Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
Title:
2010_001
An offshore platform is infected by malware - 19 days of downtime on some systems.
Day Month Year Country Activity Incident Type
XX N/A 2010 Korea, Republic of Offshore Virus/Ransomware

Summary

According to sources, in 2010, a major player in the offshore rigging sector had an offshore rig suffered a comprehensive malware attack. The event occured when the rig leaf the construction yard in South Korea for its production site in Latin America (probably Brazil). The malicious software managed to infiltrate essential controls, including offline safety mechanisms.

The malware's infiltration had a severe operational impact, forcing the rig to shut down for 19 days. Considering the high day-to-day operational costs of such rigs, even if it was not in production, substantial financial losses of over 10 million dollars could have been reached.

Victim

N/A

Claimed/Reported Threat Actor

N/A

Origin

Undisclosed

Main impact

Integrity

References

Recommendations to Offshore to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks.
Files generated on Monday, 11th December 2023.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2023.