Oil Tanker hit by ransomware attack near the Port of Naantali, Finland

Year

2019

Month

Reference number

20190003

Impact area

Vessel

Incident location

Naantali

Incident country

Finland

Victim country

Finland

Victim identity

Tanker near the Port of Naantali

Victim Type

Vessel

Method

Ransomware

Summary:

In 2019, a tanker near the port of Naantali in Finland was hit by a ransomware attack. As a result, its administration server was infected and the back up disk was wiped. Reportedly, the method of intrusion remains unclear but a Remote Desktop Protocol (RDP), a USB device or an email attachment are identified as probable attack vectors. The same vessel was infected again 4 months later near the same port. The threat actor and motives behind the attack remain a mystery.

Reference URL

https://www.transnav.eu/files/A%20Retrospective%20Analysis%20of%20Maritime%20Cyber%20Security%20Incidents,1144.pdf
https://www.mdpi.com/2673-8732/2/1/9/htm
https://www.bleepingcomputer.com/news/security/beware-of-spam-with-fake-invoices-pushing-hermes-2