Ward Transport and Logistics notified victims of March 2024 network breach

Organization
Ward Transport & Logistics Corp.
Exploit
Ransomware
Industry
Transportation and Logistics

Ward Transport and Logistics Corp., a family owned less-than-truckload carrier based in Altoona, Pennsylvania, began mailing data breach notification letters on October 2, 2024 and reported the incident to the Massachusetts Attorney General.

The notification followed an attack on the carrier's network in early March 2024 that forced Ward to take systems offline and run limited operations while it moved freight already in its network. Mike Zupon, Ward's vice president of technology, later told Trucking Dive that email is the largest threat facing carriers and that attackers can disrupt operations with as little as a routine phishing scheme, in an hour or less. Those remarks were about the sector generally. Ward has not publicly disclosed how the attackers reached its network.

Accounts of the exposed data differ. Edelson Lechtzin LLP, which announced an investigation on October 8, 2024, said the compromised information may have included names, Social Security numbers, financial records, medical data and driver's license numbers. Strauss Borrelli PLLC, reviewing the same filing, said Ward's public notice did not specify the data types and described the number of affected individuals as undetermined.

The breach tracking service Breachsense logged the intrusion as a March 4, 2024 incident attributed to the DragonForce ransomware operation, with roughly 574 GB of data taken from the company. Ward offered affected individuals complimentary identity protection services and did not publish a victim count in its regulator filing.

Sources