Cyble’s 2025 report reveals rise in cyber threats against transport and logistics sector

IMAGE-Transport-and-Logistics-Threat-Landscape-Report-2025-shows-surge-in-ransomware-and-data-breaches-MEDIABRIEF.png

Cyble Inc. releases its Transport and Logistics Threat Landscape Report 2025, revealing a sharp escalation in cyber threats targeting one of the most critical pillars of global commerce.

The report documents 283 ransomware attacks against transport and logistics organizations, more than the combined total observed in 2023 and 2024, alongside major data breaches, hacktivist campaigns, and underground activity involving compromised network access.

The analysis outlines how threat actors exploit the sector’s low tolerance for downtime, operational technology dependencies, and interconnected supply chains to cause disruption and financial impact.

Daksh Nakra, Senior Manager of Research and Intelligence, Cyble said, “The transport and logistics sector has become a prime target for cybercriminals because operational disruption translates directly into economic and societal impact.

“In 2025, we observed ransomware campaigns capable of crippling airlines, shipping firms, and ground logistics providers within hours, often by exploiting a single vulnerability across dozens of organizations,” Nakra said.

Ransomware campaigns reach wider scale

Cyble researchers observed 283 ransomware victims across the transport and logistics sector in 2025, with activity remaining consistent throughout the year. A limited number of ransomware operations accounted for a majority of incidents.

CL0P accounted for 68 attacks, representing 24% of the total, followed by Qilin with 43 attacks or 15%, Akira with 29 attacks or 10%, and Play with 20 attacks or 7%. Together, these four groups were responsible for 57% of ransomware activity targeting the sector.

Land transport and public infrastructure impacted

Land-based operations accounted for nearly three out of every four ransomware attacks, with logistics and freight services most frequently targeted. Airlines, maritime shipping firms, trucking companies, rail operators, and public transit authorities were also affected.

Data breaches expose customer and operational data

The report identifies ongoing data breach activity involving both persistent and opportunistic actors.

Documented incidents include a breach affecting approximately 6 million Qantas customers, an alleged logistics platform breach involving over 7 million user records offered for sale on underground forums, and multiple courier and postal service data leaks across Europe and Asia.

These incidents exposed personal and operational data.

Underground access markets and cargo theft

Cyble’s findings show a fragmented underground market where actors sold access to VPNs, firewalls, and internal systems belonging to transport and logistics organizations.

Such access was used to support ransomware deployment, espionage, and financially motivated attacks. The report also highlights cyber-enabled cargo theft, where weaknesses in GPS, remote monitoring, and operational technology systems were exploited.

Zero-day vulnerabilities and geopolitical hacktivism

The report notes extensive exploitation of zero-day and known vulnerabilities, particularly in perimeter devices and enterprise software. Many vulnerabilities carried CVSS scores of 9.0 or higher and enabled remote code execution. Frequently affected vendors included Microsoft, Cisco, Fortinet, Apple, Ivanti, and Citrix.

Hacktivist activity increased in 2025, with more than 40,000 data leak and dump posts affecting over 44,000 domains globally. The transport and logistics sector was targeted in campaigns linked to geopolitical conflicts, including an attack on a Russian airline that disrupted flight operations and infrastructure.