In September 2023, the BlackCat/ALPHV ransomware gang attacked Yusen Logistics, a subsidiary of the NYK Group based in Tokyo, Japan. The gang claimed to have stolen 90GB of company information. BlackCat/ALPHV, known for its sophisticated ransomware-as-a-service (RaaS) platform, employs advanced encryption techniques and targets various industries. The group has been active since late 2021 and is noted for its high ransom demands and ability to disable security tools. The consequence of the attack is the potential exposure of sensitive company information and operational disruption.
Sep, 2023In September 2023, Bordelon Marine in the USA was targeted by the Play Ransomware Group. This group, which first appeared in June 2022, has expanded its operations from Latin America to the U.S. and Germany. They are known for their sophisticated attack strategies, including exploiting known vulnerabilities and using tools like AdFind to gather Active Directory information. The attack on Bordelon Marine involved encrypting files with a '.play' extension. The incident is part of a broader trend of increasing ransomware and malware attacks, with the Play Ransomware Group listing six businesses on their data leakage site on the Tor network, indicating potential data breaches.
Sep, 2023In 2023, Germany’s IPSEN Logistics experienced a ransomware attack executed by LockBit 3.0. Known for their elaborate ransomware-as-a-service model, LockBit 3.0's techniques are highly effective in targeting firms that provide international logistics. The disruption caused to IPSEN’s operations served as a reminder of the cyber risks facing logistics providers, where even a short downtime can create cascading effects on international trade routes and supply chains.
Aug, 2023In August 2023, AKBASOGLU HOLDING Trans KA, a company in Turkey, fell victim to a Knight ransomware attack. The attackers infiltrated the company's network, stealing sensitive data including financial documents, logistics data, personal information, insurances, and confidential information. They also accessed the company's resources and partners. The stolen data is set to be made publicly available within three days, posing a threat to the company's customers. Knight ransomware, an evolution of Cyclops ransomware, operates as a Ransomware-as-a-Service (RaaS) and targets enterprise and SMB environments through phishing and spear phishing campaigns. The attack highlights the importance of multi-layered security measures, employee education, strong passwords, multi-factor authentication, regular system updates, and robust backup and disaster recovery plans.
Aug, 2023In August 2023, Aranui Cruises, the oldest cruise operator in French Polynesia, was targeted by the Medusa Locker ransomware group. The attack was reported on August 31, 2023, with a ransom demand of $100,000. The breach resulted in a data leak, the size of which is currently unknown. The information was obtained from the Medusa Locker Onion Dark Web Tor Blog page and posted by RedPacket Security. The American office of Aranui Cruises is located in San Mateo, California.
Aug, 2023In August 2023, the Qilin ransomware group targeted Thonburi Energy Storage Systems (TESM), a prominent battery manufacturer in Thailand. The group, also known as Agenda, has been active since 2022 and has targeted various sectors including healthcare, education, manufacturing, and real estate. The ransomware operates via a Ransomware-as-a-Service (RaaS) model and uses programming languages like Rust and Go to evade detection. The Rust variant, first observed in December 2022, employs intermittent encryption tactics and uses a double-extortion model, threatening to leak stolen data if the ransom is not paid. The attack on TESM was highlighted by Threat Intelligence Service Falcon Feeds, which shared screenshots from the ransomware group's dark web portal. The Qilin group posted about the attack on August 7, 2023, and provided a link to the targeted website. The ransomware uses Remote Monitoring and Management (RMM) tools and Cobalt Strike for deployment, and employs various techniques for defense evasion, including the use of vulnerable SYS drivers. Organizations are advised to implement security measures such as regular data backups, limited administrative access, and user education to protect against such ransomware attacks.
Jul, 2023On July 28, 2023, the Malaysian tanker Shanaye Queen spoofed its AIS to appear anchored in Karachi while likely loading Iranian crude oil in violation of U.S. sanctions. Satellite and AIS data confirmed ship-to-ship transfers and false cargo documentation. The vessel had a history of similar deception, highlighting the challenge of detecting AIS manipulation.
Jul, 2023In July 2023 the port of Nagoya Japan was hit with a ransomware attack by the Lockbit group. Nagoya is Japan's busiest port and an important hub for car exports and crucial to the Japanese economy. The attack shutdown the the computer system that handles shipping containers. The attack prevented the port from recieving shipping containers for two days.
Jul, 2023In July 2023, Sea Force IX, a company based in Florida, USA, known for its fine custom sport fishing yachts, fell victim to a Play ransomware attack. The attack was reported on July 19, 2023, and the information was scraped from the PLAY NEWS Onion Dark Web Tor Blog page. No files or stolen information were available for download at the time of the report. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) issued a joint Cybersecurity Advisory (CSA) on Play ransomware. The advisory, titled #StopRansomware: Play Ransomware, details the tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) used by the Play ransomware group, identified through FBI investigations as recently as October 2023. Play ransomware actors use a double-extortion model, encrypting systems after exfiltrating data, and have affected various businesses and critical infrastructure organizations across North America, South America, Europe, and Australia. The advisory encourages organizations to review and implement the provided recommendations to mitigate the risks and impacts of Play and other ransomware incidents.
Jul, 2023In a recent cybersecurity incident, the Clop ransomware group targeted MS Amlin in Canada as part of a larger MOVEit cyber-attack. The attack compromised employee and customer information from multiple companies, including AON, PwC, MS Amlin, and Digital Insight AS. Clop has made downloadable files related to these organizations publicly available. The breach of AON's IT system notably includes personal data of DPD staff. Legal experts indicate that affected individuals may be entitled to compensation if security measures were found to be inadequate. The full extent of the breach is still being determined.