Dutch shipping giant Royal Dirkzwager hit by Ransomware Attack

Year

2023

Month

March

Reference number

20230301

Impact area

Shore, Offshore

Incident location

Maassluis

Incident country

Netherlands

Victim country

Netherlands

Victim identity

Royal Dirkzwager

Victim Type

maritime logistics company

Method

Ransomware

Summary:

In March 2023 Dutch maritime logistics company Royal Dirkzwager has confirmed that it was hit with ransomware from the Play group. The Play ransomware group added the company to its list of victims. The group first emerged in July 2022 targeting government entities in Latin America, according to Trend Micro, and most recently drew headlines for a damaging attack on the City of Oakland, which has spent weeks recovering from the incident. Company CEO Joan Blaas, who bought the Royal Dirkzwager in October 2022 after it went bankrupt the month prior, told The Record the ransomware attack did not have an effect on operations but did involve the theft of data from servers that held a range of contracts and personal information. In June 2025, it was reported that the attack occurred after hackers successfully brute-forced credentials for a system that had recently migrated from on-premise to the cloud. During this transition, critical security measures were overlooked, leaving the system vulnerable. Royal Dirkzwager also noted that they had a fallback system, an old DataDrik platform built in 1983, which allowed them to continue registering shipping traffic and communicating with customers by phone.

Reference URL

https://therecord.media/royal-dirkzwager-ransomware-attack-dutch-shipping
https://dirkzwager.com/news/cyber-security-update/
https://maritime-executive.com/article/ransomware-attack-hits-ship-tracking-firm-royal-dirkzwager
https://securityaffairs.com/143714/cyber-crime/play-ransomware-royal-dirkzwager.html
https://www.digitaltrustcenter.nl/ondernemersverhalen/gevaar-op-zee-na-hack-bij-maritieme-dienstverlener