May 2025 Logistics Threat Intelligence Briefing
Threat Analysis of the Logistics Sector (01/05/2025 – 31/05/2025)
Blog
Research, detection engineering notes, and incident response lessons learned.
Latest
Threat Analysis of the Logistics Sector (01/05/2025 – 31/05/2025)
Threat Analysis for the Manufacturing Sector, 1 May 2025 – 31 May 2025
Maritime Industry Threat Analysis: May 2025
Threat Analysis of the Real Estate Industry Sector – May 2025
Threat Analysis of the Research Industry Sector – May 2025
Threat Analysis of Retail Sector: 1 May 2025 to 31 May 2025
Threat Analysis of the Technology Industry Sector: May 2025
Transportation Industry Threat Analysis for May 2025
On May 20, 2025, Kettering Health, a major healthcare network based in Ohio, experienced a ransomware attack that severely disrupted its operations. As a result, all 14 hospitals in the system were placed on emergency reroute. This meant ambulances were redirected, and staff had to switch to manual processes because digital systems—including electronic health records, internal messaging, and coordination platforms—became unavailable.
Russia’s cyber strategy increasingly relies on hybrid operations: coordinated campaigns that combine cyber attacks, disinformation, and political subversion. Since the invasion of Ukraine in 2022, the Kremlin and its supporters have amplified a new wave of cyber threats, using state-aligned groups, criminal proxies, and nationalist hacktivist collectives to target institutions across Europe.
In the constantly evolving world of ransomware, a new and unusual variation has emerged. Rather than demanding cryptocurrency payments, certain threat actors are now instructing victims to make donations to charity in exchange for decryption keys or promises not to publish stolen data. These so-calleddonation-model ransomware groupspresent themselves as ideologically driven, often citing anti-corporate motives or positioning their activity as a form of digital protest.
April 2025 — Phoenix, Arizona