Terport S.A. port terminal operator hit by Lynx ransomware attack

Year

2025

Month

December

Reference number

20251221

Impact area

Shore

Incident location

Villeta, San Antonio

Incident country

Paraguay

Victim country

Paraguay

Victim identity

TERPORT S.A.

Victim Type

Port terminal operator

Method

Ransomware

Summary:

In December 2025, TERPORT S.A., a major river port terminal operator in Paraguay, was listed as a victim of the Lynx ransomware group. Terport operates the Parana-Paraguay Waterway's most sophisticated container terminal (TERPORT-VILLETA) and the TERPORT-SAN ANTONIO facility handling general cargo, RORO, and warehousing. The Lynx group exfiltrated and encrypted confidential business data including operational records, financial documents, and logistics data using double extortion tactics. As a critical node in South American waterway trade, the breach carries cascading supply chain risks for shipping companies, freight operators, and customs authorities dependent on the terminal's coordination systems.

Reference URL

https://dailydarkweb.net/terport-ransomware-attack-paraguay-port-operator-breached-by-lynx/
https://www.redpacketsecurity.com/lynx-ransomware-victim-terport-com-py/
https://www.hookphish.com/blog/ransomware-group-lynx-hits-terport-com-py/
https://botcrawl.com/terport-data-breach/