On January 24, 2025, logistics company Coyote.com appeared on the public leak site of the Clop ransomware group. The company, a UPS subsidiary that arranges freight transportation for thousands of shippers through a network of more than 70,000 carriers, is claimed to have had internal files exfiltrated during a ransomware attack. Public reporting indicates the number of people whose information was exposed remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Coyote.Com
Get alerted the next time Coyote.Com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Coyote.Com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes the incident as a ransomware attack in which Clop gained access to Coyote.com systems and removed internal files before encrypting data. The files were later published on the group’s leak site. Coyote.com provides truckload, less-than-truckload, intermodal brokerage, and transportation management services. No confirmed total of affected records or specific categories of personal data has been released by the company or the attackers. Industry research from sources such as DoxxScan™ continuous monitoring indicates that logistics-sector breaches frequently expose employee, customer, and partner records including names, contact details, and financial information.
Why This Matters for You and Your Family
When a logistics provider like Coyote.com suffers a breach, the ripple effects reach ordinary people who shipped packages, worked with partner companies, or had their employment or vendor data stored in the affected systems. If your name, address, email, phone number, or payment details were among the internal files, criminals can use that information to attempt account takeovers, file fraudulent tax returns, or open new accounts in your name. For families this can mean sudden unexpected bills, damaged credit, or hours spent on the phone correcting records. Children’s information linked to family shipping accounts or parent email addresses can also surface in follow-on attacks.
The Doxxing and Identity-Chain Implications
Stolen internal files often contain spreadsheets that link employee names to personal email addresses, phone numbers, and sometimes spouse or dependent details. Attackers combine this data with information from other breaches to build detailed profiles. A single exposed work email can lead to gaming accounts, social-media handles, and home addresses being connected in what security analysts call an identity chain. Once mapped, these chains enable doxxing, targeted phishing, and extortion. Credential leaks like this one frequently cascade into account takeovers on personal services, including gaming platforms used by you or your children.