Year2025 |
MonthDecember |
Reference number20251221 |
Impact areaShore |
Incident locationVilleta, San Antonio |
Incident countryParaguay |
Victim countryParaguay |
Victim identityTERPORT S.A. |
Victim TypePort terminal operator |
MethodRansomware |
In December 2025, TERPORT S.A., a major river port terminal operator in Paraguay, was listed as a victim of the Lynx ransomware group. Terport operates the Parana-Paraguay Waterway's most sophisticated container terminal (TERPORT-VILLETA) and the TERPORT-SAN ANTONIO facility handling general cargo, RORO, and warehousing. The Lynx group exfiltrated and encrypted confidential business data including operational records, financial documents, and logistics data using double extortion tactics. As a critical node in South American waterway trade, the breach carries cascading supply chain risks for shipping companies, freight operators, and customs authorities dependent on the terminal's coordination systems.