JAS Worldwide confirms ransomware attack behind freight operation disruptions
- Organization
- JAS Worldwide
- Exploit
- Ransomware
- Industry
- Logistics
JAS Worldwide, an Atlanta headquartered freight forwarder founded in Milan in 1978, confirmed in late August 2024 that a ransomware attack was behind technical disruptions affecting its business. The company operates in more than 100 countries and employs over 7,000 people.
JAS said that on identifying the issue it immediately secured its systems and began an investigation with external cyber security experts, who determined that the incident was the result of ransomware. The disruption affected the company's operational capability and its ability to service customers. JAS said its email systems and website remained secure, and reported that its contract logistics business and certain entities were unaffected.
The forwarder did not say what data, if any, had been taken, and gave no figures on how many customers were affected. No criminal group claimed responsibility in the days after the disclosure. Luke Connolly, a threat analyst at Emsisoft quoted by FreightWaves, said that silence from a gang is not unusual and can reflect extortion pressure still being applied, a failure to exfiltrate data, or a claim yet to be posted.
By 2 September 2024 the company said central operating systems were working, customers were being served, and billing, payment and data integration with customer and vendor systems had largely been restored. Staff were still clearing a backlog of requests and restoring some location specific functions. JAS said it would implement additional security measures to reduce the risk of future disruption.