Warlock ransomware data breach at Ferus Smit Shipyard (Netherlands)

Year

2025

Month

September

Reference number

20250917

Impact area

Shore

Incident location

Westerbroek, Groningen

Incident country

Netherlands

Victim country

Netherlands

Victim identity

Ferus Smit Shipyard B.V.

Victim Type

Shipyard / shipbuilding company

Method

Ransomware

Summary:

In September 2025, Dutch shipbuilder Ferus Smit Shipyard B.V. (ferus-smit.home) was listed as a victim of the Warlock ransomware group. BreachSense and ransomware.live recorded the case as a data breach discovered on 17 September 2025, with Warlock claiming "all data". Additional reporting by DeXpose and other threat-intel sources confirms that Warlock is an emerging ransomware group active in 2025, typically combining network intrusion with data exfiltration and extortion. Ferus Smit Shipyard, which operates shipyards in Westerbroek (NL) and Leer (DE), thus became one of several maritime-related industrial victims in Warlock’s 2025 campaign. No detailed public information is available about operational disruption at the yard, but the exposure of internal corporate data poses ongoing risks.

Reference URL

https://www.breachsense.com/breaches/ferus-smit-shipyard-data-breach/
https://www.dexpose.io/warlock-ransomware-attack-on-ferus-smit/
https://www.ransomware.live/id/ZmVydXMtc21pdC5ob21lQHdhcmxvY2s%3D
https://www.blackfog.com/ongoing-new-ransomware-gangs-in-2025/
https://www.trendmicro.com/en_us/research/25/h/warlock-ransomware.html