In 2023, Pechexport, a Madagascar-based shipping company, was targeted by the Cyclops ransomware group in a cyberattack. The origins of the Cyclops group are unknown, but the attack affected the company's shipping operations, underlining the threat ransomware poses to maritime businesses, which are vital for global trade and the movement of goods.
Jul, 2023SBM Offshore, a Netherlands-based company specializing in offshore services, became the target of a ransomware attack by the Clop group. Clop has a history of targeting large industrial companies. The attack on SBM Offshore disrupted offshore energy services and emphasized the persistent cyber risks faced by companies in the energy and industrial sectors.
Jun, 2023In June 2023 Pro-Russian hackers targeted several Dutch ports’ websites with cyber attacks. The DDoS attacks have knocked several ports’ websites offline for several hours or even days. The port authorities of Groningen, Amsterdam, Rotterdam, and Den Helder confirmed the DDoS attacks to the broadcaster. In such a cyberattack, a website or server is flooded with requests until it crashes. The websites of the port authorities were offline for sometime.
Jun, 2023In June 2023 Pro-Russian hackers targeted North Sea Port with a DDoS attack. North Sea Port website was offline for some time. According to cybersecurity firm FalconFeeds.io, NoName05716 is behind the attack. North Sea Ports operates the ports of Vlissingen and Terneuzen in Zeeland, and the Ghent port in Belgium.
Jun, 2023In June 2023 the boat manunfacturing company, Brunswick Corporation, suffered a cybersecurity incident which caused multiple facilities to go down, it took 9 days for IT systems to be up and running again. This caused significant delays in production and will take a considerable amount of time before the delays have been worked away. The estimated damages are upwards of US$85 million dollars.
Jun, 2023In June 2023, the company AME Offshore Solutions in Australia was targeted by the LockBit 3.0 ransomware gang. The attack was first reported on June 29, 2023, when LockBit 3.0 posted AME to its data leak site, threatening to leak all stolen data if the organization failed to pay an undisclosed ransom by July 29th. The ransomware group has already published all exfiltrated data, suggesting that AME refused to cooperate. LockBit has been active since 2019 and is known for its fast encryption speed and multiple extortion techniques, including data exfiltration.
Jun, 2023In June 2023, Cyberfreight Systems Maritimes Inc., a Canadian transportation and logistics management company, experienced a data breach. The breach was carried out by the 8BASE ransomware group, which claims to have accessed invoices, financial documents, agreements, and other internal documents. The size of the data leak remains unknown. This incident is part of a broader trend of ransomware attacks by various groups, including ALPHV, Akira, KaraKurt, PLAY, and Rhysida, affecting organizations in multiple countries. Additionally, DDoS attacks by groups like Turk Hack Team and NoName057(16) have targeted websites in Switzerland, Latvia, and the Czech Republic. Miscellaneous cybersecurity updates include data breaches and the sale of phishing tools.
Jun, 2023In June 2023, Lysander Shipping, a Denmark-based global shipping company, fell victim to a ransomware attack by the 8BASE group. The cybercriminal gang, active since April 2022, employs a double extortion tactic, first stealing and then encrypting data. They threatened to publish the stolen data on July 3, 2023, if the ransom was not paid. The stolen data included sensitive files such as invoices, internal documents, bank documents, and financial records. The attack was reported by RedPacket Security on June 26, 2023. The 8BASE group predominantly targets small and medium-sized businesses in the Professional/Scientific/Technical and Manufacturing sectors. Other victims of the group include Clear Medi Healthcare from India, Job-Sa Beton from Tunisia, Pneumax from Italy, and Legalilavoro, an Italian legal consultancy firm.
Jun, 2023In June 2023, the Arab Shipbuilding and Repair Yard Company (ASRY) in Bahrain experienced a ransomware attack by the BianLian group. Founded in 1977, ASRY is a leading maritime repair and fabrication facility in the Arabian Gulf. The attackers exfiltrated 200GB of data, including client data, ship and vessel plans (including navy ships), personal data of crew members, business files, and accounting data. The stolen information was posted on BianLian's leak site on June 28, 2023. BianLian, known for targeting critical infrastructure sectors, uses valid Remote Desktop Protocol (RDP) credentials and open-source tools for reconnaissance and data extraction. Since January 2023, they have shifted focus from double-extortion to data exfiltration-based extortion. The incident was reported by RedPacket Security, which is not affiliated with any ransomware threat actors.
Jun, 2023In June 2023, the Cl0p ransomware gang attacked Hornbeck Offshore, an American company specializing in marine transportation services for the offshore oil and gas industry, based in Covington, Louisiana. Cl0p posted Hornbeck Offshore to its data leak site on June 30th, 2023, but provided no further details. Cl0p is a major Ransomware-as-service (RaaS) platform known for its advanced anti-analysis capabilities and has been active since 2019.