Year2023 |
MonthJanuary |
Reference number20230107 |
Impact areaShore |
Incident locationCanada |
Incident countryCanada |
Victim countryCanada |
Victim identityLivingston International |
Victim TypeFreight forwarder and customs broker |
MethodRansomware |
In January 2023, Livingston International, a major North American freight forwarder and customs broker, experienced a ransomware attack by the Royal ransomware gang. The attackers exfiltrated sensitive information, including employee documents, financial details, and network structure data, affecting 3,200 employees, 30,000 customers, and 125 key border entry points. The breach halted operations at the US-Canada border for two business days. The Royal ransomware group, active since January 2022, uses phishing emails and malicious advertisements to target victims. They have also been linked to other high-profile breaches, including those of Intrado, AONTTAGL, and the Queensland University of Technology. Operations at Livingston International resumed after two days, but the extent of the data breach was significant.