In 2022 DonsöData, a Swedish IT company serving the maritime sector, was hit by Play ransomware in 2022. The incident affected services that support maritime operations, underlining the interconnected vulnerabilities between IT providers and the maritime industry in the face of ransomware threats.
Dec, 2021In December 2021, Charles Kendall, a UK logistics company, was hit by the Conti ransomware group.
Dec, 2021In December 2021, Kerry Logistics in Hong Kong was attacked by the LockBit 2.0 ransomware group.
Dec, 2021In December 2021, TLP Terminal Sdn Bhd in Malaysia suffered a ransomware attack from the LV group.
Dec, 2021In December 2021, Ben Line Agencies, a shipping services company, was attacked by the LV ransomware group.
Dec, 2021In December 2021, the Indonesian and Philippine navies (based in South-East Asia) was attacked bT108:V112y hackers that used a form of malware on the system. The FunnyDream hack group, which is said to be Chinese state-sponsored, used spam mail to, with the usage of Chinoxy malware, open a backdoor. That way the FunnyDream can make another backdoor which then can be used to gain access to data. It is not clear what the impact of the attack has been, but the motives are clearly espionage.
Dec, 2021In December 2021, Hellmann Worldwide Logistics, a prominent German logistics provider, was targeted in a high-profile cyber attack by the RansomExx threat actor. The attack, motivated by financial gain, led to significant operational disruptions as the company had to take its central data center offline. Allegedly, the attackers exfiltrated 70.64GB of compressed data, including customer names, user IDs, emails, and passwords. Hellmann activated its Global Crisis Taskforce and enlisted external security specialists to investigate the incident. The company has not ruled out the possibility of data leakages and has warned customers about fraudulent calls and emails. The consequence of the attack was a significant impact on business operations, which are now largely running again but not at full capacity. The incident highlights the ongoing threat of ransomware attacks in the logistics industry.
Nov, 2021This incident occurred in November 2021 near Skagen, Denmark. Just days after Danish authorities detained the Russian research vessel Akademik Ioffe on November 1, a fabricated AIS track suggested that WARSHIP 545 had sailed along Denmark’s northern coastline within its territorial waters.
Nov, 2021In November 2021, UABL S.A., a shipping company in Argentina, was targeted by the Quantum ransomware group.
Nov, 2021An interesting ransomware attack occurred on the 25th of November in 2021 at the trusted marine services provider (SPO). The IT Systems were infected with a variant of the CLOP ransomware caused by the Russian group called CLOP Gang. The group has claimed credit for the cyberattack and has released screenshots of the stolen data. They used the CLOP ransomware, which is a virus that bypasses protection to encrypt files that aren't protected. ‘’It is part of the well-known Crypto mix ransomware family, which is a harmful file-encrypting virus that intentionally avoids security-vulnerable systems and encrypts stored data by planting the CLOP extension’'. The stolen data included full names, company name, locations, phone numbers, email addresses, bank details, and passport scans. Employees in Singapore and Malaysia appear to be the most impacted, however some records belong to employees in China, the Philippines, and the United Kingdom. The total number of people who were exposed is 2,500, which corresponds to the company's seafaring and onshore workforce in 18 countries. The incident had no significant impact on SPO's global operations. It remains not exactly clear what the purpose of this attack was. The provider has taken quick efforts to strengthen current security measures and limit the incident's potential effect. SPO is also collaborating with data security specialists to investigate the attack and identify what additional actions may be required, and it will take all necessary efforts to secure its customers and employees now and in the future.