Desk live·
ForensicPost
Ransomware/Verification/File 24-1205

Termite Claims Blue Yonder Data and Says It Will Reuse the Email Lists

A newly named group claimed the Blue Yonder data and said it intended to reuse the email lists in it. That second part is the more interesting claim.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetBlue Yonder
ActorTermite
D. Kennedy12 min readConfidence: low3 sources reviewed

A group calling itself Termite claimed the Blue Yonder intrusion and said it had taken around 680GB, including more than 16,000 email lists and over 200,000 insurance documents. It said it intended to use the email lists for further attacks.

Every figure there originates with the group. This desk records them as claims and grades the file low accordingly.

The Stated Intention Is Not A Boast About Volume

Most attacker statements in this corpus advertise: a large number, a countdown, a sample. Saying what the data will be used for next is a different kind of statement, and if true it describes a pipeline rather than an event.

A supply-chain vendor’s address book is a list of named people at named customers who already correspond with that vendor. Phishing from that footing is a materially different proposition from phishing a cold list, which is presumably the point.

This Desk Cannot Verify Any Of It And Says So

Nothing here has been examined. The corpus recorded at 25-0215 that leaked chats showed demands priced off looked-up victim revenue rather than off the material taken, which gives an attacker no incentive to count accurately and every incentive to describe the haul as useful.

A stated plan is cheaper still. It costs nothing to announce and cannot be checked, and it raises pressure on the victim at no risk to the group.

A New Name Is Not A New Group

Termite appeared as a name in late 2024. The corpus filed at 25-0218 that what collapses when an operation is dismantled is a name, a leak site and some servers, while the technique, the affiliates and the access survive.

This desk therefore treats a newly observed brand as an observation about branding rather than about capability, and records no assessment of who is behind it.

How we reported this

Compiled from contemporaneous reporting of the group’s leak-site posting, listed below. The volume, the list and document counts and the stated intention all originate with the group claiming the intrusion; none has been verified by this desk, which has examined nothing. Graded low on that basis. No assessment is offered about the composition or history of the group. Corrections: corrections@forensicpost.com.

Sources
  1. Unmasking Termite, the ransomware gang claiming the Blue Yonder attackInfosecurity Magazine
  2. Blue Yonder SaaS giant breached by Termite ransomware gangBleepingComputer
  3. Termite ransomware attack on Blue Yonder: what you need to knowSOCRadar
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary