Lyon Shipyard in the U.S. encountered a ransomware breach in December 2024, reportedly carried out by LockBit 3.0.
Dec, 2024In December 2024, Delmar International in Canada was reportedly compromised by Rhysida ransomware, disrupting logistics activities.
Dec, 2024SeaLandAire Technologies in the U.S. faced a cyberattack by Hunters ransomware in December 2024, potentially disrupting aerospace projects.
Dec, 2024The Panama-flagged MR2 tanker Elkor (IMO: 9185499) was implicated in four distinct AIS spoofing incidents in the Sea of Japan between December 2024 and March 2025. During these voyages, the ship appeared to broadcast false location data, suggesting movement within international waters, while satellite imagery later confirmed it had docked at Vostochnyy port in Russia’s Far East, where clandestine loading took place. After broadcasting misleading positions for several days, Elkor backtracked along its route, and AIS draught readings indicated that cargo operations likely occurred during the spoofing window. This behavior is part of a broader pattern among non-designated "shadow fleet" tankers that use sophisticated spoofing tactics to mask sanctioned Russian oil exports, frequently transitioning to China following these covert operations
Nov, 2024Between November 6 and 11, a tanker named Atila carried out ship-to-ship transfers of Russian Urals crude in international waters, using spoofing techniques to disguise its location. This vessel, part of the "dark fleet," was involved with two sanctions-linked suezmaxes, Sakarya and Cankiri. These tankers had previously evaded sanctions by changing their management. The cargo was likely headed to China, a major buyer of Russian oil.
Nov, 2024In November 2024, a series of DDoS attacks by Russian hacktivist groups, including the Cyber Army of Russia Reborn (CARR), targeted ports such as the Port of Brisbane. These attacks, while unsophisticated, disrupted services by flooding websites with malicious traffic. The hacktivists are linked to state-backed cyber groups like APT44 (Sandworm), and while the attacks were not highly destructive, they pointed to vulnerabilities in maritime cybersecurity.
Nov, 2024The Akira Ransomware group have targeted the Norwegian Ship Services in November of 2024. The threat actor practices multi-extortion tactics and host a TOR-based website where victims are listed along with any stolen data if a victim fails to comply with the ransom demands. Since Ship Services is providing essential maritime services across a wide spectrum for 40 years, such an attack can disrupt their operations and have impact in the organizations' reputation.
Nov, 2024Multiple small gas carriers spoof their Automatic Identification System (AIS) signals to make it appear as if they loaded at Iraq's Khor al Zubair port, when in reality, the cargoes are originating from Iran. The manipulation occurred in November 2024 and is part of efforts to bypass sanctions, as ships create fake AIS trails or use more advanced tactics to disguise their true location. Additionally, forged Iraqi documents accompany the cargo, facilitating this illicit trade.
Nov, 2024The Halliburton cyberattack, disclosed in an SEC 8-K filing, disrupted operations following an unauthorized system breach on August 21, 2024. The company isolated affected systems, launched an internal and external investigation, and notified law enforcement. While the attack's specifics and extent remain unclear, Halliburton is working with cybersecurity experts to restore systems and ensure safety. This incident highlights the growing cyber threat to critical infrastructure and the energy sector’s need for robust defenses.
Nov, 2024The Darkvault ransomware group targeted UAE’s Nejoum Aljazeera in November 2024, threatening the integrity of its operational infrastructure.