{"id":114254,"date":"2026-01-14T20:40:17","date_gmt":"2026-01-14T18:40:17","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=114254"},"modified":"2026-01-14T20:41:47","modified_gmt":"2026-01-14T18:41:47","slug":"us-cargo-firm-exposes-shipping-systems-and-customer-data-online","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/business\/114254\/us-cargo-firm-exposes-shipping-systems-and-customer-data-online\/","title":{"rendered":"US Cargo Firm Exposes Shipping Systems and Customer Data Online"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Security researchers have warned the shipping industry about cyberattacks linked to cargo thefts, involving collusion between hackers and organized crime.<br>&#8211; Bluspark Global, a key U.S. shipping tech company, recently fixed critical vulnerabilities in its Bluvoyix platform that exposed decades of customer data.<br>&#8211; Researcher Eaton Zveare discovered the flaws, including plaintext passwords and an unauthenticated API, but faced significant difficulty contacting the unresponsive company.<br>&#8211; The vulnerabilities allowed unauthorized access to create admin accounts and view sensitive shipment data, posing a severe security risk until patched.<br>&#8211; Bluspark has now resolved the issues and plans to establish a disclosure program for future vulnerability reports, though it claims no evidence of malicious exploitation.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">S<\/mark>ecurity experts have been sounding the alarm for the past year, warning the international shipping sector to significantly bolster its digital protections. A troubling trend has emerged where sophisticated cyberattacks on logistics firms are facilitating the large-scale theft and diversion of customer goods, effectively creating a dangerous partnership between hackers and organized criminal networks. This isn&#8217;t about minor thefts; it&#8217;s a systematic threat to global supply chains.<\/p>\n\n<p class=\"wp-block-paragraph\">In this context, a recent incident involving a key U.S. shipping technology provider underscores just how vulnerable these critical systems can be. <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/bluspark-global\/\" class=\"acp-entity-link\" data-entity-id=\"193317\" data-entity-category=\"Organization\" title=\"Learn more about Bluspark Global\" target=\"_blank\" rel=\"noopener noreferrer\">Bluspark Global<\/a><\/strong>, a <a href=\"https:\/\/digitrendz.blog\/z\/entity\/new-york\/\" class=\"acp-entity-link\" data-entity-id=\"4634\" data-entity-category=\"Location\" title=\"Learn more about New York\" target=\"_blank\" rel=\"noopener noreferrer\">New York<\/a>-based company, spent recent months repairing a series of basic security weaknesses in its <a href=\"https:\/\/digitrendz.blog\/z\/entity\/bluvoyix\/\" class=\"acp-entity-link\" data-entity-id=\"193318\" data-entity-category=\"product\" title=\"Learn more about Bluvoyix\" target=\"_blank\" rel=\"noopener noreferrer\">Bluvoyix<\/a> platform. This software is used by hundreds of major corporations, including prominent retailers, grocery chains, and furniture manufacturers, to manage and track freight shipments worldwide. For a period, these vulnerabilities left the platform&#8217;s digital doors unlocked, potentially exposing decades of sensitive customer shipment data to anyone on the internet.<\/p>\n\n<p class=\"wp-block-paragraph\">The company has stated that all identified security issues are now resolved. The flaws, discovered by researcher <a href=\"https:\/\/digitrendz.blog\/z\/entity\/eaton-zveare\/\" class=\"acp-entity-link\" data-entity-id=\"144854\" data-entity-category=\"Person\" title=\"Learn more about Eaton Zveare\" target=\"_blank\" rel=\"noopener noreferrer\">Eaton Zveare<\/a> in October, were severe. They included the use of <strong><a href=\"https:\/\/digitrendz.blog\/z\/topic\/plaintext-passwords\/\" class=\"acp-topic-link\" data-topic-id=\"158100\" title=\"Explore: plaintext passwords\" target=\"_blank\" rel=\"noopener noreferrer\">plaintext passwords<\/a><\/strong> for both employees and customers and a critical flaw allowing <strong>remote, unauthenticated access<\/strong> to the core shipping software. This combination could have granted attackers complete visibility into a customer&#8217;s logistics operations and historical records.<\/p>\n\n<p class=\"wp-block-paragraph\">Zveare&#8217;s attempt to responsibly report these problems, however, hit a major roadblock: <a href=\"https:\/\/digitrendz.blog\/z\/entity\/bluspark\/\" class=\"acp-entity-link\" data-entity-id=\"193321\" data-entity-category=\"Organization\" title=\"Learn more about Bluspark\" target=\"_blank\" rel=\"noopener noreferrer\">Bluspark<\/a> had no publicly available channel for security disclosures. After submitting his findings through a maritime security nonprofit and attempting contact via email, voicemail, and LinkedIn for weeks with no response, he reached out to <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/158457\/duc-money-transfer-app-exposed-drivers-licenses-and-passports\/\" class=\"acp-article-link\" data-article-id=\"158457\" title=\"Duc Money Transfer App Exposed Driver&#039;s Licenses and Passports\" target=\"_blank\" rel=\"noopener noreferrer\">TechCrunch<\/a>. Even direct emails from the publication to Bluspark&#8217;s CEO and senior leadership went unanswered. It was only after a follow-up email that included a portion of the CEO&#8217;s own exposed password, demonstrating the lapse&#8217;s severity, that a response arrived, via the company&#8217;s legal counsel.<\/p>\n\n<p class=\"wp-block-paragraph\">The path to discovery began when Zveare examined a Bluspark client&#8217;s website. He noticed a contact form that communicated through Bluspark&#8217;s application programming interface (API). By investigating further, he accessed the API&#8217;s public documentation page, which essentially provided a blueprint of all possible commands. <strong>Despite claims that authentication was required, the API demanded no credentials whatsoever.<\/strong> Using this open access, Zveare retrieved extensive user records, including usernames and unencrypted passwords, one belonging to a platform administrator.<\/p>\n\n<p class=\"wp-block-paragraph\">Although he could have used these credentials, doing so would be illegal. Instead, he used an API command listed in the documentation to create a new user account with full administrative privileges. This granted him unrestricted entry into the Bluvoyix platform, where he could view customer data dating back to 2007. Further testing confirmed the API&#8217;s lack of proper authentication, as requests could be sent without the required user tokens.<\/p>\n\n<p class=\"wp-block-paragraph\">Following contact from its legal team, Zveare provided his full vulnerability report. Bluspark&#8217;s attorneys later confirmed that most flaws had been remediated and that the company was seeking a third-party security assessment. They expressed confidence in the mitigation steps taken but declined to comment on the specifics of the vulnerabilities, the assessment firm, or the company&#8217;s security practices. When questioned, Bluspark stated there was &#8220;no indication of customer impact or malicious activity&#8221; but did not elaborate on the evidence supporting that conclusion.<\/p>\n\n<p class=\"wp-block-paragraph\">The company&#8217;s attorney, Ming Lee, mentioned that Bluspark is planning to establish a formal <a href=\"https:\/\/digitrendz.blog\/z\/topic\/vulnerability-disclosure\/\" class=\"acp-topic-link\" data-topic-id=\"74269\" title=\"Explore: vulnerability disclosure\" target=\"_blank\" rel=\"noopener noreferrer\">vulnerability disclosure<\/a> program to facilitate future reports from external researchers, though those discussions are ongoing. The episode highlights a persistent challenge in cybersecurity: many organizations lack clear, public avenues for reporting critical security flaws, leaving researchers in a difficult position when trying to protect user data from ongoing risks.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <a href=\"https:\/\/techcrunch.com\/2026\/01\/14\/us-cargo-tech-company-publicly-exposed-its-shipping-systems-and-customer-data-to-the-web\/\" target=\"_blank\">TechCrunch<\/a>)<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Security experts warn that cyberattacks on logistics firms are enabling large-scale cargo theft, creating a dangerous alliance between hackers and organized crime that threatens global supply chains. A researcher discovered severe vulnerabilities in Bluspark Global&#8217;s shipping software, including &#8230;<\/p>\n","protected":false},"author":1,"featured_media":114253,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[3253,3297,3327,3254],"tags":[151194,18176,46803,97789,151195],"entities":[151198,151196,151197,109322,151199,151200,3481,3271,3672],"class_list":["post-114254","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-cybersecurity","category-newswire","category-technology","tag-api-security-flaw","tag-cybersecurity-breach","tag-data-exposure","tag-logistics-technology","tag-supply-chain-vulnerability","entity-bluspark","entity-bluspark-global","entity-bluvoyix","entity-eaton-zveare","entity-ken-o-brien","entity-maritime-hacking-village","entity-new-york","entity-techcrunch","entity-us"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/114254","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=114254"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/114254\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/114253"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=114254"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=114254"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=114254"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=114254"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}