On December 30th, 2019 London Offshore Consultants, based in London, UK was hit by a ransomware attack claimed by Maze Group. As a result, 400 employees saw their computers freeze. The hackers claimed to have stolen 300GB of the company's data. According to the FBI, Maze Group usually appears to use multiple methods for intrusion, including the creation of malicious look-a-like cryptocurrency sites and malware email campaigns impersonating government agencies and well-known security vendors. In this particular case, the hackers published samples of the stolen data on its website, and demanded a ransom of $6,1 million in bitcoin. Although it's required to alert authorities within 72-hours after a cyberattack has occurred, SkyNews reported the shipping firm alerted the authorities two weeks after the incident. It is unclear whether the company has paid the ransom.
Dec, 2019In December 2019, the Terminal do Mucuripe at the Port of Fortaleza (Ceará, Brazil) suffered a cyberattack that disabled key port-operation IT systems. Systems responsible for truck flow, cargo entry, container logistics, and documentation became unavailable.
Nov, 2019In November 2019, shipping firm James Fisher and Sons PLC, based in Barrow-in-Furness, UK was hit by a ransomware attack in Barrow-in-Furness, UK. Hackers gained unauthorized access to the company's Computer Systems. The company shortly after disconnected all affected systems as a precautionary measure. According to the company, no data was lost eventually. As a result of the incident, the company's market shares decreased by 5.7%.
Oct, 2019GPS spoofing impacting shipping has been detected in over 20 Chinese coastal sites during 2019, including the port of Quanzhou (Shiyucun), possibly as a reaction to increased scrutiny of Iranian crude imports by the U.S. One oil terminal was affected by the incident. Ship traffic appeared in a infamous crop circle as a result of spoofing.
Sep, 2019In the night between September 25 and 26, 2020 Malta Maritime Regulator Transport Malta was hit by a cyberattack, grounding all of the company's IT Systems, making it impossible for anyone to use the agency's services. Motorists have been unable to renew their road licence and avail themselves from the services of the authority as a result of the attack. It took the company five days to get the affected systems back up, but authorities did not confirm whether any personal information had been compromised. It remains a mystery who was behind the attack.
Jul, 2019In July 2019, multiple ships are proven to have conducted in illicit ship-to-ship transfers helping DPRK evade UN import/export sanctions. In the act, the ships went dark by turning off their AIS-transmitters. This behaviour has been going on for years and there are numerous vessels involved.
Jul, 2019In July 2019, British-flagged tanker Stena Impero was reportedly fallen victim to an alleged GPS spoofing incident in the Strait of Hormuz, Iran, resulting in the vessel violating maritime regulations. Subsequently, the vessel got seized by Iran's Revolutionary Guards. The crew of the vessel, 19 in total, were held in confinement for over 19 days. Afterwards, Britain's MI6 has investigated the incident and proclaims that Iran and/or Russia could be involved in purposefully spoofing the ship into Iranian waters. The incident is considered a follow-up of the seizure of an Iranian ship by the Britain in Gibraltar two weeks earlier. The region is considered to be a high risk area for vessels. In 2016, a similar incident occurred were two U.S. Navy ships were allegedly spoofed into Iranian waters as well before getting seized by Iran's Revolutionary Guards.
Jun, 2019On June 5, 2019 an incident took place in which more than 10 ships, located all around the globe, were spoofed into a infamous crop circle near the coast of California's Point Reyes, U.S. So far it remains a mystery why these circling AIS tracks are appearing specifically at Point Reyes and a few other locations.
Jun, 2019On September 5th, 2019 a spoofing incident occurred in the port of Dalian, China. An oil tanker by the name of Jin Nui Zou, owned by the China Shipping Tanker Company Ltd, entered the Port of Dalian oil terminal in Northeast China that day. Dalian is the headquarters of two subsidiaries of COSCO shipping which were sanctioned by the U.S. government for importing Iranian crude oil. AIS tracking of the Jin Nui Zou shows it entered the Port of Dalian on a normal course. As the ship approached the terminal from the southeast, however, the vessel's AIS positions suddenly scatter throughout the port with some showing the vessel traveling at a very high speed. Eventually the vessel's AIS positions settle into a circular pattern centred around a location inside of the oil terminal tank field—on land. PS spoofing impacting shipping has been detected in over 20 Chinese coastal sites during 2019, including the port of Dalian, possibly as a reaction to increased scrutiny of Iranian crude imports by the U.S. Ship traffic appeared in a infamous crop circle as a result of spoofing. A total of 9 oil terminals in two separate terminal area's were affected by the spoofing incident.
May, 2019In May 2019, shipping firm Princess Cruises & Holland America Cruise Line, a part of Carnival Corp. was hit by a ransomware attack in Florida, USA. Hackers gained unauthorized access to a company employee's account and encrypted a part of the company's IT Systems. After compromising the account and watching the company's email traffic, the hacker allegedly was able to identify potential targets.