Forward Air has been hit by a new ransomware gang, dubbed Hades. The attack has affected the company's business operations.
Forward Air is a leading “trucking and air freight logistics company”, headquartered in Tennessee, USA. The company employs over 4,300 people.

Last week, it was reported that Forward Air suffered a cyberattack, forcing it to take systems offline to prevent the attack from spreading. The company itself later confirmed the incident.
“On December 15, Forward Air identified a security incident that impacted the functionality of certain computer systems. In accordance with our security protocols, we immediately took our systems offline, notified law enforcement, and engaged several experts to assist with our internal investigation. Our IT team is working to restore the servicesaffected” Forward Air told BleepingComputer.
The ransomware attack to have led to disruption of business operations, as documents required for the release of goods from customs were stored on the systems affected by the attack.
At the moment, Forward Air's official site is down and simply displays a message informing about the " security".
Behind the attack is the new Hades ransomware
Forward Air is said to have been affected by a new operation known as Hades.
Initially, Forward Air filed a Form 8-K with the Securities and Exchange Commission disclosing that it had been attacked by ransomware. Among other things, the company said:
“On December 15, 2020, Forward Air Corporation detected a ransomware attack that affected its systems and caused service delays for many of its customers. Immediately after the incident was detected, the company launched an investigation… The company has also cooperated with relevant law enforcement authorities“.

The Hades ransomware gang started the attack a week ago.
Upon encrypting a victim’s systems, the ransomware creates a ransom note, named “HOW-TO-DECRYPT- [extension].txt.” This note bears some similarities to the one left by the REvil ransomware . hackers
Inside the note, the victim finds a URL site that is unique to each victim. This URL takes the victim to a Tor site that contains information about the attack and a Tox messenger address that victims can use to contact the attackers. This address is the same for all victims.
According to Bleeping Computer, the hackers behind the Hades ransomware have a Twitter account, which they will likely use to leak files they steal during the attacks.
At present, no sample of the new ransomware has been found, while the amount of money the hackers are asking for to decrypt the systems is also unknown
Source: Bleeping Computer
