Two independent sources, one picture: transport and logistics are in the crosshairs, and the weak spot is rarely just technical.
Logistics companies run classic office IT alongside terminal, warehouse, and vehicle control systems, on top of constant foot and vehicle traffic at the gate. That combination opens up several routes at once for attackers, and every station in the flow of goods is one of them.
Plans routes, freight, and orders centrally, with interfaces to customers, customs, and subcontractors.
Receiving, picking, inventory: grown organically over years and tightly wired into handheld scanners and mobile devices.
Crane control, slot booking, and container logistics run on specialized systems that conventional IT security concepts rarely cover.
Dozens of unfamiliar drivers, subcontractors, and delivery partners every day, and gate staff who are used to exactly that traffic.
Cutting across all of it: customer and supplier interfaces. APIs and portals for shipment tracking, EDI connections, and freight booking connect your network directly with your partners'.
Gates, terminals, and loading docks see dozens of unfamiliar drivers, subcontractors, and delivery partners every single day, on top of high turnover among gate security staff. Someone posing as a subcontractor's driver or a delivery partner exploits exactly that routine: they act confidently, reference a supposed delivery slot, and gate staff, used to this kind of traffic, wave them through. Once inside, warehouses, terminal areas, and often unsecured network ports are within reach.
„The biggest challenge remains the human factor.“
Three incidents at logistics companies, as described in media reports. Not isolated cases, but a pattern.
The Osnabrück-based logistics provider was hit by a ransomware attack.
A cyberattack on the company affected roughly 1,600 business customers.
The freight giant disclosed an October 2025 incident attributed to a group calling itself "CoinbaseCartel".
Based on public reporting. accessgranted was not involved in these incidents.
See our own pentesting track recordOngoing freight flow and delivery deadlines come first. That's why our approach is closely coordinated with dispatch and terminal operations.
Together we define which systems are tested actively and which are only analyzed passively, especially around terminal control and shipments in transit.
Gathering information from public sources, network scans, and preparing realistic attack scenarios, including pretexting approaches targeting the gate and dispatch.
Manual testing within the agreed scope, with a defined emergency contact and an immediate stop if there's any unexpected impact on the flow of goods.
Every finding is rated by severity, exploitability, and impact on delivery capability and terminal operations.
Full documentation with remediation guidance, a management summary, and mapping to NIS2 or KRITIS requirements.
From dispatch to the gate, a single test won't get you there. These modules complement each other best in practice.
Simulated access attempts at gates, warehouses, and terminal areas. Covers the physical attack surface that shows up especially often in logistics.
Phishing and pretexting simulations tailored to dispatch, driver communication, and the constant flow of outside visitors at the gate.
Network segmentation between office IT, TMS/WMS, and terminal control, access rights, and interface hardening.
The transport sector falls under NIS2 per Annex 1 BSIG, with larger hubs additionally covered by the KRITIS regulation. Our compliance pages explain exactly what that means for you.