Lonestar Truck Group & Tag Truck Center
Attack Intelligence
Lonestar Truck Group & Tag Truck Center was compromised in a ransomware attack attributed to interlock in May 2026. The organization, operating in the Transportation/Logistics sector in United States, was added to the group's data leak site as part of an extortion campaign.
interlock operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
https://www.tntxtruck.com Lonestar Truck Group consists of multiple dealerships that sell new and used trucks and trailers, as well as providing service and parts. They work with a vast number of customers and businesses, yet they have failed to prioritize security. As a result, personal data of employees, contact information for the companies they work with, and a significant number of customer records have been leaked online. We are also presenting their confidential and financial documents for your review.
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-20131, which may have been leveraged as initial access vectors or for lateral movement.