Ransomware Attack on Administration of the Port of São Francisco do Sul

Incident Date:

May 16, 2024

World map

Overview

Title

Ransomware Attack on Administration of the Port of São Francisco do Sul

Victim

Administração do Porto de São Francisco do Sul (APSFS)

Attacker

Ransomhub

Location

São Francisco do Sul, Brazil

, Brazil

First Reported

May 16, 2024

Ransomware Attack on Administração do Porto de São Francisco do Sul

Victim Overview

The victim of the recent ransomware attack is the Administration of the Port of São Francisco do Sul (APSFS), responsible for the Port of São Francisco do Sul in Santa Catarina, Brazil. The port is a crucial trade hub, particularly for importing fertilizers, and plays a significant role in the state's economy.

Company Profile

The Administration of the Port of São Francisco do Sul is the main economic activity in the municipality where it is located, contributing around 70% of the local revenue. It accounts for 45% of total exports via maritime transport in Santa Catarina, showcasing its importance in the industry. The port stands out for its comprehensive infrastructure, including terminals and storage facilities, as well as well-established road and rail links to nearby areas. Its 9.3-mile canal provides crucial connectivity to global shipping routes, making it a vital trade hub.

Attack Overview

On May 6, 2024, the Port of São Francisco do Sul fell victim to a ransomware attack by the group RansomHub. The attack compromised over 880,000 sensitive documents, totaling 548.72 GB of data. The leaked documents include accounting, human resources, financial reports, reception, contracts, operations, and employee details.

Ransomware Group Profile

RansomHub is a new ransomware group known for distinguishing themselves by making claims and backing them up with data leaks. They operate as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money. The group is believed to have roots in Russia and has targeted various countries, including Brazil.

Penetration Method

The group's ransomware strains are written in Golang, a relatively new trend in the ransomware world. The use of AI technology has significantly impacted ransomware attacks, making them more effective. It is crucial for organizations to adopt a multilayered approach to ransomware protection to mitigate the risks of such attacks.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.