In November 2021, an ransomware attack on the communication systems of Danaos Management Consultants took place. Danaos Management Consultants is based in Piraeus in Greater Athens (Greece). The victims, consisting of several Greek shipping companies, became unable to communicate with other actors within the business. There was a loss of important files and less then 10% of the external customers had their files encrypted due to the attack. Because of the attack, Danaos sent out instructions to clients in order for them to back up important files.
Oct, 2021In October 2021, the Facebook page of warship the USS Kidd was hacked by an unknown actor. How and why the hack had taken place is unclear, since the hacker only steamed its gameplay of the game ‘Age of Empires’ on the page. It took about four days to regain control over the Facebook page. During these four days, the USS Kidd had no control over the Facebook page.
Oct, 2021In October 2021, , South-Korea based Daewoo Shipbuilding & Marine Engineering got hacked, again. For the third time, the North-Korean hackers, hacked into the computer systems of DSME. According to DSME no data was compromised, although it is unclear if any of the attacks has been successful in reaching sensitive information.
Sep, 2021In September 2021, the AIS data of the Russian WARSHIP 545 (a Steregushchiy-class corvette) was altered to falsely indicate its movement from the Russian Baltic Fleet’s base in Baltiysk into Lithuanian waters near Klaipeda. In this incident, the fake AIS track was also amplified by a disinformation campaign, with a fabricated news article claiming an unprecedented provocation by Russian warships near Lithuania. The fake news website had headline “Dangerous deception over Russian warships near Klaipeda: there has never been such a provocation against Lithuania”
Sep, 2021In September 2021, France based CMA CGM experienced a cyber-attack on their network with the usage of hacking and ransomware. The hackers used Ragnar Locker ransomware to steal and encrypt stolen customer data. In response to the attack, the company immediately shut down its access to the internet in order to stop further spreading of the ransomware to the rest of the global network. As a result, all online booking services and operation requests were shut down. Customers were asked to contact their nearest local office for bookings and inquiries. Also the ports and vessels were partially impacted. After the company refused to pay the ransom, all data was leaked.
Aug, 2021In August 2021, Petrologis Canarias suffered a ransomware attack by LockBit 2.0, impacting fuel supply operations.
Aug, 2021In August 2021, Tokio Marine Insurance Singapore Ltd. (TMiS), a subsidiary of the Tokio Marine Group, fell victim to a ransomware attack. The company detected the intrusion promptly and took swift action, including isolating its network to contain the threat and prevent further damage. Authorities were notified immediately, and an investigation was launched. Tokio Marine engaged external cybersecurity experts to assess the impact and ensure the integrity of its systems. Fortunately, no evidence of customer data breaches or leaks of confidential company information was found. The attack was confined solely to TMiS, with no impact reported on other Tokio Marine Group entities.
Aug, 2021In August 2021, the port of Houston (USA) experienced a attack on its computer network. The tried to exploited zero-day flaw, with means the flaw is not yet known to the software creator. The hacker, who appears to be a nation-state actor, had as goal to gain sensitive government information and disrupt/end the operations. By following the facilities security plan no operational data or systems were impacted.
Aug, 2021In August 2021, the Norway based Institute of marine research experienced an attack on their undersea sensors. The Russian saboteurs managed to physically cut and drag underwater surveillance equipment away from its position, thereby destroying the sensors and making it impossible for the institute to monitor activities underwater. The reason the saboteurs did this, is to create a military strategic advantage. Because now, the Russians can move around the area with their submarines, without the Norwegians knowing about it.
Jul, 2021In July 2021, South-Africa based Transnet SOC Ltd. Experienced a ransomware cyber-attack on their computer- and NAVIS System. The Blackmatter ransomware group used Death Kitty ransomware to attack the system and gain information. The attack resulted in computer systems being unusable, halted port operations, no movement of cargo, website down and the staff had to switch to manual paper and pen work. The reason for Blackmatter to attack Transnet SOC Ltd., is financial gain.