Ransomware victim disclosure
← All victimsTrans-World Shipping Service & Toledo Air Cargo
listed as tws-tac.net · Claimed by Threeam · listed 11 days ago
Status timeline
- ListedJul 18, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileTrans-World Shipping Service (TWS) and Toledo Air Cargo (TAC) is a full-service logistics company founded in 1954 and based in Toledo, Ohio. The company provides U.S. customs brokerage, international freight forwarding by land/sea/air, air cargo export services, and warehousing/distribution to import/export clients across 170+ countries. The company has been locally and family-owned for approximately 40 years.
- Industry
- Customs Brokerage & International Freight Forwarding
- Address
- 3206 Frenchmens Road, Toledo, OH 43607
- Employees
- 51-200
- Founded
- 1954
Attack summary
Severity: medium — Data has been published and the company operates in a regulated logistics/customs sector handling sensitive import/export client information; however, no specific data categories, volume, or operational disruption are confirmed in the available leak post excerpt.The threeam group claims to have compromised Trans-World Shipping's systems. The leak post provides minimal detail; no specific data exfiltration or encryption impact is stated in the disclosed excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Customer shipping records
- Business operations data
- Employee information
What the group claims
While ownership has changed over the years, the company has remained locally owned for over 65 years and family-owned for almost 40 years. The company is proud of the company's history and look forward to the future as the company continue to serv
Sources
Source
Indexed 11 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

