Russian cybercrime ring targeted freight firms in US, Europe, report says

Joint probe into “Diesel Vortex” details credential theft, check fraud and double-brokering risks

The investigation by Have I Been Squatted and Ctrl-Alt-Intel said impacted parties included users of DAT Truckstop, Penske Logistics, Electronic Funds Source, Timocom and other freight-focused systems. (Photo: Jim Allen/FreightWaves)

A Russian-linked phishing-as-a-service group ran a months-long phishing campaign targeting freight and logistics companies across the U.S. and Europe, stealing more than 1,600 login credentials.

The group dubbed “Diesel Vortex” — operated from at least September 2025 through February, focusing on platforms widely used by brokers, carriers and supply chain operators, according to a joint investigation released on Tuesday by cybersecurity researchers Have I Been Squatted and Ctrl-Alt-Intel.

The investigation found 1,649 unique credentials were compromised, drawn from 3,474 stolen login pairs. Impacted parties included users of DAT Truckstop, Penske Logistics, Electronic Funds Source (EFS), Timocom and other freight-focused systems, according to the report.

Researchers described Diesel Vortex as a structured phishing-as-a-service operation, not a lone hacker. The group built dedicated phishing infrastructure for logistics load boards, fleet portals and fuel card systems, using targeted email and voice phishing to capture credentials and multi-factor authentication codes in real time.

A key breakthrough in the investigation came after analysts discovered an exposed .git directory on a phishing domain, enabling them to reconstruct the group’s codebase and review a 36.6MB SQL database dump dated Feb. 4, Have I Been Squatted and Ctrl-Alt-Intel said in the report.

That database showed 52 phishing domains deployed, more than 75,000 targeted contact emails and 35 confirmed EFS check fraud attempts.

Diesel Vortex also used a dual-domain architecture designed to evade detection, with one “advertise” domain visible to victims and a hidden “system” domain loading phishing content inside an iframe, an element that loads another HTML element inside of a web page, such as external ads, videos or tags.

Operators controlled victim sessions through a Telegram-based console, steering targets through credential capture flows and secondary email phishing modules in real time. 

According to the report, the platform was internally branded “GlobalProfit” and appeared to be under active development as a broader phishing-as-a-service product, potentially marketed to other operators. 

Have I Been Squatted and Ctrl-Alt-Intel said they coordinated with multiple industry partners during the investigation and worked to notify affected parties.

Upcoming FreightWaves Events
Fraud & Security

Freight Fraud Symposium

Double brokering. AI deepfakes. Identity theft. Freight fraud is an existential threat to the industry. Get ahead of it.

May 20, 2026
Rock & Roll Hall of Fame • Cleveland, OH
Register Now
AI & Technology

Supply Chain AI Symposium

Past the hype. Join operators, founders, and enterprise leaders figuring out how to deploy AI in supply chain.

July 15, 2026
The Old Post Office • Chicago, IL
Register Now
Rail & Policy

Future of Rail Symposium

Reshoring is rewriting freight demand. Join shippers, rail executives, and government officials to shape the next decade.

July 28, 2026
The Signal at Chattanooga Choo Choo • Chattanooga, TN
Register Now
Fraud & Security Freight Fraud Symposium May 20 • Cleveland, OH

Double brokering. AI deepfakes. Identity theft. Freight fraud is an existential threat to the industry. Get ahead of it.

Rock & Roll Hall of Fame • Cleveland, OH Register Now
AI & Technology Supply Chain AI Symposium Jul 15 • Chicago, IL

Past the hype. Join operators, founders, and enterprise leaders figuring out how to deploy AI in supply chain.

The Old Post Office • Chicago, IL Register Now
Rail & Policy Future of Rail Symposium Jul 28 • Chattanooga, TN

Reshoring is rewriting freight demand. Join shippers, rail executives, and government officials to shape the next decade.

The Signal at Chattanooga Choo Choo • Chattanooga, TN Register Now

Noi Mahoney

Noi Mahoney is a Texas-based journalist who covers cross-border trade, logistics and supply chains for FreightWaves. He graduated from the University of Texas at Austin with a degree in English in 1998. Mahoney has more than 20 years experience as a journalist, working for newspapers in Maryland and Texas. Contact nmahoney@freightwaves.com