Maritime Cyber - New Crook in Town

Over the last couple of years interest and concern in Maritime cyber security has risen exponentially. There have been several notable incidents, from the drug trafficking related breach at Antwerp port in 2013 through to what is probably the most high profile maritime attack, the NotPetya ransomware last year which cost Maersk $300 million to rectify.

However, very few cyber incidents specifically targeted maritime companies or ports with the intention of causing damage, stealing data or money. The Antwerp episode was a byproduct of the traffickers trying to smuggle their drugs into Europe and wasn't intended to do any financial or physical harm to the port and Maersk was just one of several hundred victims of NotPetya.

"Unlike other BEC groups, GOLD GALLEON does not target a wide range of businesses but appears to focus solely on global maritime shipping businesses and their customers." 

But all that has changed and the bad guys are now actively going after companies in the maritime industry. A team from Secureworks, a subsidiary of Dell, has recently produced a detailed report about 'GOLD GALLEON' a Nigerian Cyber Crew's attacks on the Shipping Industry.

"researchers have observed GOLD GALLEON targeting firms in South Korea, Japan, Singapore, Philippines, Norway, U.S., Egypt, Saudi Arabia and Colombia."

In brief, the globally dispersed nature of shipping means that email is the most common form of communication between ships, owners and companies that provide ship management and port services, so GOLD GALLEON adapted business email compromise and business email spoofing to target the shipping industry. It's an excellent report and really worth reading.

 Lawrie Abercrombie M.Inst.IISP is the Technical Director at Arcanum, a UK National Cyber Security Centre (NCSC) accredited Consultancy working with Businesses, Government and the Defence Industry. One of only a few Lead Security & Information Risk Advisors certified by the NCSC, Lawrie specialises in Risk Management for IT and OT projects and has been briefing on Maritime Cyber in the UK and internationally in both the Public and Private sectors for several years.

If you or your organisation would like to benefit from our expertise we would be delighted to hear from you. Call us on 01558 669140 or visit our website: https://arcanum-cyber.com/maritime



要查看或添加评论,请登录

Lawrie Abercrombie FCIIS的更多文章

  • Cyber Security Professionals – A Market for Lemons?

    Cyber Security Professionals – A Market for Lemons?

    In 1970, George Akerlof, a US Nobel Prize winning economist wrote a paper on the used car market in the USA titled ‘The…

    39 条评论
  • What's in a Name?

    What's in a Name?

    I have just had a message from a "Senior Recruitment Consultant" who, having reviewed my profile on here, sent me the…

    3 条评论
  • Public Sector Cyber supporting Small Businesses

    Public Sector Cyber supporting Small Businesses

    On Tuesday 14th August, the US Senate finally passed a law directing the National Institute of Standards and Technology…

    5 条评论
  • Welcome to the Team Marie

    Welcome to the Team Marie

    You may remember that we recently asked for advice / recommendations about recruiting a Sales and Marketing Manager for…

    3 条评论
  • PREDICTIONS FOR POST 25TH MAY #4 - Cyber Insurance

    PREDICTIONS FOR POST 25TH MAY #4 - Cyber Insurance

    This is the last of our four articles on what we consider will be untended consequences of the introduction of GDPR on…

    1 条评论
  • PREDICTIONS FOR POST 25TH MAY #3

    PREDICTIONS FOR POST 25TH MAY #3

    Rise of the CISO Our first two posts in this series looked at what we predict to be a dramatic increase in data breach…

  • Predictions For Life Post 25th May #2 Financial Costs

    Predictions For Life Post 25th May #2 Financial Costs

    Our first post in this series looked at the likely increase in data breach reporting post the introduction of the new…

    6 条评论
  • PREDICTIONS FOR POST 25TH MAY #1 - Breach Reporting

    PREDICTIONS FOR POST 25TH MAY #1 - Breach Reporting

    GDPR By now, everyone in the cyber security business knows that GDPR is coming on 25th May this year. Most of the…

    2 条评论
  • Maritime, Cyber and Autonomous Ships

    Maritime, Cyber and Autonomous Ships

    Two articles published almost simultaneously represent very different attitudes to the maritime environment and cyber…

    3 条评论
  • “Don’t expect a large fine on 26th May"

    “Don’t expect a large fine on 26th May"

    As 25 May draws closer, GDPR is becoming increasingly visible, particularly here on Linkedin. A refresh of my home page…

    8 条评论

社区洞察

其他会员也浏览了