The Courier Guy allegedly hit by cyberattack

mylesillidge

Journalist
Joined
Jul 29, 2021
Messages
4,274
Reaction score
4,576
Largest parcel courier company in South Africa allegedly hit by cyberattack

The Courier Guy, South Africa's largest express parcel and e-commerce courier delivery company, has allegedly been hit by a ransomware attack.

Ransomware-as-a-service (RaaS) group MedusaLocker claimed on its dark web leak site that it attacked The Courier Guy, and alleged it would release exfiltrated internal documents from the company.
 
 
Pretty sure these guys have been on the inside for some time given all the fake parcel phishing mails I receive after placing orders that use them.

Not saying you're wrong about them having been inside for some time, but I don't think your receiving fake parcel mails is necessarily an indicator of that, since I get those same emails to an address that I've never used with any courier/ecommerce.

So maybe your experience has been more coincidental than causal.

Also the fake courier mails have been spoofing all the big couriers rather than just TCG.
 
Of course it's a spray and pray approach by most scammers, but I live in the sticks and use couriers regularly and while I receive a number of these from different companies on occasion, I receive one virtually every time a parcel is in the queue at TCG. I'm just making an educated guess here and my personal experience is that the likelihood is high that there's been a leak or insider for some time.
I noticed the same - randomly get the usual ones but consistently get fake TCG ones right after i arrange a shipment.

Interestingly - was with ABSA 20 years ago; still get fake emails / have been with Stand Bank and get loads daily.
Just opened account with Investec and now started getting from there too so while i don't suspect the bank systems having been compromised, 3rd party access (ie. ClearScore) can determine which banks you have accounts with and suspect they use that to trigger fake emails/sms/etc...
 
We really really need to start taking vulnerabilities and security risks in code, databases seriously. They are putting everyone at risk. This is especially important in the age of vibe coding, even though it is not something unique to new technology.
 
Pretty sure these guys have been on the inside for some time given all the fake parcel phishing mails I receive after placing orders that use them. They’ve probably just run out of phishing money so resorted to ransomware. TCG had better not pay the ransom. Rather lose the data.
Lol, pay it once , pay it yearly. It's like cancelling with Mweb/Rain/MTN/SABC.... They will continue to bill you. ;)
 
Not saying you're wrong about them having been inside for some time, but I don't think your receiving fake parcel mails is necessarily an indicator of that, since I get those same emails to an address that I've never used with any courier/ecommerce.

So maybe your experience has been more coincidental than causal.

Also the fake courier mails have been spoofing all the big couriers rather than just TCG.
Too much of a stretch to say it's a coincidence. So much more evidence for causal and driver's will never turn down a bit of side-hustle.
 
Pretty sure these guys have been on the inside for some time given all the fake parcel phishing mails I receive after placing orders that use them. They’ve probably just run out of phishing money so resorted to ransomware. TCG had better not pay the ransom. Rather lose the data.
What data is there to lose? Address are printed on the labels. further there should not be any private once use customer information on system what so ever. registered businesses are different and that should be safeguarded with backups.
 
Too much of a stretch to say it's a coincidence. So much more evidence for causal and driver's will never turn down a bit of side-hustle.

What would drivers have to do in relation to fake parcel phishing mails? Email addresses arent on waybills and if threat actors have access to those from the system, I can't see how they'd extract much added value from phishing emails by involving drivers.
 
They did have hackers in their system for awhile. Why else would you get a spam email saying pay X to release your courier guy parcel?
 
Adding the plus to email is rather useless, the phishers will have run a simple script on all the harvested emails, parsing them into email name and provider, then taking the name side, looking for the plus, and stripping that all out, then marrying them with the provider again to clean out the email. If you look at the sites you have used this at you will find a good number stripped this out in their system already, mostly because some email forwarders still use really old versions of assorted email systems, and they will often break when given something not bog vanilla base standard. Some even break when you use an underscore to emulate a space.
 
Top
Sign up to the MyBroadband newsletter
X