In January 2023 Oslo-based DNV – one of the world’s largest maritime organizations – said it was hit with ransomware on the evening of January 7 and was forced to shut down the IT servers connected to their ShipManager system. “DNV is communicating daily with all 70 affected customers to update them on findings of the ongoing forensic investigations. In total around 1000 vessels are affected,” DNV said in a statement.
In December 2023, the FBI successfully infiltrated the networks of the AlphV ransomware group and its affiliates, stealing decryption keys and distributing them to over five hundred affected organizations over eighteen months. The FBI also seized the group's leak site, significantly disrupting its operations. The AlphV ransomware group is suspected to be affiliated with the Russian Federation. The incident primarily targeted the private sector, and the responses from the victim government and policymakers remain unknown.
In 2023, Slade Shipping in the USA was targeted by the ALPHV ransomware group. The attack began with a malicious email containing a forked IcedID variant, which led to the installation of ScreenConnect for remote control. The attackers used various tools, including Cobalt Strike beacons and CSharp Streamer RAT, to gain credentials and move laterally within the network. Sensitive information was extracted using a custom tool called confucius_cpp. The final payload, ALPHV ransomware, was deployed after deleting backups. A ransom note referencing the group's Twitter was left post-encryption. The consequence of the attack was significant disruption to Slade Shipping's operations and potential data breaches.
In 2023, Emerson in the USA was targeted by the CL0P Ransomware Gang. The attackers exploited a vulnerability in Progress Software's MOVEit Transfer, using a web shell named LEMURLOOT to steal data from MOVEit Transfer databases. The CISA and FBI released a joint Cybersecurity Advisory providing indicators of compromise and tactics identified through FBI investigations. IT network defenders are encouraged to review the advisory and implement recommended mitigations to reduce the risk of compromise. This advisory is part of the ongoing #StopRansomware effort to help organizations protect against ransomware threats.
In a recent cybersecurity incident, the PLAY ransomware group targeted Centek Industries in the USA. The attack is part of a broader campaign by the group, which has added seven new organizations to its list of victims. Other significant incidents include a data breach at Flagstar Bank affecting over 800,000 U.S. customers, a cyberattack on Volex, and a surge in web skimming attacks on e-commerce sites. Additionally, cybersecurity agencies such as CISA, FBI, NSA, and the US Treasury have issued a joint advisory to enhance the security of Open Source Software (OSS) in Operational Technology (OT) and Industrial Control Systems (ICS).
In 2023, AG&P, a key player in energy infrastructure based in the Philippines, faced a ransomware attack launched by the notorious LockBit 3.0 group. This Russia-linked organization is known for its relentless targeting of critical industries. The incident disrupted AG&P's operations, illustrating the group's strategy of focusing on infrastructure companies whose activities have far-reaching economic consequences. The attack highlighted the pressing need for bolstering cybersecurity defenses in the energy sector, especially in regions where digital infrastructure is expanding rapidly.
GAC Egypt, a logistics provider that facilitates trade and transportation in Egypt, became a victim of the LockBit 3.0 ransomware group. The attack underscored LockBit's ongoing focus on the logistics and supply chain sector, where any disruption can create significant downstream effects. As the group originates from Russia, its tactics often involve double extortion, threatening to leak stolen data unless ransoms are paid.
The Turkey-based Melody Shipping Agency was hit by LockBit 3.0 in a 2023 ransomware incident that brought parts of its shipping operations to a standstill. The group's attacks often exploit vulnerabilities in critical maritime services, with LockBit 3.0 aiming to extract substantial ransom payments from firms that cannot afford prolonged disruptions. This incident highlighted the challenges faced by shipping companies operating in an environment increasingly fraught with cyber threats.
Stolthaeven Westport, a port operator located in Malaysia, fell victim to a LockBit 3.0 ransomware attack in 2023. LockBit 3.0 frequently targets infrastructure-related companies, recognizing the leverage gained from affecting crucial services. The incident emphasized the need for heightened cybersecurity measures in port operations
In 2023, GTT Group, a Canada-based technology company, fell victim to a ransomware attack orchestrated by BlackBasta. The group, suspected to originate from Russia, is known for its high-profile ransomware incidents and sophisticated tactics. The attack on GTT Group disrupted technological services and highlighted the continuing threat that ransomware poses to the maritime technology sector.