Year2018 |
MonthSeptember |
Reference number20180903 |
Impact areaShore |
Incident locationSan Diego CA |
Incident countryUSA |
Victim countryUSA |
Victim identityPort of San Diego |
Victim TypePort |
MethodRansomware |
Attacker countryIran |
In September 2018, a medium-sized cargo port got hit by a ransomware attack in San Diego. The criminals, two Iranian hackers, Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri, used a malware program called SamSam Ransomware, which is capable of encrypting data stored on a victim's Computer Systems. The attacker requested ransom in Bitcoin. The two men allegedly used a sophisticated approach to their attacks. They would research their targets online and scan for computer network vulnerabilities. When they struck, they would time the attack for night-time hours, when the victims would be least capable of mounting a defense, and would disguise their intrusions as normal network activity. They allegedly deployed an anonymized browsing and traffic routing service in an attempt to hide their tracks. No data loss occurred as a result of the attack, because the port's IT team had backups in place. The hack took down non-critical administrative systems for a brief period, and did not affect commercial port operations. The port did not pay the ransom demand.