Skip to content
Search AI Powered

Latest Stories

Press releases are provided by companies as is and have not been edited or checked for accuracy. Any queries should be directed to the company issuing the release.

Resilience360 Quantifies Impact of Ocean Carrier Cyberattacks

Recent cyber-attacks on ocean carriers have proven quite disruptive.

Recent cyber-attacks on ocean carriers have proven quite disruptive. Denmark’s Maersk Line incurred estimated damages of USD 300 million (EUR 253.81 million) due to the global ransomware attack it suffered in 2017. The latest attack on CMA CGM means that all the Big 4 shipping lines, including MSC and COSCO, have suffered recent disruptive cyber events. On October 1, the International Maritime Organization (IMO) also announced a cyber-attack against its IT systems, leading to disruptions in its public website and internal systems.

“Companies shipping by sea should remain vigilant of cyber intrusions that target shipping lines,” said Daniel Boccio, Supply Chain Risk Analyst, Resilience360. “Supply chain managers and IT professionals should collaborate on identifying the potential vulnerabilities and threats to their supply chains and should implement measures to increase resiliency and minimize the impact of such threats.”


On September 28, French container transportation and shipping company CMA CGM announced that it fell victim to a cyber-attack on its peripheral servers. The company has over 480 vessels, operating 200 shipping routes between 420 ports in 150 different countries. The attack led to limited IT availability across the group, sans CEVA Logistics, due to the company halting external access to applications to prevent the spread of the malware. The company later announced that it also suspects a data breach and the nature and the volume of the affected information.

Based on an assessment of the attack on the company’s China offices, preliminary assessments conclude that the attack is the work of the Ragnar Locker ransomware. In operation since December 2019, this ransomware acts in a typical manner of the Cyber Kill Chain, performing reconnaissance and exfiltrating sensitive information to be returned in exchange for ransom payment. The ransomware can be identified with an MD5 hash of 6171000983CF3896D167E0D8AA9B94BA, which serves as the primary indicator of compromise (IoC) for the threat. It is delivered as an unsigned MSI package and is known to attack Windows systems via VirtualBox.

The ransomware’s peripheral device discovery feature allows it to spread rapidly to removable and mapped network drives, explaining CMA CGM’s decision to temporarily disable external features. Notably, the ransomware has a unicode string comparison function that, when activated, prevents the ransomware from executing on computers using languages from the former Soviet Union, such as Belorussian, Azerbaijani, Ukrainian, Moldovan, Georgia, Armenian, Turkmen, Russian, Kyrgyz, Kazakh, Uzbek, and Tajik. Ragnar Locker was last seen attacking the EDP energy company in April 2020.

Given the ransomware’s peripheral device discovery feature, the company suspended its booking system to protect its customers. The suspension disrupted operations as employees lost access to internal e-mails and applications necessary to perform daily operations, with limited options for customer communications by phone. The company suspended access to electronic bookings through its websites and announced that all cargo booked before September 27 was secure; however, later bookings were yet to be processed. The company also requested customers to either call local offices or make bookings through an external booking system.

Company services at Chinese offices in Shanghai, Guangzhou, and Shenzhen were reportedly disrupted, with container terminal managers stating that cargo loading operations were likely to be affected, but ultimately were not. Fortunately, sources at Hong Kong Port stated that CMA CGM maintained normal operations at both the container terminal and on its vessels. On September 30, the company announced that operations were gradually returning to normal, with improvements to bookings and documentation processing times as back-offices reconnect to the network. Moreover, the company assured customers that maritime and port activities are fully operational, with alternative and temporary processes available for bookings.

Ragnar Locker not only targets entities of considerable logistics and industrial importance, such as EDP and CMA CGM, but also exploits VirtualBox. This is indicative of a greater threat posed to companies employing virtualization, and to an extent, remote services. Such a threat is even more notable with the considerable quantity of remote workers this year due to the COVID-19 pandemic.

While technological recovery is quick, residual business disruptions are likely, especially regarding time-sensitive shipments.

https://www.resilience360.dhl.com/news/ransomware-attack-on-french-carrier-cma-cgm-disrupts-shipping-operations/

https://www.resilience360.dhl.com/news/ransomware-attack-on-french-carrier-cma-cgm-disrupts-shipping-operations/

The Latest

More Stories

Armlogi expands shipping capabilities with Amazon Shipping integration

WALNUT, CA, Jan. 17, 2025 (GLOBE NEWSWIRE) -- Armlogi Holding Corp. (“Armlogi” or the “Company”) (Nasdaq: BTOC), a U.S.-based warehousing and logistics service provider that offers a comprehensive package of supply-chain solutions related to warehouse management and order fulfillment, today announced the integration of Amazon Shipping into its suite of shipping solutions. This new addition is expected to enhance Armlogi’s shipping capabilities, providing customers with more efficient and cost-effective options for parcel delivery.

Since its launch last week, Amazon Shipping has already enabled Armlogi to handle thousands of parcels daily. This service supports Armlogi’s commitment to offering versatile, reliable logistics solutions by ensuring timely pickup and delivery for a broad range of customer needs. Amazon Shipping is particularly noted for its efficiency and cost-effectiveness, making it an attractive option for businesses looking to optimize their shipping and distribution strategies.

Keep ReadingShow less

Featured

photo of self driving forklift
Lift Trucks, Personnel & Burden Carriers

Cyngn gains $33 million for its self-driving forklifts

a headshot of Bill Pedriana at Noblelift
Photo courtesy of Noblelift

NOBLELIFT North America welcomes Bill Pedriana as newpresident

Des Plaines, Illinois – January 7, 2025: NOBLELIFT North America, a global leader in lithium-iron material handling technology, is excited to announce the appointment of Bill Pedriana as its new President. With nearly four decades of experience in the material handling industry, Pedriana is poised to lead NOBLELIFT North America into a new era of innovation, growth, and customer-centric success.

Bill Pedriana served as Chief Marketing Officer at Big Joe Forklifts, where his visionary leadership helped rebuild the brand, develop groundbreaking products (including the Joey series of access vehicles and their cobot pallet truck concept), and execute comprehensive sales and marketing strategies. For 14 years, Pedriana played an instrumental role in achieving an extraordinary 14x growth in sales and helping to drive the global expansion of Big Joe’s parent company, EP Equipment.

Keep ReadingShow less
Loren Swakow of Noblelift

Loren Swakow announces retirement as managing director of NOBLELIFT North America

Des Plaines, Illinois – Loren Swakow, Managing Director of NOBLELIFT North America, has announced his retirement effective January 31st, 2025, leaving behind a legacy of unprecedented growth, innovation, and strong relationships built over nearly a decade at the helm of the company.

Swakow joined NOBLELIFT in October 2016, tasked with the challenge of bringing an unknown brand into the highly competitive American market. At the time, NOBLELIFT had no dealer network and minimal brand recognition. Over the course of eight years, Swakow's strategic leadership and expertise have led to remarkable success, driving average annual growth of 43%. Today, NOBLELIFT is supported by a professional dealer network spanning the entire country, with sales growth consistently outpacing the industry, a true testament to Swakow’s vision and determination.

Keep ReadingShow less
a family shops in a grocery store using a smart trolley
Photo courtesy of Instacart

Australian supermarket chain rolls out AI-powered grocery carts

Grocery shoppers in Australia will soon be able to zip in and out of the store in record time, bypassing the lines for cashiers or self-checkout kiosks altogether. They can just walk in, make their selections, and walk out with their bags in hand.

The secret to this express shopping experience is the “Caper Cart,” an AI (artificial intelligence)-powered smart trolley from San Francisco-based Instacart. In its first deployment in the Asia Pacific (APAC) region, the system is being tested by Coles Supermarkets, a food and beverage retailer with more than 1,800 grocery and liquor stores throughout the country.

Keep ReadingShow less
a women in an office watching a delivery of boxes

How green is your glue?

If you’re looking to make the packaging process more eco-friendly, the obvious place to start is with the box itself. And that’s exactly what Salt Lake City-based Packsize did when it made its initial foray into sustainable packaging back in 2002. That year, the company launched its first product, an innovative on-demand packaging system designed to reduce cardboard waste (and the need for filler material) by creating a right-sized box for each shipment.

Now the company is ready for the next step: greening up the glue.

Keep ReadingShow less