List View

Jun, 2024

Island Transportation Corp. Affected by a BinLian Ransomware Campaign

In July 2024, the BianLian ransomware group launched an attack on Island Transportation Corp (ITC), a prominent fuel transportation company in the United States. ITC, responsible for distributing fuel across several regions, confirmed the attack, which reportedly exposed sensitive business and operational data. The breach is part of a broader campaign by BianLian targeting major U.S. companies. The ransomware group is known for exfiltrating data and threatening public exposure unless ransom demands are met. ITC has not disclosed the specifics of the compromised data or the ransom amount, but the incident raises significant concerns about the vulnerabilities of the critical fuel supply chain.

Jun, 2024

Ransomhouse Hits Singapore's Berge Bulk

Singapore’s Berge Bulk experienced a cyber incident in June 2024, after the Ransomhouse group infiltrated its vessel operations.

May, 2024

Ransomware Attack Against Nigerian Nestoil Group

In May 2024, Nigeria’s Nestoil Group was hit by the Blacksuit ransomware group, sparking concerns over disruptions to oil and infrastructure operations.

May, 2024

German Shipping Company Hit by Ragroup Ransomware

German shipping company Reederei Jüngerhans became a victim of Ragroup ransomware in May 2024, impacting its fleet operations.

May, 2024

Ransomhub Hits Brazilian Port Authority

In May 2024, the Port Administration for São Francisco do Sul in Brazil came under attack by Ransomhub ransomware, disrupting port functions.

May, 2024

North Korean GPS Jamming Campaign Affects Merchant Shipping in Yellow Sea

North Korea conducted sustained GPS jamming and spoofing operations against maritime traffic in the Yellow Sea, affecting approximately 60 documented merchant vessels over a week-long period in May-June 2024, with additional attacks in November 2024. Ships' AIS systems displayed false positions near or within North Korean territorial waters, creating navigation hazards for vessels approaching South Korean ports. South Korea's Joint Chiefs of Staff officially attributed the attacks to North Korean military installations in Haeju and Kaesong, filed complaints with three international agencies (ITU, ICAO, IMO), and warned of "serious incident" risks including vessel intrusions into hostile waters.

Apr, 2024

Atlantic Fisheries Commission Attack by 8Base Rasnomware

In April 2024, the Atlantic States Marine Fisheries Commission (ASMFC) confirmed a cyber incident following a breach claimed by the 8Base ransomware group. Attackers reportedly stole invoices and personal information, demanding ransom in exchange for not releasing the data. Due to the breach, the ASMFC's email system went down, prompting them to create temporary communication channels. 8Base, known for targeting smaller organizations, added the ASMFC to its growing list of victims, further highlighting the need for enhanced cybersecurity in government and maritime organizations.

Apr, 2024

Lyon Terminal Ransomware Attack

In April 2024, the 8Base ransomware group claimed responsibility for an attack on Lyon Terminal, a major multimodal transport platform in Lyon. The attackers exfiltrated invoices, personal information, and confidential documents before setting a 72-hour deadline for payment. Their demands were made through Bitcoin, and the group’s tactic of data theft combined with encryption is a growing trend in the ransomware landscape.

Apr, 2024

Coastal Cargo Data Breach

During April 2024, the Cactus ransomware group launched an attack on Coastal Cargo Group in New Orleans, significantly affecting port and freight services.

Apr, 2024

Snatch Attacks Dubai-Based Seven Seas

April 2024 saw Dubai’s Seven Seas Group fall victim to Snatch ransomware, potentially impairing marine catering and logistics.