Year2019 |
MonthDecember |
Reference number20191202 |
Impact areaShore |
Incident location |
Incident countryUSA |
Victim countryUSA |
Victim identityMaritime Transportation Security Act (MTSA) regulated facility |
Victim TypeOther Government |
MethodRansomware |
In December 2019, Maritime Transportation Security Act (MTSA) regulated facility, based in the U.S., was hit by a ransomware (Ryuk) attack. As a result, company's operations shutdown for over 30 hours. USCG officials said they believe the point of entry was a malicious email sent to one of the maritime facility's employees. Once the link was clicked on by the employee, the company's IT servers got encrypted. The virus further burrowed into the industrial control systems that monitor and control cargo transfer and encrypted files critical to process operations. The impacts to the facility included a disruption of the entire corporate IT network (beyond the footprint of the facility), disruption of camera and physical access control systems, and loss of critical process control monitoring systems.