Maritime companies that provide ship and port management services hit by a spear-phishing attack in 2017-2018. The attackers took advantage of the industry’s lax security and the use of outdated computers. Business email compromise (BEC) and business email spoofing (BES) fraud to dupe their victims into parting with funds. The attackers are focusing on global maritime shipping businesses and their customers. Messages are crafted to appear to be legitimate employees, contacts, or other companies, are utilized to lure victims into a false sense of security. These kinds of scams will often attempt to persuade users to download malicious documents containing malware payloads or to visit malicious web pages which harvest credentials. When these credentials are stolen, threat actors can then intercept genuine business email exchanges, alter orders or financial details, and quietly reap the rewards. The threat actors use a wide range of tools after they have compromised accounts belonging to these companies. These include remote access software, keyloggers, and password stealers, many of which are available online publicly and with little investment. The threat actor utilizes tools including EmailPicky to scrape fresh victims from email contact lists, Predator Pain, PonyStealer, Agent Tesla, and HawkEye keyloggers. When it is time for payment details to be relayed to the buyer through an invoice, the threat actor intercepts the seller’s email and changes the destination bank account on the invoice to their money mule account. The attackers allegedly stole hundreds of thousands US dollars. They attempted to steal a minimum of $3.9 million U.S. dollars from maritime shipping businesses and their customers, while theft attempts average $6.7 million per year. The group behind this attack is called the Gold Galleon Group (Nigeria), consisting of 20 cybercriminals.
May, 2017Clarksons Shipbroker got hit by a hacking attack in the UK. Through the forensic investigation, Clarksons quickly learned that an unauthorized third party had gained access to its system from May 31, 2017 until November 4, 2017. The unauthorized third party accessed certain Clarkson PLC information systems through a single, isolated user account in the UK, then copied data and demanded a ransom for his safe return. The data, which the perpetrator copied and demanded ransom for return, included: date of birth, contact information, medical information, tax information, insurance information, social security number, resume, driver license information, bank account data, passport information, payment card information, ethnicity, digital signature, financial information, and criminal background information. The stock value decreased by 5% immediately after the incident. Clarksons said that it had been working with data security specialists to investigate the matter further. It is understood that it refused to do a deal with the blackmailer, hence its warning that some data might enter the public domain
May, 2017Svitzer Marine Solution got hit by e-mail forwarding attack in Australia. In this attack up to 60,000 emails from three accounts in finance, payroll and operations were secretly auto-forwarded to two external accounts between May 27 2017 and March 1 2018. This resulted in data theft, affecting almost half of the companies Australian employees. The 60,000 emails contained information on employees including tax file numbers, next of kin details, and superannuation account information. The forwarded emails originated from the company’s operating department, financial department and payroll office. It impacted more than 400 employees at the Shipping Company.
Mar, 2017In March 2017, the port of Vancouver got hit by Malware, DoS attack. An attendee of the standing-room-only crowd unknowingly had a virus on their computer, and once the computer connected to the port’s Wi-Fi, the virus started attacking the port’s network. A live feed of the meeting being played in an overflow room started experiencing problems. The staff was able to get it fixed by noon. Until the port made adjustments to its Computer System, it was getting hundreds of denial-of-service attacks per week. The port regularly experiences denial-of-service attacks, though typically not from someone inside the building.
Feb, 2017In February 2017, a container vessel got hit by a hacking attack en route from Cyprus to Djibouti. The attackers, African pirates, firstly wanted to gain full control of the vessel Navigation Systems and then direct the ship to an area where they could take complete control of the ship. Due to the hack the ship couldn’t manoeuvre and the hackers took full control of ship for 10 hours. The crew attempted to regain control of the Navigation System but had to bring IT experts on board, who eventually managed to get them running again after hours of work. The availability and integrity of the CIA model would have been compromised if the vessel was completely controlled by the cyber pirates.
Oct, 2016In October 2016, the US Navy and Hewlett-Packard Enterprise were involved in a data breach. The data breach involved a compromised laptop belonging to an Hewlett Packard Enterprise Services employee working on a U.S. Navy contract. individuals accessed the sensitive information on current and former sailors. The lost data related to the Career Waypoints database, known as C-WAY, which sailors use to submit requests to reenlist as well as requests relating to the Navy Occupational Specialty, which catalogues skills and primary jobs. The impact contains leaked personal data, including names and social security numbers of 134.386 US navy sailors.
Sep, 2016In September 2019, ships docked at Kerch Port received incorrect positional information from the Simferopol Airport in Crimea, which is over 200 kilometres distant. During that time, the Russian President and Prime Minister visited Kerch for a single day on September 15, 2016, to assess progress on the Kerch Bridge. This was the first GNSS spoofing incident in the vicinity of Kerch, and the only one in 2016. GNSS spoofing events detected in Russia are likely designed to deceive GNSS receivers on commercial drones to activate firmware-level geofence locks that prevent these drones from flying in restricted airspace such as an airport.
Aug, 2016in August 2016, U.S. ports and 13 organizations’ port authorities and logistics operators worldwide using Navis Webacces got hit by a SQL injection. In this attack the hacker released a fully working exploit online without notifying the vendor in advance. The hacker was able to view/ modify/ delete data. In 2016 an ethical hacker "bRpsd" revealed that Navis WebAccess - a web-based app that provides transport operators real-time access to operational logistics information - was highly vulnerable to a critical SQL injection vulnerability. (CVE-2016-5817) A vulnerability that could be exploited by a remote attacker to read or modify data stored in the application’s database. The patch management was well-timed, the software vendor, Navis, was informed about the vulnerability on August 9, just a day after Rpsd published the PoC exploit. Navis released custom patches on August 10.
Jun, 2016In June 2016, a small company (50-person aerospace engineering firm) in the network of the Australian defence industry got hit by a malware attack in Australia. The attackers exploited a 12-month-old vulnerability in the company’s IT Helpdesk Portal using 'China Chopper'. Those same administrative credentials gave the attacker access to the domain controller and the remote desktop server, and to email and other sensitive information. The attackers had full and unfettered access to detailed information on some of the nation’s major military defence systems – aircraft, bombs and naval vessels. The attackers exfiltrated about 30GB of data including, restricted technical information on the F-35 Joint Strike Fighter, the P-8 Poseidon maritime patrol aircraft, the C-130 transport aircraft, the Joint Direct Attack Munition (JDAM) smart bomb kit, and a few Australian naval vessels. It is uncertain who the attackers are, but it is believed to be China.
Jun, 2016In the period between January 2018 and April 2019, research was concluded into potential Illegal, Unreported and Unregulated (IUU) fishing activities near Argentina's EEZ. The research showed large scale dark activity among the hundreds of fishing vessels active in the region during that time. The vessels were mostly part of China's distant-water fleets fishing for squid. The vessels combined a total of 900,000 fishing hours, in which 600,000 hours AIS-transmitters were turned off.