52 domains are being used in phishing attempts by a financially driven threat group called “Diesel Vortex” to steal credentials from freight and logistics businesses in the United States and Europe.
The threat actor has been stealing 1,649 distinct credentials from platforms and service providers that are essential to the freight industry since September 2025.
DAT Truckstop, TIMOCOM, Teleroute, Penske Logistics, Girteka, and Electronic Funds Source (EFS) are a few of the victims of Diesel Vortex.
The typosquatting monitoring platform’s researchers After discovering an exposed repository that contained a SQL database from a phishing operation that the threat actor named Global Profit and sold to other cybercriminals under the alias MC Profit Always, Have I Been Squatted discovered the campaign.
A file containing Telegram webhook logs that showed conversations between the phishing service operators was also included in the repository. The researchers think Diesel Vortex is an Armenian-speaking actor read more about Phishing campaign targets freight and logistics orgs in the US and Europe.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
