Ransomware Attack on Administration of the Port of São Francisco do Sul
Incident Date:
May 16, 2024
Overview
Title
Ransomware Attack on Administration of the Port of São Francisco do Sul
Victim
Administração do Porto de São Francisco do Sul (APSFS)
Attacker
Ransomhub
Location
First Reported
May 16, 2024
Ransomware Attack on Administração do Porto de São Francisco do Sul
Victim Overview
The victim of the recent ransomware attack is the Administration of the Port of São Francisco do Sul (APSFS), responsible for the Port of São Francisco do Sul in Santa Catarina, Brazil. The port is a crucial trade hub, particularly for importing fertilizers, and plays a significant role in the state's economy.
Company Profile
The Administration of the Port of São Francisco do Sul is the main economic activity in the municipality where it is located, contributing around 70% of the local revenue. It accounts for 45% of total exports via maritime transport in Santa Catarina, showcasing its importance in the industry. The port stands out for its comprehensive infrastructure, including terminals and storage facilities, as well as well-established road and rail links to nearby areas. Its 9.3-mile canal provides crucial connectivity to global shipping routes, making it a vital trade hub.
Attack Overview
On May 6, 2024, the Port of São Francisco do Sul fell victim to a ransomware attack by the group RansomHub. The attack compromised over 880,000 sensitive documents, totaling 548.72 GB of data. The leaked documents include accounting, human resources, financial reports, reception, contracts, operations, and employee details.
Ransomware Group Profile
RansomHub is a new ransomware group known for distinguishing themselves by making claims and backing them up with data leaks. They operate as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money. The group is believed to have roots in Russia and has targeted various countries, including Brazil.
Penetration Method
The group's ransomware strains are written in Golang, a relatively new trend in the ransomware world. The use of AI technology has significantly impacted ransomware attacks, making them more effective. It is crucial for organizations to adopt a multilayered approach to ransomware protection to mitigate the risks of such attacks.
Sources:
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.