Skip to content
Diesel Vortex: Russian Cybercrime Group Targets US and EU Freight Companies

Diesel Vortex: Russian Cybercrime Group Targets US and EU Freight Companies

First seen 24 Sep 2026, 13:27 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 14:59 UTC
  • Diesel Vortex targeted US and EU logistics firms, stealing over 1,600 credentials.
  • The group used phishing-as-a-service tactics, including impersonation and double-brokering.
  • Collaboration among cybersecurity firms led to the exposure and takedown of the group's infrastructure.

In February 2026, the cybercrime group Diesel Vortex was uncovered, targeting freight and logistics companies in the US and EU. The group employed phishing-as-a-service tactics, harvesting over 1,600 unique login credentials from major logistics platforms. Their operations included impersonation of legitimate carriers and brokers, utilizing sophisticated spearphishing and voice phishing techniques. Internal logs revealed coordination among Armenian-speaking operators, indicating a complex network behind the attacks. The group also engaged in double-brokering, redirecting freight under stolen identities. Investigators from Have I Been Squatted and Ctrl-Alt-Intel collaborated to analyze the group's infrastructure, leading to the exposure of their codebase and operational plans. The operation is assessed to have been active from September 2025 to February 2026, with ongoing investigations into earlier activities. The takedown of their infrastructure involved multiple cybersecurity firms and organizations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-09-01
Diesel Vortex operation begins
The group started targeting freight and logistics companies, employing phishing tactics to harvest credentials.
haveibeensquatted.com
2026-02-01
Operation uncovered
Have I Been Squatted and Ctrl-Alt-Intel revealed the Diesel Vortex group's activities and tactics.
ctrlaltintel.com
2026-02-01
Takedown of infrastructure
A coordinated effort by multiple cybersecurity firms led to the takedown of Diesel Vortex's phishing infrastructure.
haveibeensquatted.com

More articles in this cluster (2)

Following this threat?

Track Central Dispatch in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed