List View

Mar, 2018

GPS jamming in the Mediterranean Sea, by the coast of Cyprus

In March 2018, vessels' GPS were jammed in the Mediterranean Sea, by the coast of Cyprus. In this incident multiple Turkish jammers are simultaneously implemented to block around 16 miles away from Cyprus and Egypt in order to jam the petroleum search.

Mar, 2018

Vessel 'Wan Heng 11' and Russian-flagged 'Patriot' go dark in East China Sea

In March 2018, a Russia-flagged ship Patriot and UN-designated Wan Heng 11 went dark and conduct a ship-to-ship transfer together. After the transfer, the Patriot reappears with draft change, which indicates cargo discharge. The Wan Heng 11 vessel stays dark and discharges cargo in Nampo, DPRK. The goal was to conduct illegal coal and oil transfers.

Jan, 2018

Port of Longview, USA hit by hacking attack

In January 2018, the port of Longview, WA, USA, got hit by a hacking attack. In this attack a Kazakh hacker named Andrey Turchin (a.k.a. 'fxmsp') hacked two administrator accounts. The attack may have affected hundreds of past and current employees and dozens of vendors. The attack led to an estimated cost of $60.000. The attack had the potential to affect 370 past and current employees and 47 vendors. The attack may also have affected 22 longshoremen. Investigators traced the attack to internet service provider addresses in Russia, Liberia and Kazakhstan. Turchin faces five criminal counts, including conspiracy to commit computer hacking, computer fraud and abuse, conspiracy to commit wire fraud, and access device fraud. The most serious charge, conspiracy to commit wire fraud, carries a sentence of up to 20 years.

Jan, 2018

Naval Undersea Warfare Centre hit by malware attack in Newport (Rhode Island), USA

In January 2018, Naval Undersea Warfare Centre in Newport, Rhode Island was hit by a malware attack resulting in a data breach. Reportedly, hackers targeted a contractor who worked for the Naval Undersea Warfare Centre. As a result, hackers stole 614GB of highly sensitive data, including information about project Sea Dragon. The incident is believed to be part of a decade-long Chinese state sponsored hacking campaign nicknamed 'Winnti Umbrella', trying to compromise political targets.

Sep, 2017

Zvezda Shipyard in Vladivostok, Russia hit by DoS attack

In September in 2017, the Zvezda Shipyard's GNSS receivers reported incorrect location information at the Vladivostok International Airport. The Zvezda Shipyard is located 30 kilometres from Vladivostok, near the remote Russian Far East town of Bolshoy Kamen. President Putin paid a visit to Bolshoy Kamen on his final day, on September 8, in Vladivostok for the 2017 Eastern Economic Forum to view the newly built Zvezda Shipyard. At 1:30 p.m. local time, the official Kremlin website reported on the visit and the Russian President's speech according to C4ADS. The only vessel anchored at the shipyard reported faked positional information at the Vladivostok International Airport at around 1:24 p.m. local time. This is the first and only time in 2017 that GNSS spoofing has been identified near Bolshoy Kamen. The fact that the GNSS spoofing discovered near the Zvezda Shipyard was only brief and isolated strongly suggests that the equipment used to cause these disruptions was based on a mobile platform and capable of creating restricted zones of spoofing.

Jul, 2017

BW Group hit by hacking attack in Singapore

In July 2017, BW Group got hit by a hacking attack in Singapore. Gaps in cybersecurity made it possible for hackers to get in. The hacking attack resulted in operational interruption and business systems were temporarily inaccessible from outside Singapore. The active directory and GPO systems were affected and the problem was serious enough for Internet and Intranet systems to be closed down temporarily. The company also suffered financial loss.

Jul, 2017

Super Yacht of Chinese Billionaire hacked on Hudson River near New York City

In July 2017 the Super Yacht, Lady May, belonging to Chinese Billionaire Guo Wengui was disabled by a cyber attack on the Hudson River near New York City. Guo accused the Chinese government of being behind the attack. The attack disabled the control systems of the yacht. It is belived the compromise occured using Guo mobile phone. According to the chief engineer, the boat started having problems with Wi-Fi as soon as the owner stepped on board. Lady May was only able to regain control of the vessel after the SIM card was removed from Guo's phone.

Jun, 2017

Cofco hit by NotPetya Wiper virus in Argentina

Cofco got hit by NotPetya Wiper virus in Argentina in June 2017. The cyber attack can be traced to software updates from the Ukrainian accounting program M.E.Doc. Investigators from the security firm Talos travel to Ukraine to assist M.E.Doc in the to analyse their systems and to find out how the company has penetrated. N477It gradually appears that hackers become ingeniously managed to gain access for months to the systems of Intellect Service, the parent company of M.E.Doc. This is a software developer of, among other things, the accounting system M.E.Doc, which is frequently used to exchange with the Ukrainian tax authorities. By hiding the malware in the software update process, NotPetya went undetected into the networks of companies that used this software. Updates have been released with a backdoor, a hacker-made change to the M.E.Doc software, which allowed them to distribute NotPetya to customers of this software vendor. it hit Argentina on Wednesday. The attack led to operational interruption. Slowing wheat and fertilizer shipments and threatening to impact the flow of soybeans to the country’s main client, China, at the height of export season. Cofco is collateral damage of the attack first targeting Ukrainian Computer Systems, carried out by Russia (Sandworm Team, also known as Unit74455).

Jun, 2017

Vessel hit by spoofing attack in the Black Sea near Putin's visit at Turk Stream launch

In June 2017, at least 20 ships in the Black Sea near Novorossiysk Commercial Sea Port claimed that their Automatic Identification System incorrectly displayed their position as Gelendzhik Airport, about 32 kilometres inland. The large number of ships involved, as well as the fact that all the ships' tracking systems placed them in the same illogical location, prompted informed speculation, that the incident was caused by Russian testing of satellite navigation spoofing technology as part of its electronic warfare arsenal. It is reported that the incidents happened in order to protect Putin and to obfuscate his movements. It was also to protect secretive Russian areas.

Jun, 2017

A.P. Møller Maersk: Pipapav, ICD Dadri, CFS Nhava Sheva hit by NonPetya Wiper virus in Ukraine

In June 2017, shipping giant A.P. Møller Maersk got hit by a malware attack. During this incident a Wiper Virus (NotPetya) infected servers all across the globe. In total 65 countries have been infected. A vendor software update was the vehicle that carried the devastating NotPetya malware virus into Maersk's IT servers . The cyber attack can be traced to software updates from the Ukrainian accounting program M.E.Doc. Investigators from the security firm Talos travel to Ukraine to assist M.E.Doc in analysing their systems and to find out how the company has penetrated. It gradually appears that hackers become ingeniously managed to gain access for months to the systems of Intellect Service, the parent company of M.E.Doc. This is a software developer of, among other things, the accounting system M.E.Doc, which is frequently used to exchange with the Ukrainian tax authorities. By hiding the malware in the software update process, NotPetya went undetected into the networks of companies that used this software. Updates have been released with a backdoor, a hacker-made change to the M.E.Doc software, which allowed them to distribute NotPetya to customers of this software vendor. The impact was immense. In total there were 17 shipping container terminals affected in Ukraine, Russia, Germany, United States, United Kingdom, France, Denmark and The Netherlands. Maersk suffered $250 – 300 million financial loss and data contamination, delayed container deliveries and traffic jams in and around ports. About 4.000 servers, 45.000 computers and 2.500 applications had to be rebuild by Maersk. In the meantime, paper documents were glued on containers and orders were taken through personal G-mail accounts, WhatsApp and Excel files. The Russian Sandworm Team, also known as Unit74455 was behind this attack and the campaign was to disrupt Computer Systems across Ukraine. A.P. Møller Maersk along with other companies are collateral damage from this attack.