In July 2024, the BianLian ransomware group launched an attack on Island Transportation Corp (ITC), a prominent fuel transportation company in the United States. ITC, responsible for distributing fuel across several regions, confirmed the attack, which reportedly exposed sensitive business and operational data. The breach is part of a broader campaign by BianLian targeting major U.S. companies. The ransomware group is known for exfiltrating data and threatening public exposure unless ransom demands are met. ITC has not disclosed the specifics of the compromised data or the ransom amount, but the incident raises significant concerns about the vulnerabilities of the critical fuel supply chain.
Jun, 2024Singapore’s Berge Bulk experienced a cyber incident in June 2024, after the Ransomhouse group infiltrated its vessel operations.
May, 2024In May 2024, Nigeria’s Nestoil Group was hit by the Blacksuit ransomware group, sparking concerns over disruptions to oil and infrastructure operations.
May, 2024German shipping company Reederei Jüngerhans became a victim of Ragroup ransomware in May 2024, impacting its fleet operations.
May, 2024In May 2024, the Port Administration for São Francisco do Sul in Brazil came under attack by Ransomhub ransomware, disrupting port functions.
May, 2024North Korea conducted sustained GPS jamming and spoofing operations against maritime traffic in the Yellow Sea, affecting approximately 60 documented merchant vessels over a week-long period in May-June 2024, with additional attacks in November 2024. Ships' AIS systems displayed false positions near or within North Korean territorial waters, creating navigation hazards for vessels approaching South Korean ports. South Korea's Joint Chiefs of Staff officially attributed the attacks to North Korean military installations in Haeju and Kaesong, filed complaints with three international agencies (ITU, ICAO, IMO), and warned of "serious incident" risks including vessel intrusions into hostile waters.
Apr, 2024In April 2024, the Atlantic States Marine Fisheries Commission (ASMFC) confirmed a cyber incident following a breach claimed by the 8Base ransomware group. Attackers reportedly stole invoices and personal information, demanding ransom in exchange for not releasing the data. Due to the breach, the ASMFC's email system went down, prompting them to create temporary communication channels. 8Base, known for targeting smaller organizations, added the ASMFC to its growing list of victims, further highlighting the need for enhanced cybersecurity in government and maritime organizations.
Apr, 2024In April 2024, the 8Base ransomware group claimed responsibility for an attack on Lyon Terminal, a major multimodal transport platform in Lyon. The attackers exfiltrated invoices, personal information, and confidential documents before setting a 72-hour deadline for payment. Their demands were made through Bitcoin, and the group’s tactic of data theft combined with encryption is a growing trend in the ransomware landscape.
Apr, 2024During April 2024, the Cactus ransomware group launched an attack on Coastal Cargo Group in New Orleans, significantly affecting port and freight services.
Apr, 2024April 2024 saw Dubai’s Seven Seas Group fall victim to Snatch ransomware, potentially impairing marine catering and logistics.