List View

May, 2023

Clop Ransomware Attack on Honeywell

In late May 2023, Honeywell International, an American advanced technology conglomerate, experienced a cybersecurity incident where sensitive company data was compromised due to the MOVEit attack spree by the Cl0p ransomware gang. The breach affected a single MOVEit server, and Honeywell confirmed the incident in an official statement on June 16th. Despite the breach, Honeywell assured that there was no material impact on business operations, and all systems remained fully operational. The company's cybersecurity defenses limited the impact to the affected server, and IT teams have since patched and upgraded the MOVEit app. The MOVEit Transfer system, developed by Progress, has been exploited by Cl0p, affecting around 3,000 deployments and at least 150 victims, including major companies and US federal agencies.

May, 2023

Hacking of Israeli Shipping and Logistics Companies

On May 23, 2023 the cybersecuritry company ClearSky provided their analysis on the Fata Morgana campaign. This campaign leveraged highly sophisticated cyber techniques to target Israel’s shipping and logistics sector through watering hole attacks. Instead of directly breaching individual companies, the attackers compromised trusted industry websites frequently visited by maritime professionals. By injecting obfuscated malicious JavaScript code, they ensured that unsuspecting users would unknowingly trigger malware downloads, allowing the attackers to gain a foothold in their systems. This approach not only increased the attack's success rate but also made attribution and detection significantly more challenging. Once a visitor interacted with an infected site, the malicious script performed system reconnaissance, gathering details on the victim’s operating system, browser version, and security settings. If the system was deemed a valuable target, the attackers would deploy a multi-stage malware payload, ensuring deeper infiltration. The hackers also employed evasive techniques, such as frequently rotating Command and Control (C2) servers and encrypting data transmissions to avoid triggering security alerts. Additionally, they exploited known vulnerabilities in web browsers and plugins, leveraging unpatched software flaws to bypass traditional cybersecurity defenses. ClearSky attributed these attacks “with a low confidence” to the Iranian nation-state hacker group Tortoiseshell. The combination of these tactics highlights the strategic and calculated nature of this cyber operation, suggesting a well-funded, state-sponsored effort aimed at disrupting Israel’s maritime sector.

May, 2023

Four tankers falsify AIS positions to hide calls to Russian Black Sea ports

Between January and May 2023, four tankers—GINZA, TIVY GOLD, KATSUYAMA and LOURA B—systematically falsified AIS positions in the Black Sea to hide calls to Russian Black Sea ports after oil sanctions came into force. Public data analysis by SkyTruth and Global Fishing Watch shows that while the ships broadcast tracks near Bulgaria and the wider Black Sea, satellite imagery and radar reveal they were actually near ports such as Novorossiysk, Feodosia and Taman in or near the Kerch Strait. The pattern allowed the vessels to appear compliant in public AIS feeds while secretly loading or discharging Russian oil, undermining sanctions enforcement and reducing trust in AIS as a safety and compliance tool.

May, 2023

Four tankers falsify AIS positions to hide calls to Russian Black Sea ports

Between January and May 2023, four tankers—GINZA, TIVY GOLD, KATSUYAMA and LOURA B—systematically falsified AIS positions in the Black Sea to hide calls to Russian Black Sea ports after oil sanctions came into force. Public data analysis by SkyTruth and Global Fishing Watch shows that while the ships broadcast tracks near Bulgaria and the wider Black Sea, satellite imagery and radar reveal they were actually near ports such as Novorossiysk, Feodosia and Taman in or near the Kerch Strait. The pattern allowed the vessels to appear compliant in public AIS feeds while secretly loading or discharging Russian oil, undermining sanctions enforcement and reducing trust in AIS as a safety and compliance tool.

Apr, 2023

Passenger hid Camera in Cruise Ship "Harmony of the Seas" Public Bathroom

In April 2023 accordinmg to an F.B.I. affidavit in support of the criminal complaint and arrest warrant a day after the Royal Caribbean ship departed from Miami for a seven-night eastern Caribbean cruise, a man identified as Jeremy Froias allegedly hid a Wi-Fi camera in a top deck bathroom, pointing its lens toward the toilet. A day later, the camera was spotted by a passenger who reported it to the ship’s security staff. They found hours’ worth of footage showing more than 150 people, including what appear to be at least 40 minors — some of whom were at least partly naked, the FBI said.

Apr, 2023

Israeli Ports DDosed by Sudanese Anonymous Group

In April 2023 a Sudanese hacker group claimed to bring down the internet sites of two Israeli ports on Wednesday as the Jewish State celebrated its Independence Day, the Ynet website reported. A group of hackers that goes by “Anonymous Sudan,” which has claimed other recent online assaults on Israeli sites, said it targeted the Haifa Port website and that of the Israel Ports Development & Assets Company, which manages Israel’s ports.

Apr, 2023

Canadian Ports of Quebec City, Halifax, Montreal DDosed by Pro-Russian Group

In April 2023 pro-Russian hacker group NoName057(16) claims cyberattacks against various Canadian ports. For some time the websites of the ports of Quebec City, Halifax and Montreal were experiencing difficulties and were inaccessible. The cyberattacks have been linked to the NoName057(16) group, which claimed them through the Russian platform Telegram.

Apr, 2023

Northern Germany shipyards hit by Ransomware attack from BianLian APT group

In April 2023 there was a Ransomware attack on Lürssen shipyard , the Flensburger Schiffbau Gesellschaft mbH & Co. and Nobiskrug Yachts GmbH. Attack was attributed to BianLian APT group and 3 terabytes of data were reportedly stolen.

Apr, 2023

Ransomware attack on the Fincantieri Marine Group

In April 2023, Fincantieri Marine Group (FMG), a U.S. Navy shipbuilder, experienced a ransomware attack, disrupting production and compromising personal information of 16,769 individuals, mainly Maine residents. The attack, involving unauthorized access between April 6 and April 12, 2023, led to the encryption of files containing names and Social Security numbers. The incident impacted manufacturing machines, causing server outages.

Apr, 2023

Ransomware Attack by LockBit 3.0 on Barcelona Cruise Port

In April 2023, the Barcelona Cruise Port in Spain, known as bcncruiseport[.]com, was targeted by a LockBit 3.0 ransomware attack. The attackers threatened to publish all available data if the ransom was not paid by April 25, 2023. The port, which includes five terminals, faced a ransom demand of $299,999 USD to destroy all information or to download the data at any moment, and $1,000 USD to extend the deadline by 24 hours.