The Courier Guy allegedly hit by cyberattack

mylesillidge

Journalist
Joined
Jul 29, 2021
Messages
4,273
Reaction score
4,573
Largest parcel courier company in South Africa allegedly hit by cyberattack

The Courier Guy, South Africa's largest express parcel and e-commerce courier delivery company, has allegedly been hit by a ransomware attack.

Ransomware-as-a-service (RaaS) group MedusaLocker claimed on its dark web leak site that it attacked The Courier Guy, and alleged it would release exfiltrated internal documents from the company.
 
Largest parcel courier company in South Africa allegedly hit by cyberattack

The Courier Guy, South Africa's largest express parcel and e-commerce courier delivery company, has allegedly been hit by a ransomware attack.

Ransomware-as-a-service (RaaS) group MedusaLocker claimed on its dark web leak site that it attacked The Courier Guy, and alleged it would release exfiltrated internal documents from the company.
Pretty sure these guys have been on the inside for some time given all the fake parcel phishing mails I receive after placing orders that use them. They’ve probably just run out of phishing money so resorted to ransomware. TCG had better not pay the ransom. Rather lose the data.
 
 
Anyone able to get the leak screenshot? My browser just sits on 'verifying'
 
Pretty sure these guys have been on the inside for some time given all the fake parcel phishing mails I receive after placing orders that use them.

Not saying you're wrong about them having been inside for some time, but I don't think your receiving fake parcel mails is necessarily an indicator of that, since I get those same emails to an address that I've never used with any courier/ecommerce.

So maybe your experience has been more coincidental than causal.

Also the fake courier mails have been spoofing all the big couriers rather than just TCG.
 
Not saying you're wrong about them having been inside for some time, but I don't think your receiving fake parcel mails is necessarily an indicator of that, since I get those same emails to an address that I've never used with any courier/ecommerce.
Of course it's a spray and pray approach by most scammers, but I live in the sticks and use couriers regularly and while I receive a number of these from different companies on occasion, I receive one virtually every time a parcel is in the queue at TCG. I'm just making an educated guess here and my personal experience is that the likelihood is high that there's been a leak or insider for some time.
 
Of course it's a spray and pray approach by most scammers, but I live in the sticks and use couriers regularly and while I receive a number of these from different companies on occasion, I receive one virtually every time a parcel is in the queue at TCG. I'm just making an educated guess here and my personal experience is that the likelihood is high that there's been a leak or insider for some time.
I noticed the same - randomly get the usual ones but consistently get fake TCG ones right after i arrange a shipment.

Interestingly - was with ABSA 20 years ago; still get fake emails / have been with Stand Bank and get loads daily.
Just opened account with Investec and now started getting from there too so while i don't suspect the bank systems having been compromised, 3rd party access (ie. ClearScore) can determine which banks you have accounts with and suspect they use that to trigger fake emails/sms/etc...
 
Pretty sure these guys have been on the inside for some time given all the fake parcel phishing mails I receive after placing orders that use them. They’ve probably just run out of phishing money so resorted to ransomware. TCG had better not pay the ransom. Rather lose the data.
Lol, pay it once , pay it yearly. It's like cancelling with Mweb/Rain/MTN/SABC.... They will continue to bill you. ;)
 
Not saying you're wrong about them having been inside for some time, but I don't think your receiving fake parcel mails is necessarily an indicator of that, since I get those same emails to an address that I've never used with any courier/ecommerce.

So maybe your experience has been more coincidental than causal.

Also the fake courier mails have been spoofing all the big couriers rather than just TCG.
Too much of a stretch to say it's a coincidence. So much more evidence for causal and driver's will never turn down a bit of side-hustle.
 
I noticed the same - randomly get the usual ones but consistently get fake TCG ones right after i arrange a shipment.

Interestingly - was with ABSA 20 years ago; still get fake emails / have been with Stand Bank and get loads daily.
Just opened account with Investec and now started getting from there too so while i don't suspect the bank systems having been compromised, 3rd party access (ie. ClearScore) can determine which banks you have accounts with and suspect they use that to trigger fake emails/sms/etc...
Clearscore are horrendous. I logged in the other day because I got an email saying "my score is about to change" and the session was still active on my PC over a month after my last login.
 
  • Like
Reactions: OCP
Pretty sure these guys have been on the inside for some time given all the fake parcel phishing mails I receive after placing orders that use them. They’ve probably just run out of phishing money so resorted to ransomware. TCG had better not pay the ransom. Rather lose the data.
What data is there to lose? Address are printed on the labels. further there should not be any private once use customer information on system what so ever. registered businesses are different and that should be safeguarded with backups.
 
Top
Sign up to the MyBroadband newsletter
X