List View

Terntank hit by Play ransomware

In 2023, the Swedish tanker company Terntank fell prey to a ransomware attack orchestrated by the Play group. Play has increasingly been linked to incidents involving maritime and logistics firms, exploiting the sector’s critical role in energy and goods transport. For Terntank, the attack disrupted tanker operations, raising concerns about ransomware’s impact on maritime safety and the secure transport of energy products.

Phising attacks against Taiwanese related maritime organisations

In 2023, Taiwanese maritime organizations were targeted by a phishing campaign, which is often a precursor to ransomware attacks. The campaign aimed at compromising sensitive information within the maritime sector, emphasizing the ongoing cyber risks facing organizations involved in international shipping and logistics. Phishing remains a common method used by threat actors to gain initial access for further exploitation, including ransomware deployment.

Volt Typhoon Cybersecurity Incident

Since mid-2021, Volt Typhoon, a state-sponsored cyber actor from China, has been targeting critical infrastructure organizations in the United States, including sectors such as communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education. The campaign focuses on post-compromise credential access and network system discovery, using stealthy techniques like living-off-the-land and hands-on-keyboard activity to evade detection. Volt Typhoon routes traffic through compromised small office and home office network equipment to blend into normal network activity. Despite efforts to disrupt their activities, Volt Typhoon remains an ongoing threat, with the U.S. government issuing multiple advisories detailing their tactics and providing mitigation steps.

Chinese Military Hackers Infiltrate Critical U.S. Infrastructure

In recent years, hackers affiliated with China’s People’s Liberation Army have infiltrated the computer systems of about two dozen critical entities in the United States, including a water utility in Hawaii and a major West Coast port. These intrusions are part of a broader effort to develop ways to disrupt key American infrastructure in the event of a U.S.-China conflict in the Pacific. The targeted sectors include power, water utilities, communications, and transportation systems. The aim of these cyberattacks is to create chaos, disrupt logistics, and hinder U.S. military operations. The hacking group Volt Typhoon, active since mid-2021, has been identified as a key player in these efforts. Although the infiltrations have not yet impacted industrial control systems, they signify a significant shift in Chinese cyber activity from political and economic espionage to pre-positioning for potential conflict. U.S. officials and cybersecurity experts have raised alarms about China's plans to disrupt or destroy essential services if a conflict arises between the two nations.

Houthi Attacks and GPS Spoofing in the Bab al-Mandab Strait

In recent incidents, Yemen's Houthi rebels have conducted kinetic attacks and GPS spoofing against merchant vessels in the Bab al-Mandab Strait, a critical waterway connecting the Suez Canal and Red Sea with the Indian Ocean. The attacks, which include the use of Iranian-supplied cruise missiles and underwater drones, have caused significant damage to vessels such as the UAE military ship Swift and a Belize-flagged ship, though no casualties were reported. These actions have disrupted global trade flows, particularly affecting crude oil and fuel shipments, and have led to increased freight costs and voyage times as major shipping companies reroute their vessels via the Cape of Good Hope. The United States, along with several other countries, is leading a multinational operation to safeguard commerce in the Red Sea. The Houthis' actions are seen as part of their support for Hamas in its conflict with Israel, and they have warned international shipping companies against dealing with Israeli ports. The strategic threat posed by the Houthis has prompted the deployment of U.S. Navy warships to the area and calls for enhanced maritime security measures.

LockBit 3.0 Ransomware Attack on Grupo Omega in Brazil

Recently, there has been an increase in ransomware attacks by the LockBit group, specifically using the LockBit 3.0 version. This ransomware targets enterprises globally, encrypting their systems and demanding ransom. LockBit 3.0 is more advanced and evasive than its predecessors, and the group is responsible for a significant portion of ransomware attacks. They have targeted financial organizations like Fawry and Amber Hill Group, and are suspected in an attack on the Industrial and Commercial Bank of China. Recommendations to prevent such attacks include regular data backups, software updates, using endpoint security solutions, and limiting user privileges. In a notable incident, the LockBit 3.0 ransomware attack targeted Grupo Omega in Brazil, causing significant disruption.

LostTrust Ransomware Attack on Liberty Lines in Italy

In September 2023, the LostTrust ransomware group, an evolution of the SFile and Mindware ransomware families, launched a multi-extortion attack on Liberty Lines in Italy. The ransomware, which shares similarities with MetaEncryptor, terminates critical services and processes to facilitate encryption and data exfiltration, removes Volume Shadow Copies, and clears Windows Event Logs. Victims receive ransom notes portraying the attackers as security specialists, threatening to publicize stolen data if the ransom is not paid. The LostTrust leaks site, mirroring the MetaEncryptor site, listed 53 victims at the time of writing. The group, believed to be a rebrand of the MetaEncryptor gang, has targeted various sectors, with the USA and Italy being the most affected. The ransomware appends the “.losttrustencoded” extension to encrypted files and generates ransom notes named “!LostTrustEncoded.txt”. Ransom demands range from $100,000 to several million dollars. SentinelOne's Singularity platform detects and prevents malicious behaviors associated with LostTrust ransomware. The attack on Liberty Lines highlights the ongoing threat posed by ransomware groups and the need for robust cybersecurity measures.

Dec, 2022

Cyberattack Threatens Release of Port of Lisbon Data

The Port of Lisbon suffered a ransomware attack and data breach on Christmas Day 2022, raising concerns about the potential exposure of confidential information. The attackers have reportedly stolen financial reports, audits, budgets, contracts, cargo information, ship logs, port documentation, among other vital port-related information, whilst already having published samples of the stolen data. The group LockBit has threatened to publish all of the files that were seized during their computer attack should their ransom demands of $1.5 million be left unmet.

Dec, 2022

Voyager Worldwide hit by cyber attack

In December 2022 maritime tech giant Voyager Worldwide was hit by a cyber attack. All systems have been taken offline at the navigation services and solutions provider, which boasts more than 1,000 shipping companies as customers around the world.

Dec, 2022

Sirius Shipping hit by Play

Sirius Shipping, a Swedish tanker company, fell victim to Play ransomware in 2022. The attack disrupted shipping operations, emphasizing the significant cyber risks to tanker companies involved in energy transport, where disruptions can have broader economic implications