In November 2023, BR Logistics USA, a worldwide shipping company based in Kearny, New Jersey, was targeted by a ransomware attack from the LockBit 3.0 group. The attackers encrypted the company's systems and demanded a ransom to be paid by November 18, 2023. LockBit 3.0, known for its fast encryption speed and multiple extortion tactics, has been active since 2019 and continues to innovate its ransomware-as-a-service (RaaS) platform. The attack is part of a broader trend of increasing LockBit 3.0 ransomware incidents globally, affecting various organizations including Fawry, Amber Hill Group, and the Industrial and Commercial Bank of China. The FBI, CISA, and MS-ISAC have issued a joint advisory detailing the indicators of compromise and recommended mitigations to protect against such threats. The advisory emphasizes the importance of regular data backups, software updates, endpoint security solutions, and limiting user privileges to mitigate the impact of ransomware attacks.
Nov, 2023On November 9, 2023, Simons Petroleum, Maxum Petroleum, and Pilot Thomas Logistics in the USA fell victim to an Akira ransomware attack. The attackers claimed to have obtained about 70GB of data, including operating files, confidential documents, personal information of employees, and NDAs. The information was scraped from the Akira Onion Dark Web Tor Blog page and posted on RedPacket Security's blog. RedPacket Security clarified that they are not affiliated with the attackers and do not host any infringing content.
Nov, 2023In November 2023, Magsaysay Maritime Corporation (MMC) and Magsaysay Global Services, Inc. (MGSI) in the Philippines potentially suffered data breaches due to ransomware attacks by the Monti ransomware group. MMC discovered the breach on November 14, 2023, which may have resulted in the unauthorized acquisition of approximately one terabyte of data, including over 70,000 passports and other sensitive personal information. MGSI experienced a similar breach on November 17, 2023, with a hacker claiming to have downloaded approximately one terabyte of data, including an MMIS database dump. Both organizations are conducting forensic investigations to confirm the extent of the breaches and have implemented several measures to mitigate potential harm, such as resetting passwords, monitoring systems, and coordinating with government agencies. Affected individuals are advised to take precautions to protect their personal information.
Nov, 2023In November 2023, Maldives Ports Limited, the sole port authority of the Maldives, experienced a data breach. The breach was carried out by the Snatch ransomware group. The size of the data leak is currently unknown.
Oct, 2023In October 2023 Corsica Ferries, a ferry company, fell victim to a cyberattack by the ALPHV group, resulting in the theft of 101 GB of confidential data at the end of October. The hackers, known for ransomware attacks, made the stolen information available on the dark web after the company refused to cooperate with their demands. While the exact contents of the stolen data remain undisclosed, it reportedly includes banking information, personal data, and internal documents such as ship drawings. Despite the attack, Corsica Ferries resumed operations after a brief interruption of its servers.
Oct, 2023In October 2023, PT Pelabuhan Indonesia (Persero), trading as Pelindo, an Indonesian state-owned port operation company, experienced a data breach attributed to the BianLian ransomware group. The breach resulted in the exfiltration of 200GB of data, including SQL and ORACLE databases, source code APIs, internal technical documentation, and development information for ICT solutions. The BianLian group, which has shifted its focus from encrypting files to solely exfiltrating data for extortion, has breached multiple high-profile organizations since its appearance in July 2022. Despite Avast releasing a free decryptor in January 2023, BianLian continues to operate, listing 118 victim organizations on its extortion portal, with 71% being U.S.-based. The group leverages legal and regulatory risks to coerce victims into paying, promising not to leak stolen data if paid. The attack on Pelindo was reported by RedPacket Security, which clarified that they are not affiliated with the attackers and do not host any infringing content.
Oct, 2023On October 2023, Viking Line and several other European ferry operators were hit by a coordinated DDOS cyberattack that disrupted booking and customer service systems. The attack targeted shore-based IT infrastructure used for passenger operations. No attribution or technical details were publicly disclosed.
Sep, 2023In September 2023, Pro-Russian hackers targeted several Croatian and one Bulgarian port with cyber attacks. DDoS attacks knocked multiple websites offline. The responibility for the attacks was claimed by NoName057(16) and Dark Storm on their respective Telegram channels. The websites of the port authorities were offline for a while.
Sep, 2023In September 2023, Gulf American Lines, a leading freight forwarding, warehousing, and logistics provider headquartered in Berkeley Heights, New Jersey, fell victim to a Medusa Locker ransomware attack. The attackers exploited an external web server, used web shells for access, and employed PowerShell for malicious activities, including disabling antivirus services. They utilized discovery and credential dumping techniques such as Mimikatz and Nishang, and established a reverse tunnel for command and control. Data was exfiltrated and later published on the Medusa leak site, with files encrypted and appended with .MEDUSA. The ransom demand was $100,000. The incident was reported by RedPacket Security, which emphasized its non-affiliation with any ransomware threat actors.
Sep, 2023In September 2023, RS Logistics Ltd, a logistics company based in Hong Kong, was targeted by the NoEscape ransomware group. The attackers encrypted the company's data and stole over 4,000 email documents, threatening to publish the data unless contacted by the company. NoEscape, a Ransomware-as-a-Service (RaaS) operation believed to be a rebranding of Avaddon ransomware, emerged in May 2023 and primarily targets industries in the United States while avoiding CIS countries. The ransomware uses a TOR-based platform for multi-extortion, listing victims and hosting exfiltrated data. The attack on RS Logistics, founded in 2003, was reported on September 2, 2023, and the company was listed on NoEscape's data leak site. The ransomware employs various evasion techniques, persistence methods, and disabling security features, with detailed technical analysis provided for detection and defense. The consequence of the attack is the potential exposure of sensitive data and operational disruption for RS Logistics.