navigation system manipulation. FURUNO ended production in October 2020 and will not provide security updates, recommending only physical security measures and network isolation as mitigations. This incident highlights the growing risks of legacy IoT/OT devices in critical infrastructure, where end-of-life products continue operating without security support, creating persistent attack vectors that threaten maritime safety and operational integrity.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(low)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
Critical Siemens SIMATIC IoT2050 Vulnerability Exposes Industrial Systems to Remote Takeover
Impact· CRITICAL

Critical Siemens SIMATIC IoT2050 Vulnerability Exposes Industrial Systems to Remote Takeover

In August 2026, CISA disclosed a critical vulnerability (CVE-2026-58115) in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed. The vulnerability stems from missing authentication on the Node-RED HTTP interface, allowing unauthenticated remote attackers to create malicious flows and execute arbitrary code with maximum privileges. With a CVSS score of 10.0, this vulnerability affects industrial control systems deployed globally across chemical, manufacturing, energy, and transportation sectors. Siemens has released version 4.3.4.1 to address the issue and strongly recommends immediate updates. This disclosure highlights the growing security risks in Industrial IoT environments as operational technology increasingly integrates with network-accessible programming interfaces. The vulnerability represents a broader trend of critical authentication bypasses in industrial control systems that could enable devastating attacks on critical infrastructure.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(high)
LM
Lateral Movement(medium)
C&C
Command & Control(medium)
E
Exfiltration(medium)
I
Impact(medium)
Read Report
First-Ever Android Car Head Unit Malware: MoYu Group's Supply Chain Attack Analysis
Impact· MEDIUM

First-Ever Android Car Head Unit Malware: MoYu Group's Supply Chain Attack Analysis

In August 2026, Kaspersky researchers discovered a sophisticated supply-chain attack by the MoYu threat group targeting Android-based car head units manufactured by DoFun, a Chinese automotive software provider. The attackers compromised the legitimate TWCore system app to deliver JarService malware, which established command-and-control communication and downloaded additional payloads. The malware transformed infected head units into proxy botnet nodes and conducted advertising fraud operations, marking the first documented malware infection chain specifically designed for automotive head units. While the malware did not interfere with critical vehicle systems, it demonstrated a new attack vector in the expanding Internet of Things landscape. This incident highlights the growing security risks in connected vehicle ecosystems as automotive manufacturers increasingly integrate internet-connected Android systems. The attack underscores vulnerabilities in automotive supply chains and the emergence of vehicles as new targets for cybercriminal monetization schemes.

1 month ago

Kill Chain

IC
Initial Compromise(high)
PE
Privilege Escalation(medium)
LM
Lateral Movement(medium)
C&C
Command & Control(high)
E
Exfiltration(high)
I
Impact(high)
Read Report
[ INCIDENT RESPONSE // UNDER ATTACK? ]

Stop Active Cloud Data Exfiltration

Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.

Looking for threats in a different sector?

Browse All Threat Reports