In June 2023, Schneider Electric, a multinational company specializing in digital automation and energy management, was targeted by the Clop ransomware gang in France. The attack exploited a zero-day vulnerability in the MOVEit Transfer software, developed by Progress Software. Clop listed Schneider Electric and other companies, including Siemens Energy and Cognizant, on its darkweb site, pressuring them to pay extortion fees to avoid data disclosure. Despite Schneider Electric's efforts to mitigate the vulnerability, Clop claimed to have stolen data from the company's systems. The MOVEit vulnerability has led to breaches in over 100 organizations, including Shell, PwC, and British Airways. Schneider Electric's response highlighted the importance of proactive cybersecurity measures and rapid incident response. The incident underscores the widespread impact of the MOVEit vulnerability, affecting various organizations globally.
Jun, 2023In June 2023, Abeko, a company based in the Netherlands, fell victim to a Play ransomware attack. The company, which has been providing services to nationally and internationally renowned companies for over 45 years, had its data exfiltrated. The attack was reported on June 2, 2023, and the publication date of the files was June 11, 2023. No files were available for download at the time of the scrape.
Jun, 2023Kaff Logistics Ltd., a logistics firm based in Hungary, was hit by a ransomware attack from a group known as Ransomware Blog in 2023. The group, whose origins remain unidentified, focuses on logistics firms, where operational disruptions can create immediate incentives to pay ransoms. The incident emphasized the need for logistics companies to implement stronger cybersecurity measures in an industry already under significant cyber threats.
Jun, 2023In 2023 Indonesia’s Harita Group, a prominent player in the manufacturing sector, was subjected to a ransomware attack by the lesser-known MalaLocker group. Though the origins of MalaLocker are unknown, their attack demonstrated the growing trend of ransomware actors targeting manufacturing firms, where downtime can directly translate into financial losses and supply chain disruptions. The attack, which targeted Zimbra servers, resulted in the leak of 99,000 emails totaling 510 GB, revealing sensitive information about the company's nickel and bauxite mining operations, coal activities, and partnerships, including with Glencore International. The incident not only disrupted Harita’s operations but also highlighted broader concerns about environmental and corporate practices in Indonesia's resource sectors.
Jun, 2023The Clop ransomware group targeted the Germany-based logistics provider, Rhenus Logistics. Clop, a ransomware organization associated with Russian cybercriminals, has a history of targeting large organizations. The attack on Rhenus Logistics disrupted their services.
May, 2023In May 2023 several websites, among whom the website of the Port Authority of Bremen, were DDoSed by the threat group NoName057(16). Overall the motivation for their attacks center around what the group calls 'anti-russian'.
May, 2023In May 2023, the website of India's largest shipbuilding and maintenance yard in Cochin was a victim of a denial of service attack claimed by a hacktivist group. The website was reported to be down briefly, however, it was quickly restored to a working condition.
May, 2023In May 2023, a massive-scale set of DDoS attacks on NATO country maritime industries has been conducted by Russian hacktivist group NoName. A large amount of these attacks were directed towards the Baltic country of Lithuania. Multiple logistics sectors were attacked, including maritime transportation and logistics. Two companies of Freught and Baltic Shipping had their websites rendered temporarely out of action
May, 2023On May 7, 2023, Swiss multinational company ABB, a leading provider of electrification and automation technology, suffered a ransomware attack by the Black Basta gang. The attack disrupted ABB's operations, affecting its Windows Active Directory and hundreds of devices, leading to delays in projects and impacting manufacturing. In response, ABB terminated VPN connections with clients to prevent further spread. The company, headquartered in Zurich and employing around 105,000 people, serves various public and private sector clients, including US federal agencies. Black Basta, known for double-extortion tactics and linked to the FIN7 hacking group, has been active since April 2022. ABB is working to contain the incident and restore normal operations. It remains unclear if a ransom demand has been issued or paid, and no data has been found on the dark web.
May, 2023On May 24, 2023, the Integral Port Administration of Quintana Roo in Mexico experienced a data breach executed by the 8BASE ransomware group. The organization, established on March 17, 1994, has majority state participation with the Government of the Free and Sovereign State of Quintana Roo as the main partner, along with minority partners from various municipalities. The size of the data leak is currently unknown.