List View

Apr, 2023

Ransomware Attack on Neptune Lines by Vice Society

In April 2023, Neptune Lines, a car carrier company based in Greece, was targeted by a ransomware attack orchestrated by the Vice Society group. The incident was reported on April 22, 2023, by RedPacket Security. The attack involved the Vice Society group scraping information from their Onion Dark Web Tor Blog page. RedPacket Security emphasized that they do not host or disclose any stolen information and are not affiliated with any ransomware groups.

Apr, 2023

Clop Ransomware Attack on DESMI

In April 2023, DESMI, a global pump solutions company based in Denmark, experienced a ransomware attack by the Clop gang. The attack led to the shutdown of all IT systems, but fortunately, the ERP and finance systems were not compromised, and production sites in China, India, America, and Denmark continued to operate without disturbances. The attack exploited the CVE-2023-34362 MOVEit vulnerability and occurred during the COVID-19 pandemic when employees were working from home. DESMI's CEO, Henrik Sørensen, confirmed that the company has no plans to pay the ransom. Third-party cybersecurity experts were hired to investigate and restore IT services. The incident has been reported to the authorities and Danish Police, and DESMI is notifying its customers and business partners about the breach. The company is focused on minimizing customer impact and expects to have systems operational within a couple of weeks.

Apr, 2023

Play Ransomware Attack on UECC in Norway

In April 2023, UECC (United European Car Carriers), a leading short-sea operator and logistics provider for the transportation of cars, vans, and high & heavy cargo in Europe, fell victim to a Play ransomware attack. The incident was reported on April 22, 2023, with the publication date of the files being May 2, 2023. At the time of the report, no files or stolen information were available. The attack was reported by RedPacket Security, which is not affiliated with any ransomware threat actors.

Apr, 2023

BlackCat/ALPHV Ransomware Attack Hits Vopak Malaysia Pengerang Terminal

ALPHV/BlackCat ransomware attack on Vopak's Pengerang Independent Terminals (PTSB) in Malaysia. The terminal (44% owned by Royal Vopak, 1.76 million cubic meters capacity) experienced unauthorized access to data including financial records, personal information, and critical client data. Attackers issued 72-hour ransom deadline. Terminal operations continued but data exfiltration was confirmed. No impact to Vopak's global network reported.

Mar, 2023

Dutch shipping giant Royal Dirkzwager hit by Ransomware Attack

In March 2023 Dutch maritime logistics company Royal Dirkzwager has confirmed that it was hit with ransomware from the Play group. The Play ransomware group added the company to its list of victims. The group first emerged in July 2022 targeting government entities in Latin America, according to Trend Micro, and most recently drew headlines for a damaging attack on the City of Oakland, which has spent weeks recovering from the incident. Company CEO Joan Blaas, who bought the Royal Dirkzwager in October 2022 after it went bankrupt the month prior, told The Record the ransomware attack did not have an effect on operations but did involve the theft of data from servers that held a range of contracts and personal information. In June 2025, it was reported that the attack occurred after hackers successfully brute-forced credentials for a system that had recently migrated from on-premise to the cloud. During this transition, critical security measures were overlooked, leaving the system vulnerable. Royal Dirkzwager also noted that they had a fallback system, an old DataDrik platform built in 1983, which allowed them to continue registering shipping traffic and communicating with customers by phone.

Mar, 2023

Ransomware Attack by Stormous on Furuno Spain S.A.

In March 2023, Furuno Spain S.A., a subsidiary of Furuno Electric Co., experienced a data breach. The breach was carried out by the STORMOUS ransomware group. Furuno Electric Co., headquartered in Nishinomiya, Japan, is a global leader in marine electronics. The size of the data leak is currently unknown.

Mar, 2023

BianLian Ransomware Attack on Nobiskrug in Germany

In March 2023, the Flensburger Schiffbau-Gesellschaft (FSG) and the Rendsburg shipyard Nobiskrug in Germany were targeted by the BianLian ransomware group. The attack led to the sealing off of all IT systems, with the group claiming access to 3TB of company data. The US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Australian Cyber Security Centre (ACSC) have warned critical infrastructure organizations about BianLian's activities. Active since June 2022, the group uses remote desktop protocol (RDP) credentials, often obtained through phishing, to infiltrate networks. Since January 2023, BianLian has focused on data exfiltration rather than file encryption, using custom Go-based backdoors and various tools for reconnaissance and credential harvesting. They threaten to publish stolen data unless a ransom is paid in cryptocurrency. Organizations are advised to audit RDP usage, disable command-line scripting, and implement strong authentication practices to defend against such attacks.

Feb, 2023

Aker Solutions' Brazilian subsidary hit by cyberattack

In February 2023 Aker Solutions subsidary C.S.E was hit by a cyber attack. The attackers claim that they have entered the IT systems, encrypted digital files and locked access to data. There is no indication that the cyber attack impacted any of Aker Solutions' other IT systems.

Jan, 2023

Ransomware Attack on Livingston International by Royal Ransomware Group

In January 2023, Livingston International, a major North American freight forwarder and customs broker, experienced a ransomware attack by the Royal ransomware gang. The attackers exfiltrated sensitive information, including employee documents, financial details, and network structure data, affecting 3,200 employees, 30,000 customers, and 125 key border entry points. The breach halted operations at the US-Canada border for two business days. The Royal ransomware group, active since January 2022, uses phishing emails and malicious advertisements to target victims. They have also been linked to other high-profile breaches, including those of Intrado, AONTTAGL, and the Queensland University of Technology. Operations at Livingston International resumed after two days, but the extent of the data breach was significant.

Jan, 2023

BianLian Ransomware Attack on Bolidt

In January 2023, the BianLian ransomware group shifted its focus from file encryption to data theft-based extortion, following the release of a decryption tool by Avast. Active since June 2022, the group gains access to networks via Remote Desktop Protocol (RDP) credentials, often acquired through phishing or initial access brokers. They use custom Go-based backdoors, remote management software, and various tools for reconnaissance and credential harvesting. The group threatens to publish exfiltrated data on a leak site and demands ransom payments in cryptocurrency. To evade detection, BianLian disables antivirus processes using PowerShell and Windows Command Shell. The US Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Australian Cyber Security Centre (ACSC) have issued warnings to critical infrastructure organizations. Recommended mitigations include auditing RDP usage, disabling command-line scripting, restricting PowerShell, and maintaining strong authentication practices.