Year2025 |
MonthNovember |
Reference number20251115 |
Impact areaShore |
Incident locationChornomorsk, Odesa region |
Incident countryUkraine |
Victim countryUkraine |
Victim identityStark Shipping LLC |
Victim TypeMaritime service provider (shipping agency) |
MethodRansomware |
In November 2025, Stark Shipping LLC, a Ukrainian maritime logistics and shipping agency operating in the Black Sea and Azov Sea ports, was listed as a victim of the Nova ransomware group. Threat-intelligence and data-breach trackers report that Nova exfiltrated and published roughly 226–275 GB of internal corporate data from Stark Shipping’s network, including operational shipping documents, port agency records, cargo manifests, client and vendor communications, financial documents and employee-related files. The incident is described as a data breach and ransomware attack using Nova’s typical double-extortion model, although open sources do not clearly confirm whether Stark’s systems were encrypted or services were interrupted. No detailed public incident-response statement from Stark Shipping has been identified so far. The case illustrates how criminal ransomware-as-a-service groups are increasingly targeting maritime support and logistics providers whose data covers multiple ports and trade partners, creating systemic exposure even when a single company is compromised.