CargoExperts, a logistics company operating in the Middle East, was targeted by LockBit 2.0 in 2022. The ransomware attack disrupted cargo services, highlighting the vulnerability of logistics companies to cyber threats in regions with critical trade routes.
May, 2022In May 2022, the London Port Authority website knocked down by a DDoS attack in Tilbury, London. The attack, thought to have been carried out by the Altahrea Team hacking gang, appears to be politically motivated, according to security researchers. These ‘loud’ attacks seem to be politically motivated, aimed at making noise rather than damage, clarify the researchers, hence why they use DDoS as a method, which is simple but very disruptive and visible.
May, 2022Blume Global Inc., a U.S.-based supply chain technology provider, was hit by AvosLocker in 2022. The group, suspected to be connected to Russia, exploited vulnerabilities that disrupted access to the company's asset management platform, affecting systems and data. The company quickly launched an internal investigation and worked with cyber forensic experts to assess and mitigate the damage. The incident highlighted ongoing challenges in securing supply chain technology, especially amid global disruptions.
May, 2022Morrison Express, a logistics company in Taiwan, was attacked by LockBit 2.0 in 2022. The ransomware disrupted international logistics operations, revealing the growing trend of targeting global logistics providers. LockBit 2.0's connections to Russia increase concerns about cross-border cyber threats.
Apr, 2022Pacific Maritime Industries Corp., operating out of the U.S., was targeted by the Onyx ransomware group in 2022. The attack affected the company’s marine services, exposing the maritime sector’s vulnerabilities to ransomware, which can disrupt essential operations tied to shipping and cargo management.
Apr, 2022Greece-based Attica Holdings S.A., a leading maritime company, was hit by a ransomware attack from Conti in 2022. Conti, linked to Russia, disrupted ferry operations, demonstrating how ransomware can impact maritime transport, especially passenger and cargo services.
Apr, 2022SOHAR Port and Freezone in Oman faced a ransomware attack from LockBit 2.0 in 2022. The Russian-linked group disrupted port operations, affecting trade activities. The incident underscored the vulnerability of port infrastructure to ransomware, which can cause major disruptions to global shipping.
Apr, 2022Basra Multipurpose Terminal in Iraq was targeted by the Midas ransomware group in 2022. The attack disrupted port activities, highlighting the risks that ransomware poses to infrastructure in regions undergoing economic development. Midas is linked to Russian-origin cybercriminal activity.
Mar, 2022The Chinese state-aligned threat actor TA423 (aka Leviathan/APT40) is behind a sustained cyber-espionage (phishing) campaign, that lasted more than a year, against countries and entities operating in the South China Sea, including organizations involved in an offshore wind farm in the Taiwan Strait. TA423 has been active for almost 10 years, with its activity dovetailing with military and political events in the Asia-Pacific region. TA423's typical targets include defense contractors, manufacturers, universities, government agencies, legal firms involved in diplomatic disputes, and foreign companies involved with Australasian policy or South China Sea operations. TA423 is one of the most consistent advanced persistent threat (APT) actors in the threat landscape, supporting the Chinese government in matters related to the South China Sea, including during the recent tensions in Taiwan.
Mar, 2022In March of 2022, the Hamburg (Germany) based Hapag-Lloyd head office, was hit by a spear-phishing attack. The IT security team found a copy of its website, which was being used by criminals. The criminals used hyperlinks, send to the users by email, to redirect users to the fake site. Once the users did a log in, the criminals became able to steal the users personal data. After finding out about the incident, the company warned users for incoming emails, and recommended to access the website by manually entering it, not with the usage of a link.