Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
Title:
2020_004
Cyberattack on a smart port.
Day Month Year Country Activity Incident Type
15 March 2020 France Port Virus/Ransomware

Summary

The victim, an administrative entity encompassing the cities of Marseille, Martigues, and the Aix-Marseille-Provence metropolis, was hit by a ransomware attack. This region, significant for its public services and infrastructure, faced a cyber incident that targeted interconnected information systems across multiple municipalities, including the Grand Port Maritime de Marseille.

According to sources, over the course of a weekend, the public sector's digital infrastructure was compromised by ransomware identified as Mespinoza/Pysa.

As a consequence, networks had to be isolated. The presence of backup and recovery systems have mitigated the damage, averting the worst outcomes. No proven impact was detected on the port’s OT systems.

Victim

Grand Port Maritime de Marseille

Claimed/Reported Threat Actor

Mespinoza/Pysa

Origin

Cybercrime

Main impact

Availability

References

Recommendations to Port to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks.
Files generated on Monday, 11th December 2023.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2023.