M.A.K. Freight Systems Data Breach

Alleged

Ransomware claim involving M.A.K. Freight Systems

Published: Aug 19, 2026 Settra
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
M.A.K. Freight Systems
Industry
Transportation and Logistics
Threat Actor
Settra
Date of Incident
Aug 19, 2026

Executive Summary

M.A.K. Freight Systems, a freight and logistics company based in Malaysia, has been listed as a victim by the Settra ransomware group. The listing was observed on August 19, 2026, and was identified through SOCRadar’s Dark Web Monitoring capabilities. The nature of the freight and logistics sector, handling significant volumes of data and potentially valuable cargo, can make companies within this industry attractive targets for ransomware attacks seeking financial gain. The Settra ransomware group’s recent activity shows a pattern of diverse targeting, with listings appearing across multiple countries and industries. In a similar batch of listings, Settra also claimed victims such as Greco Steel Products (Greece, Manufacturing), AMBITION Group (Japan), ALPHANUMERIC SYSTEMS, INC. (US), and West Coast Management and Realty. This suggests that Settra’s operations may not be exclusively focused on specific sectors like logistics, but rather leverage access gained through various means, potentially including information broker (IAB) sourced access, rather than a highly targeted campaign against a particular industry.

Technical Analysis

SOCRadar’s analysis identified one stealer-log record associated with the domain mak-freight[.]com[.]my. This record contained a single employee credential, originating from an Android mobile device. The compromise likely occurred through a mobile stealer payload, potentially targeting an enterprise application or Mobile Device Management (MDM) portal. The credential data was dated September 1, 2025, indicating it was harvested approximately eleven months prior to the Settra listing. This timeline aligns with typical information broker (IAB) practices, where credentials are harvested, stored, and subsequently sold or utilized for further malicious activities. The presence of mobile-sourced corporate credentials in underground markets is an increasing trend, driven by the maturation of mobile stealer variants. If the compromised employee identity was reused across other enterprise services, such as corporate email, VPN connections, or other cloud applications, without prompt rotation, the access may still be active and exploitable by threat actors. To mitigate potential risks, it is recommended that M.A.K. Freight Systems rotate the affected employee’s credentials immediately. Furthermore, reviewing access logs from their MDM portal, particularly for the period starting September 2025, would be crucial to identify any unauthorized activity. Continued monitoring of the dark web and stealer-log feeds is advisable for any newly discovered credentials associated with M.A.K. Freight Systems or its subsidiaries. Proactive credential hygiene checks, including mandatory password rotation and multi-factor authentication enforcement across all critical systems, remain essential preventative measures. Reviewing access logs for Microsoft 365, VPNs, and any other remote-access portals is also a key step in understanding the potential scope of credential compromise and preventing further intrusion.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.