List View

Apr, 2021

Shipping Company Bourbon Marine & Logistics hit by a suspected ransomware attack in Marseilles, France

In April 2021, Marseille (France) based Bourbon Marine & Logistics experienced an cyber-attack on their network and information systems. The result of the attack was the inability to access e-mail and other online applications. After an investigation, the company ensured that no data theft was found and no customer operations have been stopped. Efforts to restore all systems were ongoing.

Apr, 2021

Russian Defense corporation Rubin Central Design Bureau of Marine Engineering hit by malware attack in Saint Petersburg, Russia

In April 2021, the in saint Petersburg based Russian Defence Industry Rubin Central Design Bureau of Marine Engineering was attacked with the means of spear-phishing and PortDoor malware. With a malicious attachment in the form of an RTF-file, an previously unknown backdoor came into play. The campaign of the hackers (the Chinese communist party state-sponsored cyber-criminals) was to gain information about submarines that are designed by the company. Nonetheless, there was no impact.

Apr, 2021

Malaysian companies working Kasawari gas field in South China Sea victim of phishing campaign by Bejing-backed hackers TA423/Red Ladon

Mar, 2021

Carnival Corporation & PLC hit by a data breach in Miami, FL, USA

In March 2021, the Miami (Florida, USA) based Carnival Corp. experienced a data breach. The attackers used e-mail to get into the IT system of one cruise liner. There it gained access to personal information of staff and customers. On march 19th , the company detected the unauthorised access of a third party to limited proportions of the companies information systems. There appears to be evidence of a low likelihood of mis-usage of the stolen data being misused. This has been ransomware based attack that Carnival Corp. had to endure in a timespan of about two years.

Mar, 2021

CNA Inland and Ocean Marine Insurance hit by a ransomware attack in Chicago, IL, USA

In the ransomware attack on CNA Inland and Ocean Marine Insurance in March 2021 the cybercrime group used a form of ransomware named "Phoenix CryptoLocker ransomware", a spin-off of another malware "Hades" created by Russian hacking organization Evil Corp (Malwarebytes Labs, 2021). The ransomware appended the .phoenix extension on to files to encrypted them and make them inaccessible. One of CNA's employees was able to download and execute a fake browser update after visiting a legitimate website. The attackers used “additional malicious activity” to get credentials they need to move forward. The threat actors “copied, compressed and staged unstructured data obtained from file shares found on three CNA virtual servers; and used MEGAsync, a legitimate tool, to copy some of the unstructured data (“Exported Data”) from the CNA environment directly into the threat actor’s cloud-based account (the “Mega Account”) hosted by Mega NZ Limited (“Mega”). The ransomware caused network disruption and impacted certain CNA system, including corporate email. The threat actors also were able to steal important and sensitive information affecting 75,349 individuals. A significant number of them were names of current and former employees plus their dependents and their Social Security Numbers (SSNs). On the other hand, a small number of those affected had their birth dates, benefit enrolment, and medical information. Due to the exposure of valuable assets the company paid the ransom of $40 million. The reason for this group to attack CNA, is because CNA is a big insurance firm with a huge annual revenue. That means the company must have more than enough money to pay a large ransom. Also this group constantly rebrands their ransomware to evade US sanctions that withholds victims to pay the ransom.  

Mar, 2021

Shipping company K Line hit by malware attack in Japan

In March 2021, Japan based Kawasaki Kisen Kaisha (K Line) was attacked with the use of malware. There had been an unauthorised access to the overseas subsidiary systems. Also malware infection was introduced on local IT environment. The impact of the attack lead to temporarily shut down of the companies enterprise systems and its external connections. System disruptions took place as well. It took until April 21st before the company could report that the recovery had been completed.

Feb, 2021

American Bureau of Shipping Faces Clop Ransomware Attack

In February 2021, the American Bureau of Shipping fell victim to a Clop ransomware attack, affecting its digital infrastructure.

Feb, 2021

Beneteau Suffers a Ransomware Attack in February 2021

In February 2021, French boat manufacturer Beneteau experienced a ransomware attack from an unknown source.

Feb, 2021

Transport for NSW Targeted by Clop Ransomware

In February 2021, Transport for NSW, was breached by Clop ransomware.

Feb, 2021

Nine Swedish Navy vessels hit by AIS spoofing attack in the Baltic Sea

In February 2021, the AIS location of nine Swedish naval vessels was spoofed. By fabricating the AIS locations of the 9 Swedish Navy vessels, the threat actor Russia positions the navy vessels near the Russian enclave of Kaliningrad. While in reality the vessels are nowhere near the fabricated positions and are actually somewhere else. The reason Russia does this, is provocation. This substantiates Russian aggressive behaviour in response to what appears to be a naval raid. In other words, these ghost readings could be about painting Russia as the victim of international prodding. There have been nearly a hundred of these incidents with NATO naval vessels.