List View

Oct, 2018

Port of Vancouver hit by DDoS attack

In October 2018, the port of Vancouver got hit by a DDoS attack. nearly 225,000 user accounts were probed that day, though no further information was given on the consequences of this DDoS attack. By comparison, local port authorities admitted that they are probed this way every day, but never for more than 6,000 accounts at a time.

Oct, 2018

Government agencies in Ukraine and across Eastern Europe hit by a malware attack

In October 2018, government agencies in Ukraine and across Eastern Europe got hit by a malware attack orchestrated by the Carbanak Group (Russia) tied to the Russian FSB. The attackers were using a new phishing campaign, using deceptive emails to convince targets to click links and download malware. Attached to the emails were PDFs with links and other pieces of code that, when executed, would allow the attacker to steal or exfiltrate data and gain control over important computer functions. The attack was aimed at stealing information that would have been relevant to planning the operation. The information is related to Ukrainian foreign and naval affairs, information that would have been very useful if you wanted to engineer a maritime crisis.

Oct, 2018

Vessel hit by GPS interference near the Port of Jeddah in Saudi Arabia

In October 2018, vessels got hit by a GPS interference near the Port of Jeddah in Saudi Arabia. Before departure from port of Jeddah Saudi Arabia in Red Sea both GPS were found out of order. There seemed to be GPS signal interference resulting in loss of signal, missing COG / SOG and absence of GPS signals affecting bridge navigation and other communication equipment. The GPS screen showed no available satellites in the vicinity, no Lat/Long could be obtained. Another vessel lost GPS Signal on all nodes while they were approaching the Jeddah Port on 15/10/2018, 0530z. They checked with the out bound vessels and they too did not have GPS Signals. It is believed that it was jammed.

Oct, 2018

Vessel 'Lucky Star' dark activity in Songnim, North Korea

In October 2018, the vessel 'Lucky Star' goes dark in Songnim, North Korea. The goal was to trade coal during an illicit ship-to-ship transfer. The Navigation System of the vessel was turned off during the transfer.

Sep, 2018

Port of Barcelona hit by ransomware attack

On September 20, the port of Barcelona got hit by a Ryuk ransomware attack. The attackers use manual hacking techniques and open-source tools to move laterally through private networks and gain administrative access to as many systems as possible before initiating the file encryption. Once deployed, Ryuk encrypts all files except for those with the extensions dll, lnk, hrmlog, ini and exe. It also skips files stored in the Windows System32, Chrome, Mozilla, Internet Explorer and Recycle Bin directories. Ryuk uses strong file encryption based on AES-256. The attack only affected internal IT Systems, and did not affect any shipping movements in and out of the harbour.

Sep, 2018

Zvezda Shipyard in Vladivostok, Russia hit by DoS/GPS spoofing attack

In 2018, Putin returned to the Zvezda Shipyard. Again, the shipyard's GNSS receivers reported incorrect location information at the Vladivostok International Airport. The Zvezda Shipyard is located 30 kilometres from Vladivostok, near the remote Russian Far East town of Bolshoy Kamen. At the time of the president's afternoon visit to Vladivostok Airport, at least one ship based GNSS receiver positioned at the shipyard provided incorrect positioning information. The fact that the GNSS spoofing discovered near the Zvezda Shipyard was only brief and isolated strongly suggests that the equipment used to cause these disruptions was based on a mobile platform and capable of creating restricted zones of spoofing.

Sep, 2018

Port of San Diego hit by a ransomware attack

In September 2018, a medium-sized cargo port got hit by a ransomware attack in San Diego. The criminals, two Iranian hackers, Faramarz Shahi Savandi and Mohammad Mehdi Shah Mansouri, used a malware program called SamSam Ransomware, which is capable of encrypting data stored on a victim's Computer Systems. The attacker requested ransom in Bitcoin. The two men allegedly used a sophisticated approach to their attacks. They would research their targets online and scan for computer network vulnerabilities. When they struck, they would time the attack for night-time hours, when the victims would be least capable of mounting a defense, and would disguise their intrusions as normal network activity. They allegedly deployed an anonymized browsing and traffic routing service in an attempt to hide their tracks. No data loss occurred as a result of the attack, because the port's IT team had backups in place. The hack took down non-critical administrative systems for a brief period, and did not affect commercial port operations. The port did not pay the ransom demand.

Jul, 2018

COSCO shipping port in Long Beach, CA hit by ransomware attack

On the 24th of July 2018 COSCO Shipping’s Pier J terminal got hit by a ransomware attack at the Port of Long Beach and it affected lots of other countries, including the United States, Canada, Panama, Argentina, Brazil, Peru, Chile, and Uruguay. Which way the cyber criminals used to conduct ransomware on the company is . Luckily, the ransomware outbreak was limited to parts of North and South America and only the network and Computer Systems were affected. The company's main operating systems were not harmed as a result of the attack and because of that all of the ships are in good working order. To avoid further disruptions, the organization decided to shut down connections for a while with other locations, including networking phone and emails. To communicate with their clients, COSCO employees throughout the Americas have used Yahoo email accounts and social media . As well as the threat actors as the campaign of the incident remains . COSCO Shipping reported that it had been investigating and resolving network issues in the Americas.

Jun, 2018

Vessels hit by GPS spoofing attack near the Port of Shanghai in China

In June 2018, the whereabouts of nearly 300 vessels were faked. Fake signals caused ships to appear to be moving in ring patterns at short intervals. It shows ships jumping every few minutes to different locations on the circumference of large circles centred on a chemical manufacturing plant. While the disturbance affected ships all across Shanghai, the majority of those fooled were those traveling along the Huangpu River. Even the Huangpu Maritime Safety Administration (MSA), Shanghai's river police, has been vulnerable to spoofing assaults on a near-daily basis. Nobody knows who is responsible for this spoofing or what its ultimate goal is. These ships could be unsuspecting test subjects for a sophisticated electronic warfare system, or collateral damage in a struggle between environmental criminals and the Chinese government that has already cost the lives of dozens of ships.

May, 2018

GPS jamming during President Putin's visit at the Kerch Strait Bridge in Crimea, Russia

In May 2018, Putin led a caravan of construction vehicles across the bridge from Russia to Crimea to celebrate the occasion. At the time of the incident, AIS records for vessels in the Kerch Strait show that vessel transit through the straight was severely restricted. During this period, at least 24 vessels anchored in waters near the bridge sent faked GNSS positional data to the Anapa Airport, which is over 65 kilometres distant. Vehicles thought to belong to the FSO drove alongside Putin's construction truck convoy as it crossed the Kerch Bridge on the same day. A line-of-sight analysis of a GNSS spoofing device's possible range suggests that a spoofing transmitter based on one of the FSO vehicles at the Kerch bridge would likely be capable of targeting all vessels that reported spoofed position information. AIS statistics show that this was the only sustained spoofing disruption in Kerch in 2018. GNSS spoofing events detected in Russia are likely designed to deceive GNSS receivers on commercial drones to activate firmware-level geofence locks that prevent these drones from flying in restricted airspace such as an airport.