
US freight transporter Estes Forwarding Worldwide said it is investigating a data security incident following claims by the Qilin ransomware group that it breached the company’s internal network and stole sensitive data.
Headquartered in Richmond, Virginia, Estes Forwarding Worldwide (EFW) is a logistics and freight forwarding company that provides customised domestic and international transportation solutions. It is a subsidiary of Estes Express Lines, one of the largest privately held freight transportation networks in North America. EFW offers a range of services including air, ocean, and ground freight, customs brokerage, and warehousing solutions.
Recently, in a statement shared with FreightWaves, EFW CEO Scott Fisher, said that on May 28, the company was a victim of a data security incident. Immediately after identifying the incident, EFW launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
“We want to assure you there was no significant disruption to our business. Thanks to our robust cybersecurity protocols, system redundancies, and the swift response of our IT team and third-party security experts, we were fully operational within hours. We are grateful for the support of our parent company Estes Express Lines throughout this incident.
“Neither Estes LTL nor Estes Logistics were impacted by this event. Protecting your information and maintaining your trust remain our highest priorities,” CEO Fisher said.
🚨 Ransomware Alert 🚨
— FalconFeeds.io (@FalconFeedsio) June 23, 2025
Estes Forwarding Worldwide 🇺🇸
📢 Estes Forwarding Worldwide (https://t.co/LTnft2YNl2), a logistics solutions provider specializing in warehousing, trade show logistics, and multimodal transport, based in the USA, has fallen victim to Qilin ransomware.
🔍… pic.twitter.com/PFIdRgg2VR
On June 23, the Qilin ransomware group claimed responsibility for the cyber attack on EFW and listed it as a victim on its data leak site. The group said it had stolen sensitive data, including passport scans, driver’s licenses, and spreadsheets, and published the same, indicating a failed ransom negotiation.
In October 2023, Estes Express Lines said that it was a victim of a cyber security incident that caused a serious “IT infrastructure outage.” The cyber attack also affected Estes’ online tracking service for goods and vehicles in transit. Several clients of the company weren’t able to track their shipments and took to social media to voice their concerns.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543