Philippines Maritime Industry Authority (MARINA) Hacking Incident

Year

2024

Month

June

Reference number

20240601

Impact area

Shore

Incident location

Manila, Philippines

Incident country

Philippines

Victim country

Philippines

Victim identity

Maritime Industry Authority (MARINA)

Victim Type

Maritime industry authority

Method

Hacking

Summary:

In June 2024, a cyberattack by hacker "Ph1ns" breached the Philippine Maritime Industry Authority (MARINA), exposing critical maritime data, including ship specifications, ownership histories, and operational records. Exploiting vulnerabilities in subdomains, the attacker accessed 91 GB of data, exfiltrating 20 GB. Techniques included fuzzing and file upload manipulation to bypass security, escalating to full administrative control. The breach underscores the importance of strengthening cybersecurity in government systems to prevent data compromise and operational risks in critical infrastructure.

Reference URL

https://businessmirror.com.ph/2024/06/18/marinas-web-based-systems-compromised-in-cyber-attack/
https://kukublanph.data.blog/2024/06/16/cyber-attack-on-maritime-industry-authority-marina-exposes-critical-maritime-vessel-information/
https://www.pna.gov.ph/articles/1227068