On August 6, 2024, the Port of Tyne in the United Kingdom was targeted by a DDoS attack that caused its public website to become temporarily inaccessible. The hacktivist group RipperSec claimed responsibility for the attack. The Port of Tyne confirmed that operational systems, which are architecturally separated from the website, were not affected and all data remained safe and secure. Website accessibility was restored quickly and the port launched an investigation with relevant authorities. The Port of Tyne handles 5 million tonnes of cargo annually and serves as a major hub for offshore energy support.
Aug, 2024In August 2024, JAS Worldwide, a global freight forwarding and logistics provider headquartered in the United States, suffered a ransomware cyberattack that significantly disrupted its operations. The attack caused widespread delays in logistics and supply chain processes, severely affecting global operations. JAS Worldwide quickly engaged cybersecurity experts to contain the breach and initiate recovery efforts. By September 2024, essential systems were restored, and operations resumed.
Aug, 2024In August of 2024, a Russian LNG carrier, Pioneer, employed spoofing tactics to avoid detection in Norway's Arctic waters. After sending out false AIS signals, the vessel navigated undetected to the Arctic LNG 2 project, bypassing sanctions. The vessel's movements raise concerns about the use of "dark fleet" tactics to circumvent maritime regulations.
Aug, 2024August 2024 saw Italian marine services provider Albatros S.r.l. suffer a Helldown ransomware attack, likely causing operational disruptions.
Aug, 2024In August 2024, U.S.-based Keystone Engineering was targeted by Spacebears ransomware, possibly stalling marine engineering projects.
Aug, 2024The Djibouti Ports and Free Zones Authority was reportedly impacted by Ransomhub ransomware in August 2024, affecting port governance.
Aug, 2024On August 12, 2024, a ransomware attack hit the local network of the Central Port Authority of Rafina, without affecting the central systems of the Hellenic Port Authority. Some personal data of citizens and port staff may have been exposed, though no breaches have been confirmed. Authorities have implemented security measures and reaffirmed their commitment to data protection under GDPR.
Aug, 2024Between April and September 2024, two cargo vessels, Shahin and Almas, were identified as engaging in suspicious AIS behavior while conducting direct voyages from Iran to Houthi-controlled ports in Yemen. Shahin departed Bandar Abbas on April 18 and arrived in Saleef on May 1, shortly after reflagging from Tanzania to Comoros, while Almas was observed broadcasting AIS from both class A and B transponders around August–September 2024, suggesting attempts to obfuscate its movements. These voyages highlight ongoing tactics used to bypass arms embargoes and deliver military equipment, despite inspections by UNVIM in Djibouti. Experts warn that limited enforcement capacity and the removal of Saudi naval presence near Houthi ports since 2022 have allowed these activities to persist largely unchecked, contributing to renewed Houthi missile attacks on commercial shipping in the Red Sea.
Jul, 2024In June 2024, the Bulgarian Ports Infrastructure Company (BPIC) was targeted in an alleged cyberattack. Russian Cyber Army claimed responsibility for the disruptions to Bulgarian ports. However, the DDoS attack had minimal impact on operations, indicating the group's tactics were less effective than typical cyber warfare attacks.
Jul, 2024Mustang Panda, a threat actor, targeted cargo shipping companies in Europe in early 2024 using Korplug loaders. These loaders, dropped from USB drives with suspicious filenames, compromised systems in Norway, Greece, and the Netherlands. Some malware samples were blocked, but others had altered signatures and utilized DLL hijacking. The group also shares similarities with a separate actor, CeranaKeeper, which uses different tools like the TONESHELL backdoor. Both may have overlapping resources, but they operate independently.