International Trade Brokers and Forwarders Listed by 8Base Ransomware Group
If you are a customer of International Trade Brokers and Forwarders, here’s what is being claimed, and what it would mean for you.
ITBF is a company with more than 20 years of experience in the area of International Trade services. As a licensed Broker certified by the C-TPAT (Custom Trade Partnership Against Terrorism), of National Customs in the United States, we provide customs clearance services for merchandise arriving to the US at any port of unloading including Puerto Rico and Hawaii. Our direct communication with U.S. Customs allows us to provide agile and opportune support to our clients in the matter of operations logistics transportation. https://www.itbfusa.com
— from 8base’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
On January 12, 2024, International Trade Brokers and Forwarders appeared on the leak site operated by the 8base ransomware group. The company, which provides customs clearance and logistics services for shipments entering the United States, including Puerto Rico and Hawaii, had internal files exfiltrated during a ransomware attack. The listing does not specify the number of people affected or the exact volume or types of records taken beyond claiming that internal files were stolen.
Watch International Trade Brokers and Forwarders
Get alerted the next time International Trade Brokers and Forwarders files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about International Trade Brokers and Forwarders’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the 8base Listing
The primary disclosure on the 8base leak site states that ITBF suffered a ransomware incident in which attackers obtained and later published samples of internal files. The company’s own description notes it has operated for more than 20 years as a C-TPAT-certified customs broker with direct links to U.S. Customs. No customer record count, no list of specific data fields, and no ransom amount appear in the public posting. The disclosure simply states that exfiltrated material is now hosted on the extortion platform and that the victim was given a deadline to negotiate before further publication.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Why This Matters for You and Your Family
When a logistics and customs broker is breached, the information at risk often includes names, addresses, phone numbers, email accounts, shipment details, and payment records belonging to individuals and small businesses that use the service. If you or anyone in your household has imported goods through U.S. ports in the past two decades, your personal or business contact information may have been exposed. Internal files exfiltrated in ransomware attack can contain enough detail to support identity theft, tax fraud, or targeted phishing campaigns months or years later. Families who shipped personal items, vehicles, or gifts through customs brokers are not immune simply because the company serves commercial clients.
The Doxxing and Identity-Chain Risks
Stolen logistics records frequently link email addresses, phone numbers, physical shipping addresses, and sometimes dates of birth or government identification numbers. Attackers and data brokers can chain these details with username handles from forums, gaming platforms, or social media. A single exposed shipping address can tie a parent’s identity to a child’s online gaming account that uses the same household internet connection or recovery email. Once these connections surface on underground markets, the risk of account takeover, SIM swapping, or full doxxing increases sharply. Credential leaks of this nature routinely cascade into gaming account compromises that expose chat logs, payment methods, and further personal data.
8base’s Known Track Record
Public reporting attributes the emergence of 8base to mid-2022. The group has since listed hundreds of victims, focusing primarily on small and midsize businesses across professional services, manufacturing, and logistics. Their typical playbook involves gaining initial access through compromised remote desktop credentials or vulnerable VPNs, exfiltrating data before deploying ransomware, and then running a double-extortion campaign that combines encryption with public leak-site pressure. The 8base leak site is used both to name victims who refuse to pay and to publish proof files as leverage. While the group does not always release every stolen document immediately, the January 12, 2024 listing of International Trade Brokers and Forwarders follows their established pattern of gradual escalation.
What to do
- Run a DoxxScan to map every link between your handles, emails, phone numbers, and real identity, with cleanup handled by the service.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure surfaces in hours rather than months.
- Rotate any password you used on the ITBF site or related logistics portals anywhere it has been reused, and switch to 2FA through an authenticator app instead of SMS.
- Cover the entire household with DoxxScan family protection that extends to dependents and children’s gaming accounts tied to the same address or recovery details.
- Let remediation specialists manage takedown requests for any exposed personal records appearing on data-broker or extortion sites.
The incident shows that even established logistics providers with government certifications can fall victim to efficient ransomware operators who move quickly from access to extortion. Protecting yourself means treating every exposed customs or shipping record as a potential link in a larger identity chain. Start your DoxxScan trial today; its continuous monitoring, AI-powered identity-chain mapping, hands-on remediation by specialists, and household coverage—including children’s gaming accounts—give you and your family a practical defense against the breaches that keep appearing on leak sites like 8base’s.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Associated Gastroenterologists Of Central New York, P.C Listed by Booba Project Ransomware Group
Medical Practices Stolen data: 70 GB.…
northeastrehab.com Listed by BrainCipher Ransomware Group
N/A I don't have reliable, verified information about a specific company operating at this domain. …
Vera Science Listed by Genesis Ransomware Group
A Biotechnology Company…