Giant Forward Air has disclosed a data breach following a ransomware attack that allowed threat actors to access employees' personal information.

See also: MyRepublic: Facing a data breach
In December 2020, Forward Air was hit by a ransomware attack from a new cybercrime gang known as Hades. This attack caused the company’s network to shut down, leading to business disruption and the inability to release cargo for transport.
An SEC filing from Forward Air states that the company lost at least $7.5 million in less-than-truckload (LTL) shipments “primarily due to the company’s need to temporarily suspend electronic data interfaces with its customers.”.
Researchers later revealed that this attack was likely carried out by members of the Evil Corp gang, who regularly carry out attacks under different ransomware names, such as Hades, to evade US sanctions.
At the time, multiple Forward Air employees contacted BleepingComputer, concerned that the attack had exposed their personal information.
As part of the attack, the threat actors created a Twitter account that they claimed would be used to leak data stolen from Forward Air. However, no data was ever leaked by the threat actors.
See also: Sonic data breach lawsuit to continue
Forward Air reveals data breach
After all these months, Forward Air is now revealing that due to the ransomware attack, the data of its former employees was exposed.
Information that Evil Corp threat actors may have access to includes employee names, addresses, dates of birth, social security numbers, driver's license numbers, passport numbers, or bank account numbers.
While Forward Air states that there is no indication that the data has been used, they are offering those affected a free one-year membership to the credit monitoring service myTrueIdentity.
Since there is no way to determine whether a threat actor has used the stolen data, even if they promise not to after a ransom is paid, all affected employees should assume that their data has been compromised.
See also: Bangkok Airways: We apologize for the data breach
This means they should monitor bank statements and be on the lookout for targeted phishingattacks.
Information source: bleepingcomputer.com
