Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?


Data Breaches

Estes Express Lines Says Personal Data Stolen in Ransomware Attack

Estes Express Lines is informing over 21,000 individuals that their personal information was stolen in a ransomware attack.

Freight shipping giant Estes Express Lines has started informing more than 21,000 individuals that their personal information was stolen in a recent ransomware attack.

The incident was identified on October 1, 2023, and the investigation into the matter determined that the attackers gained access to the company’s network on September 26, 2023.

While residing in the network, the attackers accessed and extracted data from some of Estes’ systems, and deployed ransomware.

Estes says that a forensic investigation into the incident was concluded on November 7, but notification letters started being sent to the affected individuals only in December, after law enforcement concluded their own investigation into the incident.

The personal information that was compromised in the attack, Estes told the Maine Attorney General’s Office, included names, other personal identifiers, and Social Security numbers.

“Estes is not aware of any identity theft, fraud, or financial losses resulting from this incident,” the company said in the notification letter to the impacted individuals, a copy of which was submitted to the Maine AGO. The company told the Maine AGO that just over 21,000 individuals were affected.

“We have taken actions to mitigate the incident, including notifying and cooperating with the FBI regarding the incident, successfully locking out the unauthorized threat actor from the company’s system, and undertaking a full forensic investigation of the incident. We have also taken numerous steps to remediate the malware and harden the company’s IT systems,” Estes’ notification letter reads.

The company also underlined that it did not pay a ransom, but did not share specific details on its remediation and restoration efforts.

Advertisement. Scroll to continue reading.

While Estes did not name the ransomware that it fell victim to, the LockBit ransomware gang claimed responsibility for the attack in early November.  On November 13, the group published the data allegedly stolen from Estes on its Tor-based leak site.

Estes is offering the affected individuals free identity monitoring services for 12 months.

Related: Xerox Confirms Data Breach at US Subsidiary Following Ransomware Attack

Related: Free Decryptor Released for Black Basta Ransomware

Related: Over 900k Impacted by Data Breach at Defunct Boston Ambulance Service

Related: LoanCare Notifying 1.3 Million of Data Breach Following Cyberattack on Parent Company

Written By

Ionut Arghire is an international correspondent for SecurityWeek.


Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.


SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.


People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content


The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...


Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.


A SaaS ransomware attack against a company’s Sharepoint Online was done without using a compromised endpoint.


Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.

Data Breaches

LastPass DevOp engineer's home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud...

CISO Strategy

Okta is blaming the recent hack of its support system on an employee who logged into a personal Google account on a company-managed laptop.

Data Breaches

Delta Dental of California says over 6.9 million individuals were impacted by a data breach caused by the MOVEit hack.