158 years in business, hundreds of trucks and around 700 people. Then came a ransomware attack that started with a compromised password, and a business found itself in a situation it could no longer recover from.
This is the story of KNP Logistics, a British transport company whose history went all the way back to the 19th century. The attack encrypted systems and critical operational data, leaving hundreds of trucks without access to the information needed to run the business. KNP was already facing difficult market conditions, so it would be simplistic to say that “one password brought down a company”. But the cyberattack hit at exactly the moment when the business needed to keep operating and secure new financing.
And I couldn’t help thinking: what would it feel like to spend a lifetime building a business and then risk losing almost everything because of one access point nobody considered important enough?
I’m starting with this story not because I want to scare anyone, but because it illustrates something I have heard many times, in different forms, in conversations with business owners and managers:
“Yes, I know the risk exists. But it can’t happen to me.”
I started with cargo theft and ended up talking about passwords
Over the past few weeks, I have been researching fraud and security in transport and logistics quite intensively for a series of conversations we are preparing at DRIVION.
I started with risks that are relatively familiar to the industry: cargo theft, fuel and fuel card theft, forged documents. Then I moved on to fake carriers, identity theft, compromised accounts, phishing, ransomware, payment fraud and unauthorised access to company systems.
I have worked in transport and logistics for more than 20 years, and I thought I had a fairly good understanding of the vulnerabilities facing this industry. Even so, one of the findings genuinely surprised me:
Transport is the second most targeted sector in the European Union in terms of cyber incidents analysed by ENISA. After public administration.
Not banking. Not IT. Transport.
And once I started putting the data side by side, the picture became increasingly difficult to ignore:
- 7.5% of the 4,875 incidents analysed by ENISA in its Threat Landscape 2025 involved the transport sector, placing it second in the EU. Around 60% of initial compromise vectors are linked to phishing, while ransomware is considered the threat with the greatest impact.
- In Romania, in 2025, phishing incidents increased by 70.6%, fraud and attempted fraud by 91%, account compromises by 353%, while ransomware incidents reflected in DNSC data increased by more than 153% compared with the previous year.
- In the area of cargo crime, TAPA EMEA recorded 58,661 reported incidents across 101 countries in EMEA in just 18 months, up to 30 June 2026.
- Known losses exceeded EUR 1 billion, although a financial value was available for only 7.8% of cases.
And I went back to the example of the transport company that went bankrupt: what would it feel like to spend a lifetime building a business and end up in such a situation because of one access point that nobody considered important enough?
Because I believe this is where the real problem lies.
We do not lack information. We have specialists constantly telling us to change our passwords, enable MFA, review system access, back up our data, avoid suspicious links and close the accounts of former employees. We have probably all read these recommendations dozens of times.
And precisely because we have heard them so many times, we have started to stop hearing them.
I had a very good demonstration of this myself these days.

After weeks of reading about fraud and cybersecurity and having discussions with supply chain security specialists, I logged into the Orange platform for my phone number. The message in the image above about Orange Cybersecure appeared.
My first reaction?
To skip it.
“I don’t need this right now.”
And, for a fraction of a second, I think that somewhere in the back of my mind was exactly the idea I had just been researching for an article:
It can’t happen to me.
The situation amused me a little, but it also made me think. Because if, after two weeks of reading every day about companies being attacked, compromised accounts and fraud, my reflex can still be “I’ll look at it another time”, then perhaps the problem is not a lack of information.
It is our behaviour.
Today, almost our entire professional life is digital. I use “in the cloud” in the broadest sense from a user’s perspective: phone, laptop, tablet, email, WhatsApp, Google Drive, Microsoft 365, ERP, TMS, WMS, bank account, CRM, transport platform. Invoices, contracts, customers, passwords, documents, conversations and sometimes even information about the exact location of a shipment are accessible through a device and a digital identity.
And yet we continue to postpone the simplest things.
We use the same password for years. We do not enable multi-factor authentication because it means one extra click. We forget to withdraw access from a colleague who has left the company. We have shared accounts used by several people. We use personal Yahoo or Gmail addresses for business without minimum centralised administration and access policies. We do not periodically check who still has access to what. We receive a change of IBAN or delivery address by email and sometimes fail to confirm it through a second channel.
These are not spectacular measures. That is precisely the problem.
A sophisticated firewall looks like cybersecurity. Disabling a colleague’s access on the same day they leave looks like administration.
Until that access remains active.
I think this is the thing that has stayed with me most strongly after the research of the past few weeks: the most dangerous vulnerabilities are not always the ones we do not know about. Very often, they are the ones we do know about and keep postponing because, so far, nothing has happened.
Today we have more voices, tools and information about security than ever before. Perhaps the next step is not to read another guide.
Perhaps it is simply to take one of the recommendations we have kept postponing and actually implement it.
Because “it can’t happen to me” works perfectly.
Until the day it happens.
What do all these figures actually mean?
That we can no longer treat security as something “for later” or “for large companies”. That a truck that is physically well protected can still be completely vulnerable through an email, a cloud account or a password that has been recycled for three years. That fraudsters no longer need to break into anything – they only need to appear legitimate once, at the right moment.
And, above all, that the silence around this subject makes us, as an industry, more vulnerable, not safer. The less openly we talk about what fraud or an attack actually looks like in practice, the easier we become to predict.
That is why we have decided to address this subject head-on, with data, experts and real stories from those who have been through it, in the new BUSOLA Podcast mini-series dedicated to risk and vulnerability in transport and logistics. Because our industry contributes too much to this country’s economy – road freight transport is Romania’s leading exporter of services, contributing almost 3% to GDP – for us to continue treating security as a taboo subject.
Follow the launch of the BUSOLA Podcast mini-series on DRIVION’s channels.
