Year2023 |
MonthJune |
Reference number20230607 |
Impact areaShore |
Incident locationBahrain |
Incident countryBahrain |
Victim countryBahrain |
Victim identityArab Shipbuilding and Repair Yard Company |
Victim TypeMaritime repair and fabrication facility |
MethodRansomware |
In June 2023, the Arab Shipbuilding and Repair Yard Company (ASRY) in Bahrain experienced a ransomware attack by the BianLian group. Founded in 1977, ASRY is a leading maritime repair and fabrication facility in the Arabian Gulf. The attackers exfiltrated 200GB of data, including client data, ship and vessel plans (including navy ships), personal data of crew members, business files, and accounting data. The stolen information was posted on BianLian's leak site on June 28, 2023. BianLian, known for targeting critical infrastructure sectors, uses valid Remote Desktop Protocol (RDP) credentials and open-source tools for reconnaissance and data extraction. Since January 2023, they have shifted focus from double-extortion to data exfiltration-based extortion. The incident was reported by RedPacket Security, which is not affiliated with any ransomware threat actors.