Maritime Transportation Security Act regulated facility hit by ransomware attack in the USA

Year

2019

Month

December

Reference number

20191202

Impact area

Shore

Incident location

Incident country

USA

Victim country

USA

Victim identity

Maritime Transportation Security Act (MTSA) regulated facility

Victim Type

Other Government

Method

Ransomware

Summary:

In December 2019, Maritime Transportation Security Act (MTSA) regulated facility, based in the U.S., was hit by a ransomware (Ryuk) attack. As a result, company's operations shutdown for over 30 hours. USCG officials said they believe the point of entry was a malicious email sent to one of the maritime facility's employees. Once the link was clicked on by the employee, the company's IT servers got encrypted. The virus further burrowed into the industrial control systems that monitor and control cargo transfer and encrypted files critical to process operations. The impacts to the facility included a disruption of the entire corporate IT network (beyond the footprint of the facility), disruption of camera and physical access control systems, and loss of critical process control monitoring systems.

Reference URL

https://www.csoonline.com/article/3541810/ryuk-explained-targeted-devastatingly-effective-ransomware.html
https://www.cysiv.com/company/blog/ryuk-ransomware-2021-latest
https://www.bbc.com/news/technology-50972890
https://www.dco.uscg.mil/Portals/9/DCO%20Documents/5p/MSIB/2019/MSIB_10_19.pdf
https://www.zdnet.com/article/us-coast-guard-discloses-ryuk-ransomware-infection-at-maritime-facility/
https://www.infosecurity-magazine.com/news/us-coast-guard-sounds-alarm/