Estes Express Lines confirms cyberattack behind multi-day IT outage
- Organization
- Estes Express Lines
- Exploit
- Ransomware
- Industry
- Transportation and Logistics
Estes Express Lines, a Richmond, Virginia less-than-truckload carrier, told customers on October 2, 2023 that its technology infrastructure was down, and confirmed the following day that a cyberattack was the cause. The company declined to say which systems had been affected or to give further details of the investigation.
Estes said its terminals and drivers continued picking up and delivering freight while it worked through the event, and thanked customers and vendors for their patience. Industry observers told Cybersecurity Dive the outage forced manual workarounds, blocking new shipment bookings and making real-time route management labor intensive and prone to error.
Later disclosures filled in the timeline. Estes said the intruder gained access on September 26, 2023 and was detected on October 1, and that a forensic investigation was completed on November 7. The LockBit ransomware group claimed the attack in early November and published data it said came from Estes on November 13.
In December 2023 Estes notified more than 21,000 people that their names, other personal identifiers and Social Security numbers had been taken, filing notice with state regulators including the Maine Attorney General. The company said it did not pay a ransom, locked the attacker out of its systems, cooperated with the FBI and offered those affected 12 months of identity monitoring. It reported no confirmed instances of identity theft tied to the breach.
Updates
-
Estes filed a breach notification with the Maine attorney general on December 31, 2023, reporting that 21,184 people had personal data taken, including Social Security numbers. LockBit claimed the intrusion and leaked the stolen data on November 13, 2023.