Italian Customs Broker CAD 93 Hit by DeadLock Ransomware: Ransomware Claim — What’s Alleged & What To Do
Italian customs broker C.A.D. 93 S.r.l. was hit by DeadLock ransomware, with the incident disclosed on June 16, 2026. An undisclosed number of people may have had business data exposed; check whether your information was involved and take appropriate steps to protect it.
What happened
The incident came to public attention when ransomware monitoring sites recorded C.A.D. 93 S.r.l. as a claimed victim of the DeadLock group. The report appeared on or about June 16, 2026, and described the target as a logistics-related company handling international trade documentation. No further details on the timing of the intrusion, the method of access, or the volume of material involved have been released by the company or by investigators.
How a breach like this happens
Ransomware incidents in the supply-chain sector commonly begin with an initial foothold gained through phishing messages, exposed remote-access services, or compromised third-party software. Once inside the network, operators move laterally to locate file servers and backup systems. Data is copied before encryption occurs, after which a ransom note is left and a listing may appear on a leak site if payment demands are not met. The precise sequence in any single case remains unknown until the affected organisation publishes findings or law-enforcement agencies release technical indicators.
C.A.D. 93 S.r.l and its sector
C.A.D. 93 S.r.l. operates as a customs broker, preparing and submitting the declarations, certificates and supporting documents required for goods to cross international borders. Firms of this type routinely receive shipment manifests, invoices, transport contracts and regulatory filings that contain details about consignors, consignees and the contents of cargo. Because these records underpin lawful trade, any prolonged disruption or loss of access can affect clearance times for multiple importers and exporters that rely on the broker’s services.
What data was at risk
The listing identified the exposed material only as business data. Organisations in this sector typically store commercial correspondence, customs declarations, transport documents and client identifiers. The exact categories of information that may have been copied have not been confirmed by C.A.D. 93 S.r.l. or by any official notification issued to date.
The real-world impact
Individuals and companies whose trade documents were held by the broker face the possibility that their commercial details have been copied. Such information can be used for targeted fraud or competitive intelligence, though the scale of any such use remains unknown. For the brokerage itself, the incident may produce operational delays while systems are restored and regulatory reporting obligations are assessed. No statements regarding ransom demands or data-recovery outcomes have been made public.
Were you affected?
Anyone who has conducted customs-related business through C.A.D. 93 S.r.l. should monitor their own correspondence and financial accounts for unusual activity. A practical first step is to review recent statements from banks and freight forwarders for any unexpected references to shipments handled by the firm. Individuals can also run a free exposure scan of their email address against known breach data sets to determine whether their information appears in publicly discussed listings.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
TheGentlemen breaches Michigan IT services providerSISINT Engineering Firm Breached by QilinBrazilian IT Firm Service IT Breached by WorldLeaksChaos Ransomware Claims Breach of Universal Plant ServicesLatest breaches
Read GalaxyWarden’s full analysis of the Italian Customs Broker CAD 93 Hit by DeadLock Ransomware →
Publicly posted — pending verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.