Year2012 |
MonthApril |
Reference number20120403 |
Impact areaShore |
Incident locationKorsør |
Incident countryDenmark |
Victim countryDenmark |
Victim identityDanish Maritime Authority |
Victim TypeCoastguard |
MethodSpear-phishing |
Attacker countryChina |
In April 2012, hackers from a foreign state made their way to the Danish Maritime Authority IT Systems in search of confidential information. The hacks targeted sensitive information on Danish shipping companies and the merchant navy. The hackers probably managed to gain access to the Danish Maritime Authority IT Systems by hiding a virus in a PDF document attached to an email sent to an employee of the Agency. When the employee opened the infected PDF file, hackers were given back-door access to the contents of his computer and the rest of the Maritime Authority’s network. They got access to an additional 13 PCs and a number of servers. From there, they were able to access the Business Ministry’s IT System. As a result of the hack, there was a disclosure of sensitive information. China is seen as the likely culprit, but the Chinese Embassy in Copenhagen denied that Chinese authorities had any knowledge of the hack.