Ransomware
E1. Maritime security, geopolitics and riskDefinition
Malware encrypting systems and demanding payment; major shipping cyber threat.
Ransomware is malware that encrypts a victim’s files or systems and demands payment for the decryption key, often with a second extortion threat to leak stolen data. Shipping has been hit hard: Maersk’s June 2017 NotPetya infection cost the line an estimated 200 to 300 million US dollars and forced manual operations across terminals, and CMA CGM and COSCO suffered separate ransomware outages. The threat drives the availability and recovery emphasis of IMO Resolution MSC.428(98), backed by offline backups, network segmentation, and tested incident-response plans.
Source: IMO Resolution MSC.428(98), 16 June 2017; A.P. Moller-Maersk 2017 interim report on the NotPetya cyber attack