In April 2024, Mellitah Oil & Gas / Enigas Ly in Libya faced a ransomware threat from Ransomhub, endangering oil production systems.
Apr, 2024In what GPS experts called an "unprecedented" event, 117 commercial vessels simultaneously appeared at Beirut's international airport on April 4, 2024, due to large-scale GPS spoofing traced to Israeli defensive operations. The spoofing, designed to confuse attack drones by making them believe they're near airports, had significant collateral impact on maritime navigation. Ships received false GPS coordinates hundreds of miles from their actual positions, compromising AIS-based collision avoidance systems and forcing captains to rely on manual navigation methods. This represents the largest documented GPS spoofing incident affecting commercial maritime traffic.
Apr, 2024On April 4, 2024, the websites of both the port authority of Santos (APS) and the Procon de Santos were targeted by a cyberattack. The attack caused their online portals to go offline.
Mar, 2024In March 2024, MarineMax, a leading retailer of recreational boats and yachts, was targeted by the Rhysida ransomware group. The breach was first announced on March 12th, and the group posted samples of the stolen data, which include earnings reports, balance sheets, bank account wire transfers, customer databases, and other financial documents. Rhysida is demanding 15 BTC (approximately $950,000 to $1.007 million) as ransom. The company disclosed the cyberattack to the SEC, noting disruptions in its business operations due to containment measures. Rhysida is auctioning the stolen data on its Tor-based website, offering it exclusively to the highest bidder if the ransom is not paid. MarineMax's clientele, likely high earners, could be significantly impacted if sensitive information is leaked. The ransomware group is known for targeting various sectors and often uses phishing attacks and Cobalt Strike tools to breach networks. Researchers developed a decryption tool for Rhysida's encryption method in February 2024, but it is unclear if it remains effective. The extent of data sensitivity in the MarineMax breach is also uncertain.
Mar, 2024In March 2024, Radiant Logistics, an international freight technology company, experienced a cyberattack that disrupted its Canadian operations. Detected on March 14, 2024, the attack prompted the company to isolate its Canadian network from global systems while initiating response measures. Cybersecurity experts were engaged to assess and remediate the incident. Although operations in Canada were temporarily affected, Radiant Logistics successfully mitigated the impact within a week, with no material consequences reported on its international operations. This is the second incident affecting the company after September 1, 2022, when Radiant Logistics disclosed a data breach to the Montana Attorney General after detecting unauthorized access to specific files within its network.
Mar, 2024In March of 2024, the NoName ransomware group claimed responsibility for targeting several Danish websites, including transport, airport, and shipping sectors, though no disruptions have been confirmed. The group cited dissatisfaction with Danish cybersecurity as their motive and accused specialists of failing to address ongoing threats. While investigations revealed no signs of compromise, the attacks raise concerns about Denmark’s readiness against persistent cyber threats.
Mar, 2024The Medusa ransomware group attacked ADSP Mar Tirreno Settentrionale, the port authority for Northern Tyrrhenian Sea in Italy, in March 2024. They leaked sensitive data such as internal documents and financial records. Medusa, known for its use of malicious email attachments and torrents to infiltrate systems, continued its campaign of targeting public sector organizations, demanding substantial ransoms for the safe return of stolen data.
Mar, 2024In March 2024, Incransom targeted UK-based Graypen Ltd, posing a risk to its tanker agency logistics and operational continuity.
Feb, 2024In February 2024, the US military conducted a cyberattack against an alleged 'Iranian spy ship' which had been operating near the Chinese military base in Djibouti. The ship, named the MV Behshad, had allegedly been collecting information on cargo vessels in the Red Sea and communicating the same to the Houthi rebels in Yemen. The operation was intended to inhibit the Iranian ship’s ability to share intelligence with Houthi rebels in Yemen who have been firing missiles and drones at cargo ships in the Red Sea, the officials said. The US officially has not disclosed much information about the cyberattack. Iran denies that the ship was being used for military purposes.
Feb, 2024In February 2024, Eastern Shipbuilding Group, Inc., a key contractor for the US Coast Guard's Offshore Patrol Cutter (OPC) fleet, suffered a cybersecurity breach by the LockBit ransomware group. This incident exacerbates existing challenges following a hurricane that had previously forced the company to rebuild its shipyard. The breach raises concerns about vulnerabilities in the defense industrial base and the effectiveness of the Cybersecurity Maturity Model Certification (CMMC) in protecting sensitive information. The attack poses significant risks to national security and the USCG's OPC program, potentially impacting the shipbuilding schedule and benefiting other shipyards like Bollinger Shipyards. Eastern Shipbuilding must now address the cybersecurity threat and restore trust with stakeholders.