The NoName057(16) group, known for its pro-Russian stance, launched a cyberattack on Italy in February 2024. The attack targeted both government and private entities, including critical sectors like financial services and transport systems. Among the targeted systems was the Italian Navy’s website, which was temporarily disrupted. The group claimed responsibility for these DDoS attacks, further demonstrating the risks posed to national infrastructure by politically-motivated cybercriminals.
Feb, 2024LockBit, a notorious ransomware group, recently targeted Groupe IDEA , a French organization involved in logistics and industrial transportation, in February 2024. The attack paralyzed the company's operations by encrypting and stealing critical data. LockBit is known for its aggressive tactics, including using personalized malware like StealBit for automated data exfiltration. Despite facing internal issues, such as low pay rates, LockBit remains highly active, responsible for thousands of attacks globally. This attack is part of their ongoing financial-driven cybercrime activities.
Feb, 2024The LockBit ransomware group claimed an attack against Portline, a Portuguese company. LockBit is known for its aggressive tactics, including using personalized malware like StealBit for automated data exfiltration. This group primarily targets high-value organizations, demanding hefty ransoms in exchange for decrypting compromised data. As of February 2024, the attack paralyzed Portline's operations, highlighting the growing cybersecurity threat to the shipping industry. Despite the attack, no signs of data leaks were confirmed, and the company is working on restoring its systems and securing its infrastructure.
Feb, 2024In February 2024, LockBit 3.0 ransomware affected Northsea Yacht Support in the Netherlands, impacting luxury marine services.
Feb, 2024Semesco, a maritime company in Cyprus, became a target of LockBit 3.0 ransomware in February 2024, threatening its operational continuity.
Jan, 2024A DDoS attac has taken down the TankerTrackers online service, that tracks and report shipment of crude oil. This was timed to coincide with a simultaneous kinetic attack by the Houthis against the Marshall Island flagged, US-owned, Greek-operated tanker MV CHEM RANGER. If the information is valid, this is the first time a coordination of cyber and kinetic attacks has occured.
Jan, 2024In January 2024, Anonymous Sudan claimed responsibility for a Distributed Denial-of-Service (DDoS) attack targeting Israeli ports, including the Israel Ports Development & Assets Company and Haifa Port Company. The attack overwhelmed digital systems, causing temporary operational disruptions. This incident mirrors a similar event from November 2023, when Anonymous Sudan launched an attack on Israel’s critical infrastructure.
Dec, 2023In December 2023, a Ransomware as a Service provider called Hunters International has launched a ransomware attack on the US subsidiary of an Australian shipbuilder that has contracts to build vessels for the US Navy. According to reports, 43 files consisting of 87.2MB worth of data was taken. According to Austal no sensitive data regarding the US Navy was leaked.
Nov, 2023In November 2023, DP World who manages 40% of the maritime freight in Australia, reported that the company had suspended operation in its port terminals at Sydney, Melbourne, Brisbane, and Fremantle due to a cybersecurity incident. The company responded to the cyber threat by restricting access to its computer systems, practically disconnecting them from the net, leading to operational halt with reports of 30,000 shipping containers being stranded. Due to the extent of impact on the movement of goods to and from Australia, it is being handled as a nationally significant, according to the Australian federal government's Australian Cyber Security Coordinator. The company says data of current and former employees was compromised during the incident.
Nov, 2023In November 2023, the Bahamas-flagged cargo ship Galaxy Leader, partially owned by Israeli businessman Rami Unger, was hijacked by Yemen’s Houthi rebels in the Red Sea. Before the hijacking, the ship’s AIS (Automatic Identification System) was reportedly spoofed, broadcasting a false location off the coast of India while it was actually sailing through the Red Sea—an apparent effort to mask its real-time position. The vessel, leased from a British firm to a Japanese company, was traveling from Turkey to India when it was intercepted. The Houthis, backed by Iran, claimed responsibility, framing the act as retaliation for Israel’s military actions in Gaza and as a gesture of solidarity with Palestinians. While the ship sustained minor damage and no crew were physically harmed, 25 multinational crew members were taken hostage. The incident drew international condemnation and increased regional tensions, with both Japan and Israel demanding the crew’s immediate release.