Skip to content
Search AI Powered

Latest Stories

Press releases are provided by companies as is and have not been edited or checked for accuracy. Any queries should be directed to the company issuing the release.

Resilience360 Quantifies Impact of Ocean Carrier Cyberattacks

Recent cyber-attacks on ocean carriers have proven quite disruptive.

Recent cyber-attacks on ocean carriers have proven quite disruptive. Denmark’s Maersk Line incurred estimated damages of USD 300 million (EUR 253.81 million) due to the global ransomware attack it suffered in 2017. The latest attack on CMA CGM means that all the Big 4 shipping lines, including MSC and COSCO, have suffered recent disruptive cyber events. On October 1, the International Maritime Organization (IMO) also announced a cyber-attack against its IT systems, leading to disruptions in its public website and internal systems.

“Companies shipping by sea should remain vigilant of cyber intrusions that target shipping lines,” said Daniel Boccio, Supply Chain Risk Analyst, Resilience360. “Supply chain managers and IT professionals should collaborate on identifying the potential vulnerabilities and threats to their supply chains and should implement measures to increase resiliency and minimize the impact of such threats.”


On September 28, French container transportation and shipping company CMA CGM announced that it fell victim to a cyber-attack on its peripheral servers. The company has over 480 vessels, operating 200 shipping routes between 420 ports in 150 different countries. The attack led to limited IT availability across the group, sans CEVA Logistics, due to the company halting external access to applications to prevent the spread of the malware. The company later announced that it also suspects a data breach and the nature and the volume of the affected information.

Based on an assessment of the attack on the company’s China offices, preliminary assessments conclude that the attack is the work of the Ragnar Locker ransomware. In operation since December 2019, this ransomware acts in a typical manner of the Cyber Kill Chain, performing reconnaissance and exfiltrating sensitive information to be returned in exchange for ransom payment. The ransomware can be identified with an MD5 hash of 6171000983CF3896D167E0D8AA9B94BA, which serves as the primary indicator of compromise (IoC) for the threat. It is delivered as an unsigned MSI package and is known to attack Windows systems via VirtualBox.

The ransomware’s peripheral device discovery feature allows it to spread rapidly to removable and mapped network drives, explaining CMA CGM’s decision to temporarily disable external features. Notably, the ransomware has a unicode string comparison function that, when activated, prevents the ransomware from executing on computers using languages from the former Soviet Union, such as Belorussian, Azerbaijani, Ukrainian, Moldovan, Georgia, Armenian, Turkmen, Russian, Kyrgyz, Kazakh, Uzbek, and Tajik. Ragnar Locker was last seen attacking the EDP energy company in April 2020.

Given the ransomware’s peripheral device discovery feature, the company suspended its booking system to protect its customers. The suspension disrupted operations as employees lost access to internal e-mails and applications necessary to perform daily operations, with limited options for customer communications by phone. The company suspended access to electronic bookings through its websites and announced that all cargo booked before September 27 was secure; however, later bookings were yet to be processed. The company also requested customers to either call local offices or make bookings through an external booking system.

Company services at Chinese offices in Shanghai, Guangzhou, and Shenzhen were reportedly disrupted, with container terminal managers stating that cargo loading operations were likely to be affected, but ultimately were not. Fortunately, sources at Hong Kong Port stated that CMA CGM maintained normal operations at both the container terminal and on its vessels. On September 30, the company announced that operations were gradually returning to normal, with improvements to bookings and documentation processing times as back-offices reconnect to the network. Moreover, the company assured customers that maritime and port activities are fully operational, with alternative and temporary processes available for bookings.

Ragnar Locker not only targets entities of considerable logistics and industrial importance, such as EDP and CMA CGM, but also exploits VirtualBox. This is indicative of a greater threat posed to companies employing virtualization, and to an extent, remote services. Such a threat is even more notable with the considerable quantity of remote workers this year due to the COVID-19 pandemic.

While technological recovery is quick, residual business disruptions are likely, especially regarding time-sensitive shipments.

https://www.resilience360.dhl.com/news/ransomware-attack-on-french-carrier-cma-cgm-disrupts-shipping-operations/

https://www.resilience360.dhl.com/news/ransomware-attack-on-french-carrier-cma-cgm-disrupts-shipping-operations/

The Latest

More Stories

Mitsubishi Logisnext Americas Group Announces UniCarriers® Forklifts’ Premier Club Winners for 2024

MARENGO, Ill. (Feb. 19, 2025)Mitsubishi Logisnext Americas, the exclusive manufacturer and provider of UniCarriers® Forklifts across North, Central and South America, proudly announces the winners of its Premier Club Awards for2024. This prestigious program honors the top nine UniCarriers Forklifts dealers throughout the Americas who exemplify the brand’s commitment to excellence, performance and customer satisfaction.

Each year, Premier Club winners set the highest standards in dealership professionalism, consistently exceeding expectations in market performance, aftermarket parts sales, new equipment sales, and overall service quality. Their dedication to innovation and reliability continues to elevate the UniCarriers brand and inspire the entire dealer network.

Keep ReadingShow less

Featured

kion linde tugger truck
Lift Trucks, Personnel & Burden Carriers

Kion Group plans layoffs in cost-cutting plan

photo of exotec as/rs

Exotec Launches Next Generation of Skypod System, an All-in-One Robot-Based AS/RS

Atlanta, GA, Feb 6, 2025 - Today Exotec®︎, a global warehouse robotics provider, announced the commercial launch of the Next Generation of Skypod®︎ system with higher performance, improved storage density, and advanced software features.

The Next Generation of Skypod comes with a number of design improvements including a new and more compact Skypod robot, a workstation for robot-to-robot picking, high-throughput Exchanger, and denser storage. These redesigns combined with new software features improve the throughput at a single workstation by 50% while also enhancing storage density up to 30% compared to the previous generation.

Keep ReadingShow less

Vanderlande to Showcase How to Automate Your Warehouse Success at ProMat 2025

ATLANTA– February 5, 2025Vanderlande, the global partner for future-proof warehouse solutions, today invited ProMat 2025 attendees to visit booth #S1503 to learn more about the fully integrated technologies, best-of-breed solutions and comprehensive services available to warehousing operations regardless of where they are in their automation journeys. Vanderlande experts will also present two interactive conference seminars that will draw on real-world examples and lessons learned to show attendees how they can successfully deploy automation for the faster and more efficient warehousing needed to stay competitive and thrive.

Known for providing leading global brands with the most advanced distribution centers (DCs), Vanderlande offers the fully-integrated and comprehensive suite of solutions dynamic retailers, including omnichannel brands and e-commerce companies in the general merchandise, apparel and food sectors, need to excel. The company’s automation technologies encompass the systems, software, robotics and services needed to optimize throughput, order accuracy and storage capacity in the most demanding fulfillment and store replenishment operations.

Keep ReadingShow less

Warp Announces Preparation for U.S. Government Partnership to Enhance Service and Efficiency

Los Angeles, CA, Jan. 29, 2025 (GLOBE NEWSWIRE) -- Warp, a tech-powered network of cross-docks and carriers offering various vehicle sizes, announced that 2025 it will extend its solutions and services to the U.S. government. Warp aims to modernize government freight logistics with machine-learning-driven planning, optimized network strategies, and flexible solutions to create efficient, cost-effective, and sustainable supply chain transportation.

Focused on optimizing every load, every time, Warp employs machine learning (ML), artificial intelligence (AI), and groundbreaking consolidation techniques to blur the traditional lines of freight shipping by combining the best elements of LTL, FTL, and parcel delivery. Using its homogenous fleet including cargo vans, sedans, box trucks, and 53-foot trailers, Warp facilitates carrier injections, inbound vendor consolidation, pool point distribution, zone-skipping, store replenishment, and national retail distribution for some of the world’s largest shippers.

Keep ReadingShow less
Toyota Material Handling MidSouth’s Forklift Donation Raises $40,000 for Higher Education

Toyota Material Handling and Toyota Material Handling MidSouth partner to donate 5,000-pound-capacity pneumatic forklift at Concrete Industry Management’s annual charity auction.

Photo courtesy of Toyota Material Handling

Toyota Material Handling MidSouth’s Forklift Donation Raises $40,000 for Higher Education

LAS VEGAS, Jan. 28, 2024 – Toyota Material Handling MidSouth, a full-service dealer for Toyota Material Handling, showcased its dedication to fostering the next generation of industry professionals by donating a 5,000-pound-capacity Toyota Core IC Pneumatic forklift to the Concrete Industry Management’s (CIM) annual charity auction on January 22.

The forklift’s winning bid of $40,000 significantly contributed to the auction’s total proceeds of $2.15 million, supporting CIM’s mission to address the growing demand for skilled professionals in the concrete industry. Offered at five universities, CIM equips students with technical, communication and management expertise, preparing them for successful careers in a rapidly evolving industry. Proceeds from the auction are used to assist CIM in funding higher education programs that offer degrees in concrete industry management.

Keep ReadingShow less