Maritime Computer Emergency Response Team ADMIRAL dataset ADMIRAL dataset

Publicly disclosed information for this event

Index Number:
Title:
2023_004
An offshore engineering company is hit by a ransomware attack.
Day Month Year Country Activity Incident Type
15 February 2023 Norway Offshore Virus/Ransomware

Summary

A Norwegian offshore engineering contractor reported a cyberattack on its subsidiary in Brazil. The subsidiary provides maintenance and modification services for offshore oil and gas installations. The attack impacted the subsidiary's IT systems, and the group worked to contain and neutralize the threat. The full extent of the breach was to be determined, and the company was in dialogue with Brazilian authorities regarding the incident.

The attackers claim to have gained access to the IT systems, encrypted digital files, and locked access to data. The company currently has no indications that other parts of its IT systems were infected.

Victim

Aker Solutions

Claimed/Reported Threat Actor

N/A

Origin

Cybercrime

Main impact

Availability

References

Recommendations to Offshore to reduce Virus/Ransomware risks:

  • Map, understand, patch and secure your exposed assets on the Internet.
  • Implement email filtering systems to detect and block phishing emails.
  • Train your organisation, personnel regularly against these threats.
  • Install efficient Endpoint Detection and Response (EDR) tools.
  • Work with your CSIRT organization to better understand the Tactics, Techniques and Procedures used by threat actors.
  • Monitor your IT and OT systems to quickly detect potential pre-ransomware activity.
  • Implement an efficient offline backup policy.
  • Encrypt all sensitive data to avoid further data leaks.
Previous Next
Disclaimer: the data are provided as is. France Cyber Maritime and the M-CERT take no responsibility for the soundness, quality, precision, nor the eventual attribution made by the referenced URLs. We give a lot of respect and support to the victims of attacks.
Files generated on Monday, 11th December 2023.
ADMIRAL is licensed under the Creative Commons CC-BY-NC license. Copyright © France Cyber Maritime 2023.