Skip to content
Search AI Powered

Latest Stories

Press releases are provided by companies as is and have not been edited or checked for accuracy. Any queries should be directed to the company issuing the release.

Resilience360 Quantifies Impact of Ocean Carrier Cyberattacks

Recent cyber-attacks on ocean carriers have proven quite disruptive.

Recent cyber-attacks on ocean carriers have proven quite disruptive. Denmark’s Maersk Line incurred estimated damages of USD 300 million (EUR 253.81 million) due to the global ransomware attack it suffered in 2017. The latest attack on CMA CGM means that all the Big 4 shipping lines, including MSC and COSCO, have suffered recent disruptive cyber events. On October 1, the International Maritime Organization (IMO) also announced a cyber-attack against its IT systems, leading to disruptions in its public website and internal systems.

“Companies shipping by sea should remain vigilant of cyber intrusions that target shipping lines,” said Daniel Boccio, Supply Chain Risk Analyst, Resilience360. “Supply chain managers and IT professionals should collaborate on identifying the potential vulnerabilities and threats to their supply chains and should implement measures to increase resiliency and minimize the impact of such threats.”


On September 28, French container transportation and shipping company CMA CGM announced that it fell victim to a cyber-attack on its peripheral servers. The company has over 480 vessels, operating 200 shipping routes between 420 ports in 150 different countries. The attack led to limited IT availability across the group, sans CEVA Logistics, due to the company halting external access to applications to prevent the spread of the malware. The company later announced that it also suspects a data breach and the nature and the volume of the affected information.

Based on an assessment of the attack on the company’s China offices, preliminary assessments conclude that the attack is the work of the Ragnar Locker ransomware. In operation since December 2019, this ransomware acts in a typical manner of the Cyber Kill Chain, performing reconnaissance and exfiltrating sensitive information to be returned in exchange for ransom payment. The ransomware can be identified with an MD5 hash of 6171000983CF3896D167E0D8AA9B94BA, which serves as the primary indicator of compromise (IoC) for the threat. It is delivered as an unsigned MSI package and is known to attack Windows systems via VirtualBox.

The ransomware’s peripheral device discovery feature allows it to spread rapidly to removable and mapped network drives, explaining CMA CGM’s decision to temporarily disable external features. Notably, the ransomware has a unicode string comparison function that, when activated, prevents the ransomware from executing on computers using languages from the former Soviet Union, such as Belorussian, Azerbaijani, Ukrainian, Moldovan, Georgia, Armenian, Turkmen, Russian, Kyrgyz, Kazakh, Uzbek, and Tajik. Ragnar Locker was last seen attacking the EDP energy company in April 2020.

Given the ransomware’s peripheral device discovery feature, the company suspended its booking system to protect its customers. The suspension disrupted operations as employees lost access to internal e-mails and applications necessary to perform daily operations, with limited options for customer communications by phone. The company suspended access to electronic bookings through its websites and announced that all cargo booked before September 27 was secure; however, later bookings were yet to be processed. The company also requested customers to either call local offices or make bookings through an external booking system.

Company services at Chinese offices in Shanghai, Guangzhou, and Shenzhen were reportedly disrupted, with container terminal managers stating that cargo loading operations were likely to be affected, but ultimately were not. Fortunately, sources at Hong Kong Port stated that CMA CGM maintained normal operations at both the container terminal and on its vessels. On September 30, the company announced that operations were gradually returning to normal, with improvements to bookings and documentation processing times as back-offices reconnect to the network. Moreover, the company assured customers that maritime and port activities are fully operational, with alternative and temporary processes available for bookings.

Ragnar Locker not only targets entities of considerable logistics and industrial importance, such as EDP and CMA CGM, but also exploits VirtualBox. This is indicative of a greater threat posed to companies employing virtualization, and to an extent, remote services. Such a threat is even more notable with the considerable quantity of remote workers this year due to the COVID-19 pandemic.

While technological recovery is quick, residual business disruptions are likely, especially regarding time-sensitive shipments.

https://www.resilience360.dhl.com/news/ransomware-attack-on-french-carrier-cma-cgm-disrupts-shipping-operations/

https://www.resilience360.dhl.com/news/ransomware-attack-on-french-carrier-cma-cgm-disrupts-shipping-operations/

The Latest

More Stories

Seegrid joins Open Source Robotics Alliance

Seegrid RS1 AMR utilizing ROS 2 to perform manipulation task in industrial facility.

Photo courtesy of Seegrid

Seegrid joins Open Source Robotics Alliance

November 19, 2024 - Seegrid Corporation, a leading manufacturer of autonomous mobile robot (AMR) solutions for palletized material handling in the US, today announced its membership in the Open Source Robotics Alliance (OSRA), an initiative of the Open Source Robotics Foundation (OSRF). Through this partnership, Seegrid will contribute its industry-leading expertise through its active involvement in the open-source robotics community. The company joins a vibrant network of innovators, collectively driving open-source development for the betterment of the global robotics landscape.

As part of the OSRA, Seegrid will actively support initiatives that foster collaboration and shared knowledge across the robotics field. The company aims to participate in key OSRF activities, including the renowned ROSCon event, as well as on-line communities such as GitHub and ROS Discourse.

Keep ReadingShow less

Featured

Rich Egan headshot

Rich Egan, Averitt's vice president of international solutions

Averitt

Averitt names Rich Egan vice president of international solutions

COOKEVILLE, Tenn. – Averitt has appointed Rich Egan as the company’s new vice president of international solutions. Egan, who brings over 40 years of experience in the transportation industry and has specialized in international logistics since 1990, will assume the position held by the retiring Charlie McGee.

Since joining Averitt in 2019 as director of international solutions, Egan has played a pivotal role in shaping the company’s global logistics strategy. His expertise and commitment to service excellence have contributed significantly to Averitt’s growth in this sector. In his new role, Egan will lead the international solutions team and drive strategic initiatives to enhance Averitt's global logistics offerings.

Keep ReadingShow less

Conveyor Solutions, KVK, Electrical Services Group, SIM Aftermarket Services, and SIM Software, combine

Elgin, Il. - October 21, 2024 – Systems in Motion today announced that its new name and brand will be effective immediately. This name change is part of a rebranding initiative, but is also the culmination of the companies’ close working relationship for the past five years and represents their unified strength. Systems in Motion will continue to provide material handling services as a tier-one, turnkey material handling integrator.

The Systems in Motion name creates a single and powerful platform – one that embodies client and industry goals of moving forward – while understanding the complexities and unique objectives of every system. The new brand also signifies the culmination of investment in internal processes that streamline procedures, and deliver a seamless customer experience.

Keep ReadingShow less
HTL Freight Acquires CTS Logistics, Expanding into Managed Transportation

HTL Freight Acquires CTS Logistics, Expanding into Managed Transportation


September 24th, Charlotte, NC - HTL Freight, a rising leader in the third-party logistics (3PL), is pleased to announce the acquisition of CTS Logistics, a full-service managed transportation company (4PL) headquartered in Windham, NH. This acquisition, HTL Freight’s fourth major transaction since 2021, reinforces its commitment to delivering exceptional freight solutions across North America.

Keep ReadingShow less
ETIHAD CARGO celebrates 20 years of successful operations in India

ETIHAD CARGO celebrates 20 years of successful operations in India

Abu Dhabi, United Arab Emirates – Etihad Cargo, the cargo and logistics arm of Etihad Airways, is celebrating 20 years of operations in India, a milestone that reflects the airline's ongoing commitment to the Indian market since its first flight to Mumbai on 26 September 2004. Over the years, Etihad Cargo has expanded its presence in India, now offering belly hold capacity via nonstop services between Abu Dhabi and 12 major Indian cities, with plans for further growth.

Etihad Cargo handles over 46,000 tonnes of cargo annually ex India, connecting the country to over 100 global destinations via its Abu Dhabi hub via 588 widebody and narrowbody rotations each month. To meet the needs of specific sectors, Etihad Cargo has enhanced its product range, adding new features and launching new products. Key commodities handled include electronics, including mobile phones and semiconductors, garments, pharmaceuticals, perishables, e-commerce, automobile components and courier shipments, reflecting the diversity and strength of India's manufacturing and export sectors.

Keep ReadingShow less