Cyber Incident Victim: Amital Software
Date:
Dec 2020
Location:
Israel
Summary
A cyberattack targeted a logistics software provider and at least 40 of its clients, compromising servers and exfiltrating sensitive information. The incident also affected an additional 15-20 unrelated companies beyond the initial victim's customer base, though comprehensive details about all impacted entities remain unclear. Iran was reportedly identified as the likely perpetrator behind the coordinated breach.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
A cyberattack targeting Israeli logistics companies occurred in early December 2020, impacting Amital Data and its Unifreight logistics software platform along with at least 40 client organizations. The attackers successfully exfiltrated information from compromised servers, though the specific nature of the stolen data was not disclosed in public reports. The incident remained undiscovered until December 13, 2020, when one affected entity filed a disclosure with the Tel Aviv Stock Exchange. Initial assessments indicated the attack's primary focus was supply chain disruption through Amital's software ecosystem, which served as a central point of failure for multiple logistics operators. No technical details regarding intrusion vectors or malware were released publicly at this stage of the investigation.

Subsequent inquiries by Calcalist revealed the attack's broader scope, identifying 15-20 additional compromised companies that were not clients of Amital Data, suggesting either collateral damage or parallel targeting beyond the initial supply chain vector. The full list of affected organizations remained unconfirmed as of the reporting date. Public attribution assessments cited in media pointed to Iranian state-sponsored actors as the likely perpetrators, though no official government confirmation or forensic evidence supporting this claim was included in the initial disclosures. The incident prompted coordinated response efforts among victims, though specific containment measures or remediation actions taken by Amital or its clients were not detailed in available reports. Financial impacts and operational disruptions stemming from the breach were acknowledged but not quantified in disclosed documentation.
