At the end of March 2022, occurrences of “dark activity” has sharply increased within Russian waters. Because of the war with Ukraine, engaging in business with Russia can lead to a blacklisting. Because of this, a lot of ships turn off their navigation system. By doing so, the ships can’t be traced and thereby engage in business with Russians without being noticed.
Mar, 2022In March 2022, a ferry on the Borholmslinjen (Borholms line) got delayed for two hours after a jamming incident. Alegedly, two Eastern European trucks onboard the ferry contained jamming equipment that caused the ferry's GPS system to malfunction. When the lorries disembarked from the vessel, its GPS system suddenly started working again.
Feb, 2022In February 2022, Vladimir Putin's £73 million superyacht was renamed "FCKPTN" by hacker group Anonymous, and making it appear as if it had crashed into Snake Island. The hackers hacked into the ship's navigational data and changed the ship's destination to "Hell," then to the little island where 13 Ukrainians stood up to a Russian battleship. According to Bloomberg reporter Ryan Gallagher they did it by manipulating the maritime AIS. In a tweet, Anonymous declared "cyberwar" on Russia's government.
Feb, 2022In February 2022, India based Jawaharlal Nehru Port Container Terminal, was hacked. The hacker hacked the computer systems of the JNPT through the internet, thus shutting down all the computers in the it department. Company officials and computer experts tried to restart the system in the JNPT container. For five days the terminal remained shut down, forcing the diverting of essential cargo and doing the terminals work manually.
Feb, 2022In February 2022, a ransomware attack on the computer systems of “Expeditors International of Washington Inc.” had taken place. The attack resulted in limited ability to conduct operations. Even 8 days after the incident, most of the staff remain absent from the corporal Seattle office. Also are employees not allowed to access their computers. This incident created even more stress on the already fragile global supply chains. As per the end of march, all the core systems were fully operational again.
Feb, 2022In February 2022, UK ferry operator Wightlink was hit by a cyber-attack. The ferry operator, based in Portsmouth UK, had its back-office IT Systems compromised because of hackers. As result, a small number of information files may have been compromised. As soon as Wightlink discovered the incident, the company engaged third party cybersecurity experts the investigate and asses the incident.
Feb, 2022The German industrial services company Muehlhan was hit by a Conti ransomware attack in 2022. Conti, a group linked to Russia, is notorious for targeting companies in industrial and critical sectors. The ransomware attack affected Muehlhan's services in areas like ship maintenance and offshore operations, underlining the risks to companies that provide specialized industrial services across multiple sectors.
Jan, 2022This maritime incident involving a form of ransomware started in Germany on the 29th of January in 2022. The two companies that were hit by the attack were Mabanaft GmbH and the Oil tanking GmbH Group, which share a parent company. The cyber criminals operated with a ransomware-as-a-service (RaaS) business model. The attackers were a group of Russians who previously referred to themselves as ‘’The Darkside Group’’ and therefore ‘’Blackmatter’’. Now the group is called the ‘’Black Cat’’ and they move around networks very quickly. Because of the actions of these cyber criminals, part of Germany's fuel delivery system was knocked out for a few days, and payments at certain filling stations were halted. It was clear that the aim of the attack was financial gain, but the amount of money that was requested by the group is . For most of its inland supply activity in Germany, Mabanaft has declared force majeure. Around 233 petrol stations were disturbed, most of them in northern Germany. They had to reroute to various supply depots because of the attack. No Oil Tanking operations outside of Germany were harmed. A consequence of this was that facility workers are having to do the job manually. The company immediately took steps to improve the security of the systems and processes. They initiated an investigation towards the incident with the help of experts. They’re also working closely with the appropriate authorities. In a company statement they said that they tried to resolve the issue in accordance with the contingency procedures, as well as to fully comprehend the incident's scale.
Jan, 2022SEA-Invest reported they had suffered a cyber attack against their IT networks on Sunday, January 30, 2022. The Conti Ransomware Gang, Gold Ulrick, used a ransomware type called Conti and affected the IT systems of the company. The aim of the attackers was financial gain. The impact of this was that all 24 of the seaports they run across Europe and Africa were affected by the attack. Six oil terminals in the ports of Antwerp, Ghent, Terneuzen and Amsterdam are also experiencing disruption as a result of a cyber attack. The companies have had to suspend some operations, affecting oil flows in the Netherlands, Belgium and across Germany. It is not clear whether the cyber attacks are linked.
Jan, 2022On the 29th of January, 2022, a ransomware attack was discovered. The attack was executed on oil terminals in ports in the Netherlands, Belgium and the port of Hamburg, Germany. These ports are all part of the EVOS group. After the discovery of the ransomware attack, emergency measurers took place. The impact concluded the inability of terminals to process barges, making it impossible for tankers to deliver or unload.