Skip to content

Pattons Shipping Records Published Free With Goods Values and Delivery Details

Breach Report Australia Freight and Logistics Published Free

Pattons Shipping Records Published Free With Goods Values and Delivery Details

A forum actor posting as Keishell, crediting two others, has published what they describe as the myTnT shipment database belonging to pattons.com.au, an Australian business. The data is the company's carrier portal records rather than anything belonging to the carrier itself. The field list runs to more than twenty five items, covering shipping account numbers, booking and tracking references, sender and recipient names, companies, emails, phones and full postal addresses, tax identifiers, goods descriptions and declared values, weights, shipment dates, delivery status, pricing, payment terms and invoice numbers, customs data, Incoterms and dangerous goods codes. A spreadsheet is offered as proof of access. No record count is given. The claim is unverified.

RecordsNot stated
Field types25+
DistributionFree
ActorKeishell

Post details

Targetpattons.com.au
CountryAustralia
SectorFreight and logistics
ListingFree download
VolumeNot stated
Stated sourceCarrier portal account
Observed
ActorKeishell

!What the post claims

  • Shipping account numbers
  • Booking and shipment numbers
  • Tracking information
  • Full names
  • Company names
  • Email addresses
  • Phone numbers
  • Full postal addresses
  • VAT and tax identifiers
  • Goods descriptions
  • Declared goods values
  • Package weights and volumes
  • Shipment dates
  • Delivery status
  • Pricing and billing data
  • Payment terms
  • Invoice numbers
  • Customs information
  • Incoterms
  • Dangerous goods codes
  • Return shipment details
  • Collection and delivery instructions

Screenshots

Forum post publishing Pattons shipment records, observed 31 August 2026.

Mapped techniques

The post describes no intrusion method. All entries are inferred from the artefacts, not stated.

  • Initial access T1078 Valid accounts Inferred The data is scoped to one customer's shipping account rather than to the carrier as a whole, which points to access to that account rather than to the platform behind it.
  • Collection T1213 Data from information repositories Inferred The proof image is a filtered spreadsheet view with column headers intact, consistent with an export function used at scale rather than records copied by hand.
  • Exfiltration T1567 Exfiltration over web service Inferred Distribution runs through a public file host linked from the post. The route out of the environment is not described.

Potential impact

Shipment records answer what is being moved, what it is worth, where it is collected and on what date, which is the working brief for cargo theft, and the dangerous goods codes narrow that further to consignments worth intercepting. The billing side is the second problem: invoice numbers, payment terms and pricing for named counterparties are precisely what makes a fraudulent payment redirection convincing to an accounts department. Because a freight account records both ends of every movement, the exposure reaches the company's customers and suppliers, none of whom had any relationship with the portal.

iStatus Unverified

The proof image is more useful than most, showing an export with column headers, filter controls and the repetitive internal detail that real operational data carries. What it does not show is scale, since no record count appears anywhere, nor how the account was reached. Worth stating plainly for anyone reporting this: the records belong to one company's carrier account, and nothing here indicates a compromise of the carrier. Dark Web Informer has not retrieved the file and is not linking it, and the company has not publicly addressed the claim.

Dark Web Informer // Threat Intelligence

Latest