Ransomware victim disclosure
← All victimsHOC Global Solutions
listed as Hoc · Claimed by Qilin · listed 21 hours ago
Status timeline
- ListedJul 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Jul 28, 2026
About the victim
AI dossier — public-source company profileHOC Global Solutions is a privately owned Canadian customs brokerage and logistics provider founded in 1974, headquartered in Toronto with operations across North America. They provide customs clearance, freight forwarding, air/ocean transport, and supply chain management services with representatives in over 450 locations across 196 countries.
- Industry
- Customs Brokerage & Freight Forwarding Logistics
- Address
- Toronto, Ontario, Canada (headquarters); Tonawanda, New York, USA (branch)
- Founded
- 1974
Attack summary
Severity: medium — Confirmed data publication by ransomware group targeting a logistics/customs broker handling sensitive trade and import/export data. However, lack of detailed leak post content and proof count limits confidence in severity elevation. Potential exposure of business/shipment data of moderate scale.Qilin ransomware group claims to have attacked HOC Global Solutions. No leak post content was provided; disclosed status indicates data has been published, but specific attack claims and data categories are not detailed in available materials.
Data the group says was taken
AI dossier — extracted from the leak post- customs documentation
- freight shipping records
- client shipment data
- customs clearance information
- supply chain records
What the group claims
N/A
Sources
Source
Indexed 21 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

