Forward Air Corp
bd_69daca6e5bc59daa · schema v1 · pii pii-v1
Full breach record for Forward Air Corp →3 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Hades on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Dec 15, 2020
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Illinois State AGbd_bb0159aed9dd5ed62021-01-01 · +17dVerified by operator
- New Hampshire State AGbd_a3124749f0e44aa02020-11-16 · +29dVerified
- Maine State AGbd_08f5bdd8be02662b2020-11-11 · +34dCandidate
- Maine State AGbd_4e519c8e4352ad1e2021-09-24 · +283dVerified
Show 6 more filings ↓Show fewer ↑up to 287d gap
- Montana State AGbd_9366040c480f58172021-09-24 · +283dVerified
- Massachusetts State AGbd_942507cd1a8b43cc2021-09-24 · +283dVerified
- Maine State AGbd_9f6be7535a79c40c2021-09-24 · +283dVerified
- California State AGbd_b222ea320c8293ed2021-09-24 · +283dVerified
- Indiana State AGbd_f364a48b4e1da9442021-09-24 · +283dVerified
- New Hampshire State AGbd_4b984181509b96682021-09-28 · +287dVerified
Showing first 10 of 13 linked disclosures.
Filing propagation · 11 filings · 7 states
View merged incident ↗Pattern: first filing Nov 11 (ME), last Sep 28 (NH) — a 321-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 13 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
hades
According to ransomware.live, According to PCrisk, Hades Locker is an updated version of WildFire Locker ransomware that infiltrates systems and encrypts a variety of data types using AES encryption. Hades Locker appends the names of encrypted files with the .~HL[5_random_characters] (first 5 characters of encryption password) extension.