In February 2021, the India based AllCargo Logistics (ECU Worldwide) experienced an ransomware attack on their online system. The attackers are the Mount locker ransomware gang. This cyber gang has advanced tactics to eventually deploy an certain kind of ransomware in the system that encrypts an steals files. With their campaign being financial gain, the hackers stole 2 terabytes of data, made communication impossible and shut down the emails system.
Feb, 2021In February 2021, France based Bénéteau Group experienced a malware attack on their computer system. The hackers probably used a phishing mail to implement the malware in the system, which then managed to slow down or stop the companies production in France for days. In order to stop the malware spreading, the company had to disconnect itself from all information systems. as a result of the attack, the IT Systems were shut down and the telephone system had been disabled. Bénéteau Group did not want to share many details about the attack, but its appears to bear the markings of ransomware assault.
Jan, 2021In January 2021, the Virgin Islands Port Authority was targeted by the Pysa ransomware group, leading to disruptions in its operations.
Jan, 2021In January 2021, the Norwegian aquaculture firm AKVA Group suffered a ransomware attack from an unknown group.
Dec, 2020In December 2020, AIDA cruise ships were suffering what was described as an immense IT problems that eventually lead to cancelling the New Years Eve cruises the company had arranged. In an email seen by BleepingComputer, Aida told passengers for the AIDAperla cruise ship that their trip was cancelled due to IT restrictions affecting the companies' phone systems and email. In addition, AIDA Cruises is displaying a message on their websites telling customers that it is not currently possible to reach them via phone or email. The company suspects that the problems are caused by a ransomware attack (DoppelPaymer).
Dec, 2020In 2020 a ransomware attack occurred on the Cruise Company Hurtigruten in Norway. The attack took place the 13th of December 2020 on two vessels named 'Fram and Midnatsol’. Customers' data (which includes names dates of birth, passport numbers, email addresses, and phone numbers) was reportedly stolen by hackers using a ransomware virus data assault. The data that was encrypted, had affected visitors who travelled onboard the Fram between 2018 and 2020 and for guests aboard the Midnatsol between 2016 and 2020. Also, the personal information of customers who have been treated by a medical provider during their stay on one of the two ships may have been affected by the attack. Unfortunately, the aim and threat actors of the incident are still unclear. Because of the attack, the enterprise was forced to take the website down. As you can see on the image below, the company's website displayed a message. The company notified appropriate authorities and filed a statement to the Oslo Stock Exchange after discovering the cyberattack on its servers. This cyberattack occurs as Norwegian organizations work together to establish a cyber resilience centre to aid shipowners and management in strengthening their defences. They work together to get an overview of the current situation and to keep the attack from spreading and causing harm.
Nov, 2020Port of Kennewick, USA was hit by a ransomware attack in November 2020. The attack was put in motion by sending a malicious e-mail to a company employee, followed by encryption of the company's files, locking servers and database for nearly a week. The port declared not to pay the demanded ransom. The port has had the same professional IT firm on contract for years and they've made regular upgrades on the port's servers.
Nov, 2020In November 2020, the AIS location of the USS Roosevelt naval vessel was spoofed. By fabricating the AIS locations of the USS Roosevelt, the threat actor Russia positions the navy vessel near the Russian enclave of Kaliningrad. While in reality the vessel is nowhere near the fabricated position and is actually somewhere else. The reason Russia does this, is provocation. This substantiates Russian aggressive behaviour in response to what appears to be a naval raid. In other words, these ghost readings could be about painting Russia as the victim of international prodding. There have been nearly a hundred of these incidents with NATO naval vessels.
Oct, 2020Shipping Company Matson was hit by a ransomware attack in Oakland, CA in October 2020 by REvil hacker group (Sodinokibi/Sodin), resulting in encryption of all the company's servers and files. Thereafter, hackers gave the company 72-hours to pay or the price would be doubled.
Sep, 2020One of the most popular ransomware attacks is the one on the large French Shipping Company CMA CGM. This cyber incident occurred in the end of September 2020 (Port Technology International Team, 2021). During the ransomware attack in September 2020, the cybercriminals from a group named ‘’Ragnar Locker Gang’’ stole personal data from clients using the Ragnar Locker ransomware and demanded a ransom before giving the data back to the company. In an email sent on the 27th of September and seen by researchers, the hacker requested the French carrier to contact it within two days via live chat and pay for the special decryption key. It was clear that the aim of the attack was financial gain. The exact price was not shared outside the company. Besides that, the company stated that their marine and port activities were still working normally. To prevent the ransomware from spreading to the rest of the worldwide network, the corporation quickly disabled its internet connection. As a result, all online booking services and requests for operations were suspended. For bookings and queries, customers were directed to their nearest local office. Even though the ports and boats remained operational, loading processes were hampered to some extent.