In July 2024, BlackBerry reported that an India-aligned nation-state threat actor has been targeting ports and maritime facilities in the Indian Ocean and Mediterranean Sea. Using spear-phishing emails with malicious documents, the group exploited known vulnerabilities in Microsoft Office to implant malware. The attacks focused on espionage.
Jul, 2024In July 2024, TotalEnergies Clientes SAU, a subsidiary of the global energy company TotalEnergies, experienced a cyberattack that compromised the personal data of 210,715 customers. The breach involved unauthorized access to one of its sales management computer systems, exposing sensitive customer information. In response, the company has collaborated with law enforcement and the Spanish Data Protection Agency to address the incident and pursue legal action against those responsible.
Jul, 2024Carigali Hess Operating Company in Malaysia experienced a ransomware breach in July 2024, linked to the Hunters group and threatening oil assets.
Jul, 2024In July 2024, the Hunters ransomware group targeted Indika Energy in Indonesia, jeopardizing its energy supply chain.
Jul, 2024In July 2024, Heidmar Inc., a global leader in marine transportation services specializing in the commercial management of tanker pools based in Greece, has fallen victim to the Akira Ransomware. The group claims to have access to 20GB of organizational data, which includes personal files of employees, customer information, NDAs, confidential agreements, and agreements with international customers.
Jul, 2024A sanctions-busting "dark fleet" VLCC with documented AIS spoofing history collided with a legitimate Singapore-flagged tanker in the South China Sea on July 19, 2024. The Ceres I was broadcasting false "at anchor" status while moving and disabled its AIS immediately before the collision. The incident caused fires on both vessels, one fatality, multiple injuries, and a 17km² oil spill. After the collision, Ceres I fled with AIS disabled before being intercepted by Malaysian Coast Guard. This represents the most significant real-world safety incident directly attributable to dark fleet AIS manipulation practices.
Jun, 2024In June 2024, a cyberattack by hacker "Ph1ns" breached the Philippine Maritime Industry Authority (MARINA), exposing critical maritime data, including ship specifications, ownership histories, and operational records. Exploiting vulnerabilities in subdomains, the attacker accessed 91 GB of data, exfiltrating 20 GB. Techniques included fuzzing and file upload manipulation to bypass security, escalating to full administrative control. The breach underscores the importance of strengthening cybersecurity in government systems to prevent data compromise and operational risks in critical infrastructure.
Jun, 2024The ElDorado ransomware group targeted Tankerska Plovidba, a Croatian shipping company, exfiltrating 1.7TB of data. The June 2024 attack highlights the group's use of double-extortion tactics, where they encrypt and steal data, threatening to release it unless a ransom is paid. ElDorado is known for exploiting vulnerabilities like phishing and RDP misconfigurations, and has impacted multiple organizations since its emergence in 2024.
Jun, 2024Grendi Group, an Italian shipping and logistics company, reported a cyber-attack on June 12, 2024, involving a malicious email attachment. The attack was quickly contained without evidence of data breaches. The company isolated compromised systems and conducted a thorough security audit, ensuring no personal or business data was exposed. Grendi has since updated its security measures and urged continued vigilance in maintaining strong cybersecurity practices.
Jun, 2024In June 2024, a mass AIS spoofing event occurred, with nearly 50 ships showing their locations at Simferopol International Airport in Crimea, and approximately 30 at Gelendzhik Airport. This disruption in the Black Sea region caused vessels to display absurd speeds and locations, such as crude oil tankers moving at over 100 knots. The event likely correlates with ongoing electronic warfare in the area, though it represents a large-scale spoofing event, potentially linked to Russo-Ukrainian tensions. The spoofing disappeared by June 5, 2024.