Desk live·
ForensicPost
Ransomware/Availability/File 22-0220

Expeditors Shut Down Global Operations for Eight Days After Cyberattack

Expeditors International shut down most of its operating systems on 20 February 2022. For about eight days a company handling freight across more than 100 countries could not arrange shipments or clear customs — and the cost fell on its customers.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetExpeditors International
ActorUnattributed
D. Kennedy11 min readConfidence: medium3 sources reviewed

On 20 February 2022 Expeditors International, a Seattle-headquartered freight forwarder with around 18,000 employees across some 350 locations in more than 100 countries and revenues above $10 billion, announced it was the subject of a targeted cyberattack and shut down most of its operating systems.

The company reported limited ability to arrange freight shipments or manage customs and distribution. Eight days later most staff were still absent from the corporate office and employees could not log in. Operations were reported returning to normal from 3 March, with significant expenses acknowledged. The company did not formally confirm the attack type.

Shutting Down Was The Response

Taking systems offline deliberately is a containment decision, and it converts an uncertain compromise into a certain outage. It is frequently correct and it is never free.

We have recorded the same decision at 22-1002, where a hospital system went offline and to paper, and at 23-0625. What this file adds is that the organisation making the decision and the organisations bearing it were different: a freight forwarder’s downtime is measured in other companies’ cargo.

Nobody Counts A Container That Did Not Move

No individual was notified. No record count exists. No regulator produced a finding. On every measure this database usually applies, nothing happened.

What happened was eight days of interruption to a node in global logistics during a period when supply chains were already strained. We have argued at 24-1231 that availability harm goes uncounted, and at 22-0301 that just-in-time systems have no buffer by design. Expeditors is that argument without even a vehicle-production figure to stand in for the damage.

Silence About The Mechanism

The company described a targeted attack and did not characterise it further. Widely reported as ransomware, it was not confirmed as such, and no actor was named.

We have recorded at 26-0802 that a quarter of its files establish no entry route, and this is one of them. The desk notes the pattern it keeps finding at 23-1110 and 22-0301: the operational facts get reported because outsiders can see them, and the mechanism goes unreported because only the victim can supply it.

How we reported this

Compiled from contemporaneous reporting and the company’s public statements and filings, listed below. The attack was widely described as ransomware but was not confirmed as such by the company; no operation is named and no ransom demand or payment is asserted. No figure for financial impact is carried — the company acknowledged significant expenses without a public figure at the time. The absence of a confirmed mechanism is why this file is graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Cyberattack Hits Global Operations of Logistics Giant Expeditors InternationalSecurityWeek
  2. Global logistics giant Expeditors suffers cyberattack, shuts down operations systemsFreightWaves
  3. Expeditors cyberattack fells firm for 8 days — customers in darkThe Stack
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary