BianLian Ransomware Attack on Arab Shipbuilding and Repair Yard Company

Year

2023

Month

June

Reference number

20230607

Impact area

Shore

Incident location

Bahrain

Incident country

Bahrain

Victim country

Bahrain

Victim identity

Arab Shipbuilding and Repair Yard Company

Victim Type

Maritime repair and fabrication facility

Method

Ransomware

Summary:

In June 2023, the Arab Shipbuilding and Repair Yard Company (ASRY) in Bahrain experienced a ransomware attack by the BianLian group. Founded in 1977, ASRY is a leading maritime repair and fabrication facility in the Arabian Gulf. The attackers exfiltrated 200GB of data, including client data, ship and vessel plans (including navy ships), personal data of crew members, business files, and accounting data. The stolen information was posted on BianLian's leak site on June 28, 2023. BianLian, known for targeting critical infrastructure sectors, uses valid Remote Desktop Protocol (RDP) credentials and open-source tools for reconnaissance and data extraction. Since January 2023, they have shifted focus from double-extortion to data exfiltration-based extortion. The incident was reported by RedPacket Security, which is not affiliated with any ransomware threat actors.

Reference URL

https://ransomwareattacks.halcyon.ai/attacks/bianlian-attacks-arab-shipbuilding-and-repair-yard
https://www.redpacketsecurity.com/bianlian-ransomware-victim-arab-shipbuilding-and-repair-yard/
https://www.breachsense.io/breaches/arab-shipbuilding-repair-yard-data-breach/