The Attack Surface Nobody Maps
A mid-sized UK logistics or courier operation has a sprawling digital footprint that most cybersecurity conversations ignore entirely. There is the customer-facing website with order tracking and quote forms. There is the fleet management portal — often a third-party SaaS platform — where routes, driver locations, and load manifests live. There are the driver apps on personal or company-owned mobile devices. There is the integration layer connecting the TMS (Transport Management System) to customer portals, accounting software, and potentially to clients' own ERPs.
Each of these is an attack surface. Each has its own authentication model, its own data stores, and its own exposure to the internet. A penetration test that only looks at the public website is missing most of the picture.
Why UK Logistics Is a High-Value Target
**Cargo theft intelligence** — before a physical cargo theft, organised crime groups increasingly use cyberattacks to gather logistics intelligence. Manifest data, route timing, drop-off locations, and driver schedules are all valuable. A compromised TMS or fleet portal gives attackers the information needed to intercept high-value loads. The UK's National Vehicle Crime Intelligence Service (NaVCIS) has noted the correlation between cyber intrusions and subsequent cargo theft events in several cases.
**Ransomware for operational leverage** — logistics operations are time-critical. A ransomware attack that takes down your TMS, route planning software, or driver communication system during peak season (Black Friday, Christmas, Q4) creates enormous pressure to pay quickly. Attackers know this and time attacks accordingly. The 2023 attack on logistics firm Yodel disrupted UK parcel deliveries for weeks.
**Business email compromise targeting finance** — logistics companies issue large numbers of invoices and process supplier payments at volume. The finance teams at larger 3PLs are regular BEC targets — attackers compromise or spoof a senior email account and redirect supplier payment details, or impersonate a client requesting an urgent payment. UK Finance reported that logistics and freight was among the top sectors for APP (Authorised Push Payment) fraud in 2024.
**Client data in the tracking portal** — if your customer tracking system stores delivery addresses, contact names, and potentially business addresses for B2B clients, you hold personal data on thousands of individuals. A breach creates UK GDPR exposure and ICO notification obligations.
What a Pen Test Should Cover
**Customer-facing systems**: the website, quote tools, online booking, and the customer tracking portal. Standard OWASP Top 10 testing applies here — injection vulnerabilities, authentication weaknesses, IDOR (can a customer view another customer's order by manipulating an ID in the URL?), session management.
**Driver and operations portals**: these are frequently treated as internal systems and receive less security scrutiny, but they are often internet-accessible (drivers need to log in from the road) and hold sensitive operational data. Authentication strength, MFA enforcement, and session timeout policies are the first things to check.
**API security**: logistics platforms are heavily API-driven — TMS integrations, carrier APIs, client portals. APIs often have weaker authentication than web front-ends and are less well tested. Unauthenticated endpoints, overly permissive scopes, and missing rate limiting are common findings.
**TMS and fleet management platform access**: if your TMS is a SaaS platform (Mandata, Paragon, Descartes, Microlise), a pen test of your own systems will not cover the platform itself, but it can assess how your credentials are stored, whether MFA is enforced, and whether the integration between your systems and the platform leaks sensitive data.
**Email infrastructure**: DMARC, DKIM, and SPF configuration. If your domain lacks DMARC enforcement, anyone can send emails that appear to come from your operations team — a significant BEC risk.
The IDOR Problem in Tracking Portals
Insecure Direct Object Reference (IDOR) is disproportionately common in logistics tracking systems. The pattern: a customer gets a tracking link like `yourcompany.co.uk/track?order_id=10472`. If the application does not verify that the requesting user is authorised to view order 10472, incrementing that number (10473, 10474...) lets any user view any order.
In a logistics context, this leaks delivery addresses, recipient names, and business locations for every order in the system. For a company with B2B clients, that is potentially commercially sensitive data about client supply chains.
This is not a theoretical vulnerability — it appears in pen test reports across the logistics sector regularly, usually because tracking portals were built quickly without authorisation checks being a design consideration.
GDPR and the ICO's View on Logistics Data
The ICO has published enforcement notices against logistics and delivery companies for inadequate data security. The specific issues that attract attention: unencrypted transmission of delivery data, excessive retention of historical delivery addresses, and lack of data processing agreements with sub-contractors and last-mile delivery partners.
If you use sub-contractors or owner-operators who access your TMS or receive route data, those are data processors under UK GDPR. You need Data Processing Agreements (DPAs) in place with each of them. This is commonly overlooked in the logistics sector, where subcontracting is structural.
Two Specific Actions for UK Logistics Businesses
**Enforce MFA on your TMS and fleet management portals.** Driver and operations staff credentials are a prime target. If a driver's phone is compromised or their credentials are in a breach database, an attacker with access to your fleet portal can see live vehicle locations, driver schedules, and load manifests. MFA on these portals is straightforward to implement and dramatically reduces the value of stolen credentials.
**Audit your tracking portal for IDOR.** Ask your development team or a security tester to systematically check whether authenticated customers can access other customers' order data by manipulating order IDs, tracking numbers, or reference parameters. If they can, that is a reportable data breach waiting to happen.
Yrzo AI's automated scan tests your customer-facing website and tracking portal for the vulnerability classes most common in logistics systems — IDOR, authentication weaknesses, injection flaws, and missing security headers. Scans from £99 at yrzoai.dev.
Find out if your website has these vulnerabilities
Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.
Scan your website →