Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
Title:
2023_001
A fleet management software is shut down to respond to a ransomware attack.
Day Month Year Country Activity Incident Type
7 January 2023 Norway IT Services Virus/Ransomware

Summary

The victim, a prominent classification society, is also known for its marine fleet management software.

According to sources, on January 7th, the servers of its fleet management software were shut down, following a ransomware attack. Following the attack, the server environment underwent extensive rebuilding. The affected servers were sequestered from the broader IT infrastructure, with a subsequent forensic investigation.

Consequently, about 70 customers and approximately 1,000 vessels using the service were impacted by the disruption (it is wrong to say that 1,000 vessels were targeted by the ransomware attack, as can be sometimes read. Communications have been ongoing with these affected parties.

Victim

DNV

Claimed/Reported Threat Actor

N/A

Origin

Undisclosed

Main impact

Availability

References

Recommendations to IT Services to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks.
Files generated on Monday, 11th December 2023.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2023.