Technology
Major US shipping platform left customer data wide open to hackers
NEWYou can now listen to Fox News articles!
Cargo theft is no longer just about stolen trucks and forged paperwork. Over the past year, security researchers have been warning that hackers are increasingly targeting the technology behind global shipping, quietly manipulating systems that move goods worth millions of dollars.
In some cases, organized crime groups use hacked logistics platforms to redirect shipments, allowing criminals to steal goods without ever setting foot in a warehouse. One recent case involving a critical U.S. shipping technology provider shows just how exposed parts of the supply chain have been, and for how long.
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter
A key shipping platform was left wide open
CRIME RINGS, HACKERS JOIN FORCES TO HIJACK TRUCKS NATIONWIDE, FUELING MAJOR HOLIDAY SHIPPING SECURITY FEARS
Digital shipping platforms now control how goods move worldwide, making cybersecurity failures a direct risk to the global supply chain. (John Keeble/Getty Images)
The company at the center of this incident is Bluspark Global, a New York-based firm whose Bluvoyix platform is used by hundreds of companies to manage and track freight moving around the world. While Bluspark isn’t a household name, its software supports a large slice of global shipping, including major retailers, grocery chains and manufacturers.
For months, Bluspark’s systems reportedly contained basic security flaws that effectively left its shipping platform exposed to anyone on the internet. According to the company, five vulnerabilities were eventually fixed, including the use of plaintext passwords and the ability to remotely access and interact with the Bluvoyix platform. These flaws could have given attackers access to decades of shipment records and customer data.
Bluspark says those issues are now resolved. But the timeline leading up to the fixes raises serious concerns about how long the platform was vulnerable and how difficult it was to alert the company in the first place.
How a researcher uncovered the flaws
Security researcher Eaton Zveare discovered the vulnerabilities in October while examining the website of a Bluspark customer. What started as a routine look at a contact form quickly escalated. By viewing the website’s source code, Zveare noticed that messages sent through the form passed through Bluspark’s servers using an application programming interface, or API.
From there, things unraveled fast. The API’s documentation was publicly accessible and included a built-in feature that allowed anyone to test commands. Despite claiming authentication was required, the API returned sensitive data without any login at all. Zveare was able to retrieve large amounts of user account information, including employee and customer usernames and passwords stored in plaintext.
Worse, the API allowed the creation of new administrator-level accounts without proper checks. That meant an attacker could grant themselves full access to Bluvoyix and view shipment data going back to 2007. Even security tokens designed to limit access could be bypassed entirely.
Why it took weeks to fix critical shipping security flaws
One of the most troubling parts of this story isn’t just the vulnerabilities themselves, but how hard it was to get them fixed. Zveare spent weeks trying to contact Bluspark after discovering the flaws, sending emails, voicemails, and even LinkedIn messages, without success.
With no clear vulnerability disclosure process in place, Zveare eventually turned to Maritime Hacking Village, which helps researchers notify companies in the shipping and maritime industries. When that failed, he contacted the press as a last resort.
Only after that did the company respond, through its legal counsel. Bluspark later confirmed it had patched the flaws and said it plans to introduce a formal vulnerability disclosure program. The company has not said whether it found evidence that attackers exploited the bugs to manipulate shipments, stating only that there was no indication of customer impact. It also declined to share details about its security practices or any third-party audits.
10 ways you can stay safe when cyberattacks hit supply chains
Hackers can break into a shipping or logistics platform without you ever realizing your data was involved. These steps help you reduce risk when attacks like this happen.
1) Watch for delivery-related scams and fake shipping notices
After supply chain breaches, criminals often send phishing emails or texts pretending to be shipping companies, retailers, or delivery services. If a message pressures you to click a link or “confirm” shipment details, slow down. Go directly to the retailer’s website instead of trusting the message.
2) Use a password manager to protect your accounts
If attackers gain access to customer databases, they often try the same login details on shopping, email, and banking accounts. A password manager ensures every account has a unique password, so one breach doesn’t give attackers the keys to everything else.
Next, see if your email has been exposed in past breaches. Our #1 password manager (see Cyberguy.com) pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2026 at Cyberguy.com
3) Reduce your exposed personal data online
Security researchers found exposed APIs that allowed access to sensitive shipping data without proper authentication. (Portra/Getty Images)
Criminals often combine data from one breach with information scraped from data broker sites. Personal data removal services can help reduce how much of your information is publicly available, making it harder for criminals to target you with convincing scams.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com
4) Run strong antivirus software on your devices
Strong antivirus software can block malicious links, fake shipping pages, and malware-laced attachments that often follow high-profile breaches. Keeping real-time protection enabled adds an important layer when criminals try to exploit confusion.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
HUGE DATA LEAK EXPOSES 14 MILLION CUSTOMER SHIPPING RECORDS
5) Enable two-factor authentication wherever possible
Two-factor authentication (2FA) makes it much harder for attackers to take over accounts, even if they have your password. Prioritize email, shopping accounts, cloud storage and any service that stores payment or delivery information.
6) Review your account activity and delivery history
Check your online shopping accounts for unfamiliar orders, address changes, or saved payment methods you don’t recognize. Catching changes early can prevent fraud from escalating.
7) Consider identity theft protection
Identity theft protection services can alert you to suspicious credit activity and help you recover if attackers access your name, address or other personal details. Identity Theft companies can monitor personal information like your Social Security Number (SSN), phone number, and email address and alert you if it is being sold on the dark web or being used to open an account. They can also assist you in freezing your bank and credit card accounts to prevent further unauthorized use by criminals.
See my tips and best picks on how to protect yourself from identity theft at Cyberguy.com
8) Place a free credit freeze to stop new fraud
If your name, email, or address was exposed, consider placing a credit freeze with the major credit bureaus. A freeze prevents criminals from opening new accounts in your name, even if they obtain additional personal data later. It’s free, easy to lift temporarily, and one of the most effective steps you can take after a breach. To learn more about how to do this, go to Cyberguy.com and search “How to freeze your credit.”
9) Lock down your shipping and retailer accounts
Review the security settings on major shopping and delivery accounts, including retailers, grocery services and shipping providers. Pay close attention to saved delivery addresses, default shipping locations and linked payment methods. Attackers sometimes add their own address quietly and wait before making a move.
10) Businesses should review third-party logistics access
If you run a business that relies on shipping or logistics platforms, incidents like this are a reminder to review vendor access controls. Limit administrative permissions, rotate API keys regularly, and confirm vendors have a clear vulnerability disclosure process. Supply chain security depends on more than just your own systems.
Hackers increasingly target logistics technology, manipulating systems to redirect shipments without physical theft. (Thomas Trutschel/Photothek via Getty Images)
Kurt’s key takeaway
Shipping platforms sit at the intersection of physical goods and digital systems, making them attractive targets for cybercriminals. When basic protections like authentication and password encryption are missing, the consequences can spill into the real world, from stolen cargo to supply chain disruption. The incident also highlights how many companies still lack clear, public ways for researchers to report vulnerabilities responsibly.
Do you think companies that quietly power global supply chains are doing enough to protect themselves from cyber threats? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
We found 20 Verge-approved gifts on sale ahead of Valentine’s Day
Valentine’s Day is coming up fast, and if you haven’t started shopping yet, there are a lot of great gifts on sale that should still arrive in time if you order soon. Several Verge-approved gadgets are seeing some of their best discounts since the holidays, with options we think will appeal to a wide range of interests, from thoughtful picks like digital photo frames to e-readers, smart speakers, smartwatches, massagers, and even practical stuff like vacuums. While some are bigger-ticket items, quite a few cost under $100, so there’s something here for a range of budgets, too.
Below, we’ve rounded up the best Valentine’s Day gift deals you can shop right now across a range of categories and prices, whether you’re buying for a partner, a friend, or yourself.
Technology
Fox News AI Newsletter: ‘The American people are being lied to about AI’
NEWYou can now listen to Fox News articles!
Welcome to Fox News’ Artificial Intelligence newsletter with the latest AI technology advancements.
IN TODAY’S NEWSLETTER:
– Palantir’s Shyam Sankar: Americans are ‘being lied to’ about AI job displacement fears
– OPINION: Elon Musk says you can skip retirement savings in the age of AI. Not so fast
– Chevron CEO details strategy to shield consumers from soaring AI power costs
LIES EXPOSED: “The American people are being lied to about AI,” Palantir CTO Shyam Sankar warns in the opening line of his new Fox News op-ed. And one of the biggest lies, he said, is that artificial intelligence is coming for Americans’ jobs.
Shyam Sankar, chief technology officer of Palantir Technologies Inc., speaks during the Hill & Valley forum at the U.S. Capitol in Washington, D.C., on Wednesday, April 30, 2025. (Getty Images)
RISKY RETIREMENT: Billionaire Elon Musk recently told people not to worry about “squirreling” money away for retirement because advances in artificial intelligence would supposedly make savings irrelevant in the next 10 to 20 years.
OFF-THE-GRID: Chevron CEO Mike Wirth detailed the company’s strategy to harness U.S. natural resources to meet soaring artificial intelligence power demand — without passing the cost along to consumers.
The COL4 AI-ready data center is located on a seven-acre campus at the convergence point of long-haul fiber and regional carrier fiber networks on July 24, 2025, in Columbus, Ohio. (Eli Hiller/For The Washington Post via Getty Images)
POWER CRISIS NOW: Artificial Intelligence and data centers have been blamed for rising electricity costs across the U.S. In December 2025, American consumers paid 42% more to power their homes than ten years ago.
LATEST POLLING: As the emphasis on implementing artificial intelligence across society grows, voters think the use of AI technology is happening too fast — and they have little confidence the federal government can regulate it properly.
PRIVACY NIGHTMARE: A popular mobile app called Chat & Ask AI has more than 50 million users across the Google Play Store and Apple App Store. Now, an independent security researcher says the app exposed hundreds of millions of private chatbot conversations online.
CAP-EX SURGE: Alphabet executives struck a confident tone on Wednesday’s post-earnings call, signaling that Google’s heavy investments in artificial intelligence are now translating into real revenue growth across the business.
Google Headquarters is seen in Mountain View, California, on May 15, 2023. (Tayfun Coskun/Anadolu Agency via Getty Images)
MERIT OVER FEAR: Shyam Sankar, the chief technology officer and executive vice president of Palantir Technologies, told Fox News Digital that artificial intelligence will be a “massively meritocratic force” within the workplace and offered advice to corporate leaders on how to best position their companies and employees for success.
FAKE LOVE HEIST: A woman named Abigail believed she was in a romantic relationship with a famous actor. The messages felt real. The voice sounded right. The video looked authentic. And the love felt personal. By the time her family realized what was happening, more than $81,000 was gone — and so was the paid-off home she planned to retire in.
FOLLOW FOX NEWS ON SOCIAL MEDIA
Facebook
Instagram
YouTube
X
LinkedIn
SIGN UP FOR OUR OTHER NEWSLETTERS
Fox News First
Fox News Opinion
Fox News Lifestyle
Fox News Health
DOWNLOAD OUR APPS
Fox News
Fox Business
Fox Weather
Fox Sports
Tubi
WATCH FOX NEWS ONLINE
Fox News Go
STREAM FOX NATION
Fox Nation
Stay up to date on the latest AI technology advancements, and learn about the challenges and opportunities AI presents now and for the future with Fox News here.
Technology
Google is expanding AirDrop support to more Android devices ‘very soon’
After introducing AirDrop support to Pixel 10 devices last year, Google is now set to expand it to phones made by other Android partners. Eric Kay, vice president of engineering for Android, confirmed in a press briefing attended by Android Authority that “a lot more” Android devices will be able to use Quick Share to initiate AirDrop sessions with Apple devices this year.
“We spent a lot of time and energy to make sure that we could build something that was compatible not only with iPhone but iPads and MacBooks,” Kay said. “Now that we’ve proven it out, we’re working with our partners to expand it into the rest of the ecosystem, and you should see some exciting announcements coming very soon.”
Currently, Google’s Pixel 10 phones are the only Android devices that can use Quick Share — Android’s own wireless peer-to-peer transfer feature, previously known as Nearby Share — to communicate directly with Apple’s AirDrop. Google hasn’t outlined any specific Android partners or devices for the update yet, but both Nothing and chipmaker Qualcomm teased in November that support was coming.
Kay also discussed Google’s efforts to improve the process for iOS users who switch to Android, helping to prevent incomplete data transfers, lost messages, and other issues. Apple has been working on a “user-friendly” way of transferring data from iPhones to other devices since early 2024, and Google and Apple’s collaborative efforts were seen being tested in Android Canary 2512 for Pixel devices in December.
“We’re also going to be working to make it easy for people who do decide to switch to transfer their data and make sure they’ve got everything they had from their old phone,” Kay said during the same briefing. “So there’s a lot more going on with that.”
-
Indiana5 days ago13-year-old rider dies following incident at northwest Indiana BMX park
-
Massachusetts6 days agoTV star fisherman, crew all presumed dead after boat sinks off Massachusetts coast
-
Tennessee7 days agoUPDATE: Ohio woman charged in shooting death of West TN deputy
-
Indiana5 days ago13-year-old boy dies in BMX accident, officials, Steel Wheels BMX says
-
Politics1 week agoVirginia Democrats seek dozens of new tax hikes, including on dog walking and dry cleaning
-
Politics3 days agoTrump unveils new rendering of sprawling White House ballroom project
-
Austin, TX1 week ago
TEA is on board with almost all of Austin ISD’s turnaround plans
-
Texas6 days agoLive results: Texas state Senate runoff