When a regional petroleum transporter lands on a ransomware leak-site tracker, industrial and logistics SMBs feel the same pressure—dispatch systems, ERP, fleet records, and the vendor VPNs that keep loads moving. Public aggregators indexed Crossett (domain www.crossettinc.com / crossettinc.com) as a claimed victim of the Termite ransomware group around September 26, 2026.
Ransomware.live lists discovery around 2026-09-26 00:43 UTC, activity Other, country US, with victim name “Crossett.” The tracker description identifies Crossett Home as a petroleum transporter operating across major Eastern U.S. markets and Ontario, Canada—established 1928, specializing in fuel transportation, with a fleet described as over 100 modern tractors and 210 trailers. The live company site at crossettinc.com (www redirects here) presents Crossett Inc. as that petroleum transporter. As of our sources, we have no confirmed company disclosure of encryption scope, stolen dispatch or customer files, terminal downtime, or ransom payment—so we treat the Termite listing as a leak-site / tracker claim only.
For industrial SMBs, fuel and bulk haulers, logistics shops, and Brotherly’s production/exhibit-adjacent partners that depend on reliable freight across Georgia, Tennessee, Alabama, and New York, the useful lesson is dispatch/ERP continuity plus vendor VPN hygiene—not inventing a confirmed breach the named company has not published.
What trackers report—and what they do not
Public facts from aggregators: Crossett; www.crossettinc.com; claimed by Termite; discovery ~Sept. 26, 2026; US; petroleum transporter / Eastern US + Ontario context. Aggregators republish the actor listing; they do not equal a verified inventory of dispatch databases, ERP customer data, ELD/fleet systems, or terminal OT. We do not have a company-confirmed encryption event, data inventory, yard or office downtime, ransom demand, or payment. Do not invent those details from silence.
Fuel haulers and industrial logistics SMBs share a familiar pattern with the manufacturers and fab shops that buy freight from them: office Microsoft 365 or Google Workspace next to dispatch/ERP PCs, shared drives of load and customer records, and vendor remote access for telematics or support that becomes painful the moment a headline hits the inbox.
Why industrial and logistics SMBs should treat this as their drill
Delivery windows and install schedules do not pause for a tracker post. Organizations that lean on password-only email, untested dispatch/ERP backups, and flat vendor VPN access inherit the headline as scam and continuity risk—even when your yard or shop is in Northwest Georgia, metro Atlanta, Chattanooga, Birmingham, or Wallkill.
Post-headline phishing is predictable: spoofed “broker,” “shipper,” “fuel supplier,” or “vendor IT” messages referencing Termite or Crossett. Assume attackers will recycle the story against petroleum transporters, bulk haulers, electrical distributors, lighting reps, and exhibit/production shops that share logistics vendors. Ask: if email or dispatch were degraded for a week, how would you still move loads and spot fake recovery calls?
Clear takeaway
Treat the Termite leak-site claim against Crossett as a continuity and scam-hygiene drill for industrial and logistics SMBs—and Brotherly production/exhibit-adjacent shops that depend on them—require MFA on email and VPN, protect dispatch, ERP, and fleet backups with immutable copies and a restore test, inventory vendor remote access, segment OT/yard systems from office identity where practical, and brief staff against post-headline phishing—without inventing encryption, stolen files, downtime, or payment the company has not confirmed.
Actions to take this week
- Require MFA on email (Microsoft 365 / Google Workspace), VPN, admin portals, and shared dispatch or “ops” accounts—password-only access remains the cheapest path onto a lean logistics network.
- Verify immutable backups of dispatch/ERP data, fleet and compliance records, customer load files, and shared project drives—and run a restore test this month.
- Inventory vendor remote access (telematics, ELD, ERP support, managed IT): unique accounts, MFA, time-bounded sessions, and a revoke path.
- Segment yard/OT and shop-floor systems from office identity where practical—a compromised purchasing mailbox should not equal full access to dispatch servers or terminal controllers.
- Brief staff on post-headline phishing: unexpected links about “the Termite claim,” secrecy demands, or urgent wire requests are red flags; verify via a known phone number, not the email thread.
Brotherly Technology helps industrial SMBs, logistics and transportation partners, electrical and cable suppliers, commercial lighting agencies, AV integrators, and exhibit/experiential fabrication shops across Rome, Northwest Georgia, metro Atlanta, and our TN/AL/NY footprint turn industry cyber headlines into a short continuity review—without inventing threat details a named company has not confirmed. The Termite claim against Crossett, as indexed by ransomware.live, is a timely reminder to run that drill now.
Sources:
- Ransomware.live — Crossett / Termite — Discovery ~2026-09-26 00:43 UTC; US; domain www.crossettinc.com; petroleum transporter context in actor description; claim-level listing.
- Crossett Inc. (crossettinc.com) — Company context: petroleum transporter, Eastern U.S. and Ontario; www.crossettinc.com redirects here; no incident acknowledgment cited here.