Port of Barcelona hit by ransomware attack

Year

2018

Month

September

Reference number

20180901

Impact area

Shore

Incident location

Barcelona

Incident country

Spain

Victim country

Spain

Victim identity

Port of Barcelona

Victim Type

Port

Method

Ransomware

Summary:

On September 20, the port of Barcelona got hit by a Ryuk ransomware attack. The attackers use manual hacking techniques and open-source tools to move laterally through private networks and gain administrative access to as many systems as possible before initiating the file encryption. Once deployed, Ryuk encrypts all files except for those with the extensions dll, lnk, hrmlog, ini and exe. It also skips files stored in the Windows System32, Chrome, Mozilla, Internet Explorer and Recycle Bin directories. Ryuk uses strong file encryption based on AES-256. The attack only affected internal IT Systems, and did not affect any shipping movements in and out of the harbour.

Reference URL

https://www.zdnet.com/article/port-of-san-diego-suffers-cyber-attack-second-port-in-a-week-after-barcelona/
https://www.zdnet.com/article/us-coast-guard-discloses-ryuk-ransomware-infection-at-maritime-facility/
https://insurancemarinenews.com/insurance-marine-news/cyber-attacks-in-san-diego-barcelona/
https://www.csoonline.com/article/3541810/ryuk-explained-targeted-devastatingly-effective-ransomware.html
https://www.cysiv.com/company/blog/ryuk-ransomware-2021-latest
https://safety4sea.com/cm-2018-highlights-major-cyber-attacks-reported-in-maritime-industry
https://www.stormshield.com/news/cybermaretique-a-short-history-of-cyberattacks-against-ports/