Makfreight.com Listed by Settra Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
SourceLeak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.
Makfreight.com has been listed by the Settra ransomware group, with the incident disclosed on August 18, 2026. An undisclosed number of people may have had personal data exposed; affected individuals should check the company’s site or contact support for further guidance.
On August 18, 2026, the ransomware group Settra listed Makfreight.com on its leak site, naming M.A.K. Freight Systems in connection with a claimed cyber incident. Public detail is limited: the listing does not establish how many people may be involved, what files if any were taken, or how the group says it gained access. As of writing, the company has not publicly confirmed the incident.
A leak-site listing is an extortion tactic and an accusation, not independent verification. For customers, carriers, and partners who work with a cross-border freight broker, the practical question is what to watch for if the claim later proves partly or fully accurate—and what remains unknown today.
What the listing says
According to the listing, Settra has named Makfreight.com (M.A.K. Freight Systems) as a victim. The reported date associated with the public claim is August 18, 2026. The number of people affected is unknown. Data types named as exposed are not disclosed. Method of intrusion, ransom demand, timelines inside the network, and any proof-package contents beyond the fact of the listing are not described in the material provided for this report.
Settra’s appearance of a company name on a leak site should be read as the group’s claim. It does not, by itself, confirm that systems were encrypted, that data left the environment, or that any particular records are in circulation. Recycling of older material, exaggeration, and pressure tactics are known features of ransomware leak ecosystems; none of that can be ruled in or out from the listing alone.
Inside Settra
Settra is known publicly as a ransomware and extortion-oriented crew that follows a pattern common to many modern groups: pressure organizations by threatening to publish stolen data on a dedicated leak site if demands are not met. Like other actors in this space, Settra’s public face is the listing and any files or samples the group chooses to dangle; those materials are controlled by the claimant and are not a substitute for forensic confirmation by the victim or by regulators.
Typical tactics associated with such groups in open reporting include initial access through common enterprise weak points, movement inside networks, theft of data for leverage, and double-extortion messaging. None of those general patterns should be treated as a proven playbook for this specific Makfreight.com listing. The group claims involvement with this organization; independent confirmation of intrusion, exfiltration, or impact has not been established in the facts available here.
Who is Makfreight.com?
M.A.K. Freight Systems, associated with Makfreight.com, is described as a non-asset-based freight brokerage established in 1998. It offers customized transportation solutions across Canada, the United States, and Mexico, including full truckload (FTL) and less-than-truckload (LTL) services by road, intermodal, and air, using various equipment types.
Freight brokers sit between shippers and carriers. In ordinary operations they handle shipment details, contacts, billing and payment flows, and coordination across borders. That role makes continuity of operations and trust in commercial data important to many counterparties even when a cyber claim remains unverified. A listing aimed at such a firm matters because logistics relationships often involve repeated exchange of business contact data and shipment-related information—not because any specific theft has been proven.
What was likely exposed
The listing does not disclose what data types, if any, were taken. Exact contents are unconfirmed. No inventory of files, record counts, or categories should be treated as fact on the basis of the claim alone.
If files were taken from a firm in this sector, organizations of this kind typically hold some mix of the following—presented only as sector-typical possibilities, not as a description of this incident:
- Business contact details for shippers, carriers, and internal staff (names, phones, email addresses)
- Shipment and routing-related records, references, and scheduling information
- Invoices, rate confirmations, payment and banking-related commercial data
- Contracts, onboarding documents, and operational correspondence
- Credentials or system access material only if such items were stored in reachable systems—again unconfirmed here
Whether any of those categories apply in this case is unknown. People affected remain unknown. Readers should not assume their information was included.
Why it matters
For individuals and small businesses that deal with a broker, the conditional risks are familiar: if contact and commercial data were copied, phishing and invoice-fraud attempts can increase, sometimes spoofing a known logistics partner. Cross-border trade adds complexity—multiple jurisdictions, carriers, and payment paths—so a convincing fake “updated banking details” or “shipment hold” message can cause real financial loss even when the underlying breach claim is still disputed.
For the organization, a public extortion listing can create reputational and operational pressure regardless of ultimate technical findings. Partners may ask for assurances; staff may see a rise in social-engineering attempts that merely name the company. None of that proves negligence or confirms data loss; it reflects how leak-site claims are designed to work.
What a listing does establish is narrow: a named group has chosen to associate this company with its extortion channel on a given date. What it does not establish is scope, accuracy of any data description, or current exposure of any particular person.
What to do now
Treat the situation as a caution signal, not as proof that your records are public. If you work with M.A.K. Freight Systems or Makfreight.com, consider these conditional steps:
- If you receive urgent payment-change, W-9, or routing requests that cite this incident, verify out of band using a known phone number or prior contact—not reply chains alone.
- If you use shared portals or emailed documents with the broker, watch for unexpected login prompts and enable multi-factor authentication where available.
- If you suspect a invoice or identity scam tied to logistics email, document it and report it through your bank or local fraud channels as appropriate.
- Monitor financial and email accounts for unusual activity over the coming weeks without assuming compromise.
- Prefer official company channels for status; do not rely on ransomware sites for accurate inventories of your data.
You can also run a free exposure scan of your email to check whether your information has already surfaced in known breach data sets unrelated or related to other incidents. That check does not confirm or deny Settra’s claim about Makfreight.com; it only helps you see whether your address appears in previously compiled breach corpora. Stay alert to conditional risk, and treat unconfirmed leak-site accusations as claims until the company or another authoritative source says otherwise.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Wcmanagement.info Listed by Settra Ransomware GroupAlphanumeric.com Listed by Settra Ransomware GroupGrecosteel.com Listed by Settra Ransomware GroupAm-bition.jp Listed by Settra Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Makfreight.com Listed by Settra Ransomware Group →
Publicly posted by settra — unverified claim, pending independent verification. Leak-site claim data adapted from Ransomfeed.it, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.