In June 2020, the in La Rochelle (France) based Fountaine-Pajot Yard experienced a hack in their computer systems. After the hackers worked their way in to the computer networks of the company, they blocked the usage and access to them. This way they managed to slow down the production at the French boat building sites. There is no clarification about the kind of ransomware that was used to block the Computer Systems, bet the goal of the hackers was financial gain.
May, 2020On May 9 2020, the port of Shahid Rajaee, Iran was hit by a cyberattack, causing transport chaos for days after crashing the facility’s Computer System. The cyberattack created kilometres-long line-ups of vehicles outside the port and vessels stuck in the harbour. Israel has been accused of launching the cyberattack, assumably as a retaliation for an earlier cyberattack on Israel a month earlier, following reports of possible Iranian involvement in this cyberattack on May 8 2020.
May, 2020On May 18 2020, Kowloon, Hong-Kong based ship manager Anglo-Eastern was hit by a ransomware attack, resulting in a part of the company's workstations and servers being encrypted. The company responded by taking down its servers in order to quarantine the malicious virus. Although, according to the company, it took days to recover the encrypted data, no data was lost eventually.
May, 2020BlueScope Steel, a company located in the Port of Kembla, USA, was hit by a ransomware attack in May 2020. The attack affected some of the company's IT System, mainly affecting manufacturing and sales operations in Australia, followed by disruption of business activities all across the country. BlueScope Steel's CFO said that the company's cyber security team had acted promptly to respond to the incident.
Apr, 2020In April 2020, The Geneva (Switzerland) based Mediterranean Shipping Company (MSC) experienced a malware attack on their servers. The malware-based attack was confined to a limited number of physical computer systems in the headquarters in Geneva only. The malware attack was based on an engineered targeted vulnerability. The attack caused a data centre outage. This resulted in the company’s digital booking tool to be offline. Also the company’s website was down. The effects lasted for about five days, denying customers access to said systems. With MSC not being the first shipping giant to get attacked, it is possible to see a growth in attacks on shipping giants overall.
Mar, 2020In March 2020, the port of Marseilles was hit by a ransomware attack (Mespinoza/Pysa), allegedly by hacker group Mespinoza. In this case, maritime infrastructures were not directly targeted, but were incidentally affected due to their interconnection with information systems in Aix-Marseille-Provence, which was the main target of the attack.
Feb, 2020In February 2020, freight brokerage Total Quality Logistics (TQL), based in Cincinnati, USA had hackers breach their IT Systems compromised sensitive information of possibly 85,000 carriers, including tax ID numbers and bank account numbers. This ultimately led to a carrier lawsuit alleging company's negligence in the hacking incident. The company insisted that the attack did not involve ransomware or malware of any kind. According to the company, its IT security teams identified the issue quickly and countered immediately to secure all online information.
Jan, 2020In January 2020, Melbourne (Australia) based Toll Group experienced a ransomware attack on their corporate server by the hack group Nefilim. The hackers used Mailto ransomware to encrypt the stolen data and decode the files so that they are useless. The goal of the hackers was clearly financial gain. Investigations shows that a total of 220 Gigabytes of data was stolen from one specific server. The data contains information about past- and present Toll Group employees. The firm refused to “settle” with the group.
Dec, 2019In December 2019, a spoofing incident occurred near Elba, Italy, temporarily affecting the Navigation System of 870+ vessels nearby. The affected vessels were spoofed and shown at incorrect time and location. Analyses pointed out that the AIS spoofing generator was located in the Elba Island area. Spoofing is increasingly becoming an issue in the maritime industry.
Dec, 2019In December 2019, Maritime Transportation Security Act (MTSA) regulated facility, based in the U.S., was hit by a ransomware (Ryuk) attack. As a result, company's operations shutdown for over 30 hours. USCG officials said they believe the point of entry was a malicious email sent to one of the maritime facility's employees. Once the link was clicked on by the employee, the company's IT servers got encrypted. The virus further burrowed into the industrial control systems that monitor and control cargo transfer and encrypted files critical to process operations. The impacts to the facility included a disruption of the entire corporate IT network (beyond the footprint of the facility), disruption of camera and physical access control systems, and loss of critical process control monitoring systems.