A.P. Møller Maersk: Pipapav, ICD Dadri, CFS Nhava Sheva hit by NonPetya Wiper virus in Ukraine

Year

2017

Month

June

Reference number

20170603

Impact area

Shore

Incident location

Incident country

Ukraine

Victim country

Ukraine

Victim identity

A.P. Møller Maersk: Pipapav, ICD Dadri, CFS Nhava Sheva

Victim Type

Shipping Company

Method

Malware

Attacker country

Russia

Summary:

In June 2017, shipping giant A.P. Møller Maersk got hit by a malware attack. During this incident a Wiper Virus (NotPetya) infected servers all across the globe. In total 65 countries have been infected. A vendor software update was the vehicle that carried the devastating NotPetya malware virus into Maersk's IT servers . The cyber attack can be traced to software updates from the Ukrainian accounting program M.E.Doc. Investigators from the security firm Talos travel to Ukraine to assist M.E.Doc in analysing their systems and to find out how the company has penetrated. It gradually appears that hackers become ingeniously managed to gain access for months to the systems of Intellect Service, the parent company of M.E.Doc. This is a software developer of, among other things, the accounting system M.E.Doc, which is frequently used to exchange with the Ukrainian tax authorities. By hiding the malware in the software update process, NotPetya went undetected into the networks of companies that used this software. Updates have been released with a backdoor, a hacker-made change to the M.E.Doc software, which allowed them to distribute NotPetya to customers of this software vendor. The impact was immense. In total there were 17 shipping container terminals affected in Ukraine, Russia, Germany, United States, United Kingdom, France, Denmark and The Netherlands. Maersk suffered $250 – 300 million financial loss and data contamination, delayed container deliveries and traffic jams in and around ports. About 4.000 servers, 45.000 computers and 2.500 applications had to be rebuild by Maersk. In the meantime, paper documents were glued on containers and orders were taken through personal G-mail accounts, WhatsApp and Excel files. The Russian Sandworm Team, also known as Unit74455 was behind this attack and the campaign was to disrupt Computer Systems across Ukraine. A.P. Møller Maersk along with other companies are collateral damage from this attack.

Reference URL

https://www.rtlnieuws.nl/geld-en-werk/artikel/1860486/cyberaanval-kost-maersk-255-miljoen-euro

https://www.reuters.com/article/us-cyber-attack-maersk-idUSKBN19I1NO
https://commons.wmu.se/cgi/viewcontent.cgi?article=1662&context=all_dissertations
https://www.maritime-executive.com/article/cyberattack-hits-multiple-greek-shipping-firms
https://insurancemarinenews.com/insurance-marine-news/maersk-line-gradually-returning-normality-cyber-attack/
https://insurancemarinenews.com/insurance-marine-news/maersk-gets-cyber-attack-control-operators-hit/
https://www.ifv.nl/kennisplein/Documents/20201202-IFV-Cybergevolgbestrijding.pdf
https://www.ifv.nl/kennisplein/Documents/2018-IFV-H6-Cyberaanval-op-Maersk.pdf
https://nos.nl/artikel/2180375-miljoenenschade-door-virus-containerterminals-blijven-dicht
https://www.dutchnews.nl/news/2017/06/smart-port-in-rotterdam-confounded-by-cyber-attack/
https://www.stormshield.com/news/cybermaretique-a-short-history-of-cyberattacks-against-ports/
https://www.forbes.com/sites/leemathews/2017/08/16/notpetya-ransomware-attack-cost-shipping-giant-maersk-over-200-million/
https://threatspan.com/2017/12/29/top-11-maritime-security-compromises-of-all-time/