Ransomware Attack on Administration of the Port of São Francisco do Sul
Ransomware Attack on Administração do Porto de São Francisco do Sul
Victim Overview
The victim of the recent ransomware attack is the Administration of the Port of São Francisco do Sul (APSFS), responsible for the Port of São Francisco do Sul in Santa Catarina, Brazil. The port is a crucial trade hub, particularly for importing fertilizers, and plays a significant role in the state's economy.
Company Profile
The Administration of the Port of São Francisco do Sul is the main economic activity in the municipality where it is located, contributing around 70% of the local revenue. It accounts for 45% of total exports via maritime transport in Santa Catarina, showcasing its importance in the industry. The port stands out for its comprehensive infrastructure, including terminals and storage facilities, as well as well-established road and rail links to nearby areas. Its 9.3-mile canal provides crucial connectivity to global shipping routes, making it a vital trade hub.
Attack Overview
On May 6, 2024, the Port of São Francisco do Sul fell victim to a ransomware attack by the group RansomHub. The attack compromised over 880,000 sensitive documents, totaling 548.72 GB of data. The leaked documents include accounting, human resources, financial reports, reception, contracts, operations, and employee details.
Ransomware Group Profile
RansomHub is a new ransomware group known for distinguishing themselves by making claims and backing them up with data leaks. They operate as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money. The group is believed to have roots in Russia and has targeted various countries, including Brazil.
Penetration Method
The group's ransomware strains are written in Golang, a relatively new trend in the ransomware world. The use of AI technology has significantly impacted ransomware attacks, making them more effective. It is crucial for organizations to adopt a multilayered approach to ransomware protection to mitigate the risks of such attacks.
Sources:
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!