Ransomware hit fleet management for 1.000 ships

B2B Cyber ​​Security ShortNews

Share post

DNV, the provider of the fleet management software ShipManager, was hit by a ransomware attack and had to shut down large parts of its IT systems. This affects 70 DNV customers and their 1.000 ships.

DNV's ShipManager servers fell victim to a ransomware cyberattack on the evening of January 7th. DNV experts immediately shut down the servers in response to the incident. DNV is in regular contact with all ShipManager users regarding the situation. Around 70 customers who operate around 1.000 ships are affected. All affected customers have been advised to consider appropriate remedial actions based on the type of data they have uploaded to the system.

70 customers with 1.000 ships affected

The good news for all customers: All ships can continue to use the offline functions of the ShipManager software on board. Other systems on board the ships should not be affected. Thus, the cyber attack has so far had no impact on the ships' operational capability. However, companies use the software for managing ships and crews. The description of the software mentions: a planned maintenance system, shipping procurement, ship safety management systems, crew management system, hull integrity management, dry dock and ship repair, and shipping data analysis.

DNV announces: “There is no evidence that any other data or servers are affected by DNV. The server outage will not affect other DNV services. The ship manager's IT infrastructure is isolated from DNV's other servers. The forensic investigation will be conducted by DNV's global IT security partners. This has confirmed that no lateral movement to other parts of DNV's IT infrastructure was carried out as part of the attack. Information such as DNV user accounts, emails and all other services are unaffected by the incident."

DNV Group is itself a provider of security services

A bit embarrassing: The group has its own cyber security department and offers testing & verification, governance, risk and compliance, safety & security risk management, insight & training, incident response & investigation, strategy & programs and even an ICS penetration testing service. Perhaps the group should have used this service on themselves.

The attack was reported to the Norwegian police, who informed the relevant police authorities. It has also been reported to the Norwegian National Security Authority, the Norwegian Data Protection Authority (DPA) and the German Cybersecurity Authority. All affected customers have been informed of their responsibility to notify the relevant data protection authorities in their countries.

Editor/sel

More at DNV.com

 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more