Danish Maritime Authority hit by spear phishing attack

Year

2012

Month

April

Reference number

20120403

Impact area

Shore

Incident location

Korsør

Incident country

Denmark

Victim country

Denmark

Victim identity

Danish Maritime Authority

Victim Type

Coastguard

Method

Spear-phishing

Attacker country

China

Summary:

In April 2012, hackers from a foreign state made their way to the Danish Maritime Authority IT Systems in search of confidential information. The hacks targeted sensitive information on Danish shipping companies and the merchant navy. The hackers probably managed to gain access to the Danish Maritime Authority IT Systems by hiding a virus in a PDF document attached to an email sent to an employee of the Agency. When the employee opened the infected PDF file, hackers were given back-door access to the contents of his computer and the rest of the Maritime Authority’s network. They got access to an additional 13 PCs and a number of servers. From there, they were able to access the Business Ministry’s IT System. As a result of the hack, there was a disclosure of sensitive information. China is seen as the likely culprit, but the Chinese Embassy in Copenhagen denied that Chinese authorities had any knowledge of the hack.

Reference URL

https://backend.orbit.dtu.dk/ws/portalfiles/portal/156025857/Lagouvardou_MScThesis_FINAL.pdf
https://commons.wmu.se/cgi/viewcontent.cgi?article=1662&context=all_dissertations
http://maritimedenmark.dk/?Id=17968
https://www.thelocal.dk/20140922/denmark-was-hacked-by-state-sponsored-spies/