Year2022 |
MonthJanuary |
Reference number20220101 |
Impact areaShore |
Incident locationHamburg |
Incident countryGermany |
Victim countryGermany |
Victim identityMabanaft GmbH, GmbH Group Oil tanking |
Victim TypeOil Company |
MethodRansomware |
Attacker countryRussia |
This maritime incident involving a form of ransomware started in Germany on the 29th of January in 2022. The two companies that were hit by the attack were Mabanaft GmbH and the Oil tanking GmbH Group, which share a parent company. The cyber criminals operated with a ransomware-as-a-service (RaaS) business model. The attackers were a group of Russians who previously referred to themselves as ‘’The Darkside Group’’ and therefore ‘’Blackmatter’’. Now the group is called the ‘’Black Cat’’ and they move around networks very quickly. Because of the actions of these cyber criminals, part of Germany's fuel delivery system was knocked out for a few days, and payments at certain filling stations were halted. It was clear that the aim of the attack was financial gain, but the amount of money that was requested by the group is . For most of its inland supply activity in Germany, Mabanaft has declared force majeure. Around 233 petrol stations were disturbed, most of them in northern Germany. They had to reroute to various supply depots because of the attack. No Oil Tanking operations outside of Germany were harmed. A consequence of this was that facility workers are having to do the job manually. The company immediately took steps to improve the security of the systems and processes. They initiated an investigation towards the incident with the help of experts. They’re also working closely with the appropriate authorities. In a company statement they said that they tried to resolve the issue in accordance with the contingency procedures, as well as to fully comprehend the incident's scale.