Ransomware victim disclosure
← All victimsaceforwarding.com
Claimed by threeam · listed 20 days ago
Status timeline
- Listed
May 1, 2026
- Data leaked
At a glance
- Group
- threeam
- Status
- Data leaked
- Country
- United States
- Sector
- Transportation/Logistics
- Listed on leak site
- May 1, 2026
About the victim
AI dossier — public-source company profileACE Forwarding is a US-based freight forwarding and logistics company founded in 1994 in the Detroit, Michigan area. The company provides air freight, expedited ground transport, crating, international forwarding, intermodal, and warehousing services to industries including aerospace, automotive, retail, and medical. It operates a fleet of over 30 company-owned vehicles and maintains government contractor credentials (CAGE Code: 9VCX5; UEI: JQVVGJ35HK77).
- Industry
- Freight Forwarding & Logistics
- Address
- Detroit, Michigan area, United States (precise street address not stated on public site)
- Founded
- 1994
Attack summary
Severity: high — Data has been published (disclosed status: data_published) by a known ransomware group, confirming exfiltration of business data. The company holds government contractor credentials (CAGE/UEI codes) and serves regulated sectors including aerospace, automotive, and medical, elevating the potential sensitivity of exposed data beyond typical logistics firms.The ThreeAM ransomware group claims to have compromised ACE Forwarding and has reached the data_published stage, indicating exfiltration and publication of company data. No specific ransom amount or data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Company operational data
- Customer shipment records
- Government contractor credentials/identifiers
- Employee information (probable)
- Business correspondence (probable)
What the group claims
Ace Forwarding started out in 1994 as a small operation with a single truck picking up and delivering to and from the Detroit airport, fulfilling our customers time-critical shipments and becoming the go-to logistics operation when time was of the
Sources
Source
Indexed 20 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
