List View

Jun, 2012

United States Department of Homeland Security transportation worker Identification hit by hacking incident

In June 2012, the United States Department of Homeland Security transportation worker Identification was hit by an hacking incident. The attackers hacked at least one DHS-TWIC protected computer and downloaded its database schema. Team Digi7al Twitter account was used to make unlawful public disclosure. They did it because of boredom. The hackers found they were 'somewhat politically inclined to release the things [they had]'. Also because it was 'fun and we can'. The impact of the incident was theft of biometric and other sensitive personal information of transportation workers. Unlawful disclosure of database schema through Twitter, damaging DHS-TWIC's website by making it vulnerable to future attacks. The threat actor was TeamDigi7al (Nicholas Paul Knight, while on USS Harry S. Truman and Daniel Trenton Krueger). It is not exactly clear what measures the company took during and after the incident.

Apr, 2012

Oil terminals in Kharg Island, Iran hit by malware attack

In April 2012, oil terminals in Kharg Island, Iran got hit by malware attack. During this attack a Wiper malware entered in the internal Computer System causing equipment oil terminals disconnecting. The attack had affected several oil facilities and had damaged hard drive data. The websites of the Iranian oil ministry and national oil company had been knocked offline. Data about users of the sites had been stolen as a result of the attack. This attack was soft war by the West. The aim was to increase pressure so that Iran will compromise in the upcoming nuclear talks. Iran has mobilised a "cyber crisis committee" to handle the aftermath of the attack and bolster defences. The ministry appears to have been the initial target of the virus, which the Iranian authorities say they first noticed in March but apparently were unable to dismantle.

Apr, 2012

GPS jamming incident impacting 254 ships in South Korea

In 2012, a GPS jamming incident happened in South Korea. it was reported that 1,016 airplanes and 254 ships in South Korea experienced GPS disruptions during the 16 days’ (Apr 28 – May 13) 2012 North Korean jamming in 2012. The jamming also led to equipment oil terminals disconnecting, affected several oil facilities and had damaged hard drive data

Apr, 2012

Danish Maritime Authority hit by spear phishing attack

In April 2012, hackers from a foreign state made their way to the Danish Maritime Authority IT Systems in search of confidential information. The hacks targeted sensitive information on Danish shipping companies and the merchant navy. The hackers probably managed to gain access to the Danish Maritime Authority IT Systems by hiding a virus in a PDF document attached to an email sent to an employee of the Agency. When the employee opened the infected PDF file, hackers were given back-door access to the contents of his computer and the rest of the Maritime Authority’s network. They got access to an additional 13 PCs and a number of servers. From there, they were able to access the Business Ministry’s IT System. As a result of the hack, there was a disclosure of sensitive information. China is seen as the likely culprit, but the Chinese Embassy in Copenhagen denied that Chinese authorities had any knowledge of the hack.

Australian Customs and Border Protection Service Agency hit by hacking attack

In 2012, the Australian Customs and Border Protection Service Agency got hacked by a criminal syndicate. In this attack cybercriminals hacked the IT-systems. The hackers were able to see if their shipments were flagged as suspicious. In such cases, the smuggled goods were never picked up. The border agency lost control of the cargo systems during the hack. The campaign was to smuggle and traffic forbidden goods.

Jun, 2011

Port of Antwerp and Rotterdam hit by malware attack

In the year 2011-2013, the port of Antwerp and port of Rotterdam got hacked by Belgian hackers working for a drug cartel. In this incident the hackers obtained access at two container terminals by using spear phishing attacks, by sending e-mails with attachments containing Trojan directed at port authority workers and shipping companies. They were also breaking into offices to install Key-logging devices to capture passwords. Once the computers were under their control they could track ‘their’ containers, in order to arrange pick-ups. They did this by changing location and delivery times of the containers that had the drugs in them. Due to this attack containers (mostly including drugs) disappeared, the port had to pay €200.000 for countermeasures and the police seized 250kg of cocaine in a container leaving Antwerp for Holland, after discovering 114kg of the same drug in April. Illicit drugs and contraband worth approximately US$ 365 million, firearms and approximately US$ 1,5 million were seized when authorities finally became aware. In total 1044 kilos of cocaine as well as 1099 kilos of heroin has been seized by authorities and a dozen of suspects have been arrested.

Mar, 2011

GPS jamming incident in South Korea

In 2011, a GPS jamming incident happened in South Korea. In the 11 days (Mar 4–14) of large scale North Korean jamming attack there are reported GPS disruptions of 145 cell towers, 106 airplanes and 10 ships.

French submarine company DCNS hit by hacking attack in India

In 2011, the French submarine company DCNS was hit by hacking attack in India. An overseas actor hacked into their network, to conduct economic warfare. It resulted in the theft of 22.400 files including highly sensitive documents detailed the stealth capabilities as well as magnetic, electromagnetic and infrared data of the Scorpène-class vessel. It allowed the attackers to understand everything about the submarines: what speeds it can do, how noisy it is, what speeds the mast can be raised at, et cetera. The leak has raised doubts about the security of DCNS’s submarine project in Australia where it is locked in exclusive negotiations after seeing off rivals for a A$50 billion ($38 billion) contract to build the Barracuda next generation of submarines.

Aug, 2010

GPS jamming incident in South Korea

On August 23, in 2010 GPS disruptions, that were caused by North Korea, occurred in South Korea and affected 181 cell towers, 15 airplanes and one battle ship. The exact location where the disruptions have taken place were Kaesong, Gimpo and Paju. The attack lasted four days. To counter the attack, they are developing anti-jam programs.

Apr, 2010

Hyundai Merchant Marine hit by backdoor entry Fucobha

Hyundai Merchant Marine hit by backdoor entry Fucobha from April 2010 to 2013. The North Korean attackers relied on spear-phishing and exploits for known vulnerabilities. During the operation, the attackers were using the “Icefog” backdoor set (also known as “Fucobha”). "Icefog" is a small yet energetic APT group. Victims remain infected for months or even years and attackers are continuously exfiltrating data. It was a cyber-espionage campaign, named Kimsuky. Compromising the supply chain. Targeting government institutions, military contractors, maritime and shipbuilding groups, telecom operators, satellite operators, industrial and high technology companies and mass media. The intent of the attack was data theft., extracting documents, email account credentials as well as passwords allowing access to resources within the network.