Swire Pacific Offshore hit by a ransomware attack in Singapore

Year

2021

Month

November

Reference number

20211101

Impact area

Shore

Incident location

Singapore

Incident country

Singapore

Victim country

Singapore

Victim identity

Swire Pacific Offshore

Victim Type

Offshore Marine Service Provider

Method

Ransomware

Attacker country

Russia

Summary:

An interesting ransomware attack occurred on the 25th of November in 2021 at the trusted marine services provider (SPO). The IT Systems were infected with a variant of the CLOP ransomware caused by the Russian group called CLOP Gang. The group has claimed credit for the cyberattack and has released screenshots of the stolen data. They used the CLOP ransomware, which is a virus that bypasses protection to encrypt files that aren't protected. ‘’It is part of the well-known Crypto mix ransomware family, which is a harmful file-encrypting virus that intentionally avoids security-vulnerable systems and encrypts stored data by planting the CLOP extension’'. The stolen data included full names, company name, locations, phone numbers, email addresses, bank details, and passport scans. Employees in Singapore and Malaysia appear to be the most impacted, however some records belong to employees in China, the Philippines, and the United Kingdom. The total number of people who were exposed is 2,500, which corresponds to the company's seafaring and onshore workforce in 18 countries. The incident had no significant impact on SPO's global operations. It remains not exactly clear what the purpose of this attack was. The provider has taken quick efforts to strengthen current security measures and limit the incident's potential effect. SPO is also collaborating with data security specialists to investigate the attack and identify what additional actions may be required, and it will take all necessary efforts to secure its customers and employees now and in the future.

Reference URL

https://www.itpro.co.uk/security/hacking/361658/cl0p-hacking-group-hits-global-conglomerate-swire-pacific-offshore

https://www.hellenicshippingnews.com/swire-pacific-offshore-notice-of-cyber-security-incident/
https://thecybersecurity.news/general-cyber-security-news/cl0p-hacking-group-hits-swire-pacific-offshore-14820/
https://www.seatrade-maritime.com/technology/swire-pacific-offshore-hit-cyberattack
https://www.bleepingcomputer.com/news/security/marine-services-provider-swire-pacific-offshore-hit-by-ransomware/
https://portswigger.net/daily-swig/maritime-giant-swire-pacific-offshore-suffers-data-breach-following-cyber-attack
https://insurancemarinenews.com/insurance-marine-news/ransomware-attack-on-swire-pacific-offshore-personnel-data-leaked/