CSIDB logo
Incident

Overseas Express Shipping Company

Incident posture

Attack window
Sep 2020
Location
Japan
Status
Historical
CIA posture
Available to members
Updated
2025-10-28 00:00

Linked entities

Victim
Overseas Express Shipping Company
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Overseas Express Shipping Company was targeted in a ransomware attack by the LockBit group, which exfiltrated and publicly leaked a database containing approximately 5.8 million records of sensitive personal information, including names, addresses, and email addresses. LockBit utilized dark web forums and a dedicated blog to intimidate the victim and pressure ransom payments, though technical failures in their encryption and decryption processes reportedly enabled some affected organizations to restore operations without paying. The incident highlighted LockBit's adoption of established ransomware tactics, including data theft for leverage and recruitment of affiliates, despite operational inconsistencies that undermined their effectiveness.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On September 14, 2020, the ransomware group LockBit announced the launch of a dedicated blog on a Russian-language dark web forum, using it to publish stolen data from two victims: Yaskawa Electric Corporation and Overseas Express Shipping Company. The group, which operated under the Ransomware-as-a-Service (RaaS) model, had previously recruited affiliates through forum posts on January 17, 2020. LockBit’s blog post contained Overseas Express Shipping Company’s database comprising 5.8 million records, including personally identifiable information (PII) such as names, addresses, email addresses, and internal corporate documents. This data leak followed an unconfirmed ransomware attack against the shipping company, though the effectiveness of LockBit’s file encryption during the incident remained unclear. The publication of the database aligned with established ransomware intimidation tactics, where groups leverage stolen data to pressure victims into paying ransoms by threatening or executing public releases.

The incident’s technical execution faced scrutiny from another cybercriminal using the alias “wexford,” who publicly accused LockBit on September 2, 2020, of failing to deliver ransom payments after four months of collaboration. Wexford alleged LockBit’s ransomware had critical flaws in both encryption and decryption processes, enabling some victims to restore operations using network backups without paying. This claim cast doubt on whether Overseas Express Shipping Company’s systems were successfully encrypted or whether the data leak represented retaliation for non-payment. No information was disclosed regarding Overseas Express’s detection methods, containment efforts, or whether it negotiated with LockBit. The confirmed impact included the exposure of sensitive customer and corporate data, potentially facilitating identity theft or further targeted attacks. LockBit’s simultaneous leak of Yaskawa Electric Corporation’s proprietary financial and technical data underscored the group’s focus on high-value targets across multiple industries.

Sources

Sources available to members: 1 source.

CSIDB