Ports Of San Diego & Barcelona Come Under Attack

Cyber-attacks have now been reported at three ports in the last two months.
Two major international ports fell victim to cyber-attacks within the span of a week, putting the shipping industry on alert for a possible threat actor targeting the entire sector.

The first to fall was the Port of Barcelona, Spain, on September 20, last week. The second attack was reported yesterday, September 25, by the Port of San Diego, in the United States.

None of the two port authorities revealed any details about the nature of the cyber-attacks, leaving security experts to speculate about possible causes.

The cyber-attack on the Port of Barcelona did not affect ship movements in and out of the harbor, and a local newspaper reported that it impacted only land operations, such as loading or unloading of boats, although the Port denied there was a serious disruption to customers.

In a tweet two days after the initial attack, the Port of Barcelona said that only internal IT systems were affected, but did not offer other details, even after a week's worth of requests for comments and questions from ZDNet.

The Barcelona cyber-attack was followed by another one recently, this time against the Port of San Diego, a medium-sized cargo port on the US west coast.

‘Port employees are currently at work but have limited functionality, which may have temporary impacts on service to the public, especially in the areas of park permits, public records requests, and business services," said Randa Coniglio, Chief Executive Officer for the Port of San Diego in a statement released a day after the attack.

Port officials did not respond to a request for further comment from ZDNet, but they said they are still investigating the hack.

Just like the Barcelona port, San Diego officials stayed mum regarding the nature of the attack. It is unclear if the two incidents are related or alike, and the whole maritime industry may benefit from a little bit of openness about the two incidents. Port authorities around the world should be on alert, regardless.

One of the security researchers who tipped ZDNet about the last incident noted that both port authorities described the cyber-attacks as disruptive, a term commonly used with ransomware attacks, which are destructive in nature, but not with other forms of cyber-attacks, such as data breaches, where intruders' main goal is to stay undetected by leaving systems intact and working.

This is speculation, at this point, as both ports declined to provide technical details, but the speculation has its merits, based on a previous incident.

Back in July, there was a ransomware attack that was initially reported as an infection affecting the Long Beach Port, which was later tracked down and isolated to the port terminal of the China Ocean Shipping Company (COSCO), and later the company's internal network, one of the world's largest shipping firms.

With three "disruptive" cyber-attacks reported by three ports in two months, some might wonder if a threat group isn't targeting ports intentionally. This isn't a surprise, as ports handle a huge amount of business, and any disturbance can lead to serious financial losses.

When the NotPetya ransomware outbreak started to spread last year, one of the first companies to report issues was Maersk, the world's largest cargo shipping company. Maersk's poor security practice cost the company over $300 million in damages, and the company's IT staff had to reinstall 4,000 servers, 45,000 PCs, and 2,500 applications in ten days, in what the chairman called a "heroic effort."

Last year, UK shipping provider Clarksons PLS was also hacked and blackmailed by a hacker who breached the company's systems and claimed to have stolen its database. Clarksons refused to pay, but the event made headlines anyway.

Port authorities and ships have long been considered easy to hack. One cyber-security firm, in particular, published a long string of blog posts detailing the various ways in which someone could hack IT systems in ports and on ships. 

But these blog posts describe high-tech hacks and are probably not the main entry of these attacks. Usually failure in IT maintenance of regular systems is the point of entry for most hackers, such as outdated software, open RDP endpoints, or employees running malicious files received via email, etc.

Ironically, five months before it got hacked, the Port of Barcelona published a blog post titled "Are ports prepared to deal with threats from hackers?"

Apparently not.

Updated on September 27, 14:00 ET: A Port of San Diego spokesperson confirmed via email that the cyber-attack was a ransomware infection.

"We can confirm it is ransomware, but cannot provide additional details at this time," the spokesperson said.

ZDNet:

You Might Also Read:

The Maritime Industry's Slow Boat To Cybersecurity

« A Self-Flying AI-Powered Drone That Can Track You
Liberating Personal Data »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

IX Associates

IX Associates

IX Associates is a UK based IT Integration business specialising in risk, compliance, eDefence, and network security solutions.

High-Tech Bridge

High-Tech Bridge

High-Tech Bridge SA is a Swiss MSSP provider offering security auditing, source code review and computer forensics.

BMC Software

BMC Software

BMC provide solutions for IT service management, Cloud management, IT workload automation, IT operations, and mainframe system management.

Zentera Systems

Zentera Systems

Zentera's CoIP (Cloud over IP) solution offers enterprise-grade networking and security for the emerging cloud ecosystem.

SISA

SISA

SISA is a global forensics-driven cybersecurity solutions company, trusted by leading organizations for securing their businesses with robust preventive and corrective cybersecurity solutions.

Arthur J Gallagher & Co

Arthur J Gallagher & Co

Arthur J. Gallagher & Co. is a global insurance brokerage and risk management services firm. Services include Cyber Liability insurance.

CWSI

CWSI

CWSI provide a full suite of enterprise mobility, security and productivity solutions to many of Ireland and the UK’s most respected organisations across a wide range of industry and public sectors.

Prima Cyber Solutions (PCS)

Prima Cyber Solutions (PCS)

Prima Cyber Solutions is focused on protecting your business from the massive and devastating impacts that cyber-attacks may cause.

Netstar

Netstar

Netstar is an IT Support company based in Central London providing fully managed IT Support, Cyber Security and Technology Consulting services.

Cyber Security Services

Cyber Security Services

Cyber Security Services is a cyber security consulting firm and security operations center (SOC).

Symptai Consulting

Symptai Consulting

Symptai Consulting is a leading Cyber Security, Digital Transformation and Anti-Money Laundering firm serving the Caribbean and the wider world.

Air IT

Air IT

Air IT are a responsive, client-focused and award-winning Managed Service Provider, helping clients achieve success and transformation through their IT and communications.

Deloitte

Deloitte

Deloitte is a multinational professional services firm providing audit, consulting, financial advisory, risk management, tax, and related services to clients.

Guardsman Cyber Intelligence (GCI)

Guardsman Cyber Intelligence (GCI)

GCI provides proven cyber intelligence solutions to protect your business against ever present physical and digital threats shadowing your online business.

Summit 7 (S7)

Summit 7 (S7)

Summit 7 is a national leader in cybersecurity, compliance, and managed services for the Aerospace and Defense industry and corporate enterprises.

Harness

Harness

Harness delivers an end-to-end software delivery platform that helps engineering teams achieve the highest levels of engineering excellence.