Ransomware Attack on Administration of the Port of São Francisco do Sul

Incident Date: May 16, 2024

Attack Overview
VICTIM
Administração do Porto de São Francisco do Sul (APSFS)
INDUSTRY
Government
LOCATION
Brazil
ATTACKER
Ransomhub
FIRST REPORTED
May 16, 2024

Ransomware Attack on Administração do Porto de São Francisco do Sul

Victim Overview

The victim of the recent ransomware attack is the Administration of the Port of São Francisco do Sul (APSFS), responsible for the Port of São Francisco do Sul in Santa Catarina, Brazil. The port is a crucial trade hub, particularly for importing fertilizers, and plays a significant role in the state's economy.

Company Profile

The Administration of the Port of São Francisco do Sul is the main economic activity in the municipality where it is located, contributing around 70% of the local revenue. It accounts for 45% of total exports via maritime transport in Santa Catarina, showcasing its importance in the industry. The port stands out for its comprehensive infrastructure, including terminals and storage facilities, as well as well-established road and rail links to nearby areas. Its 9.3-mile canal provides crucial connectivity to global shipping routes, making it a vital trade hub.

Attack Overview

On May 6, 2024, the Port of São Francisco do Sul fell victim to a ransomware attack by the group RansomHub. The attack compromised over 880,000 sensitive documents, totaling 548.72 GB of data. The leaked documents include accounting, human resources, financial reports, reception, contracts, operations, and employee details.

Ransomware Group Profile

RansomHub is a new ransomware group known for distinguishing themselves by making claims and backing them up with data leaks. They operate as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money. The group is believed to have roots in Russia and has targeted various countries, including Brazil.

Penetration Method

The group's ransomware strains are written in Golang, a relatively new trend in the ransomware world. The use of AI technology has significantly impacted ransomware attacks, making them more effective. It is crucial for organizations to adopt a multilayered approach to ransomware protection to mitigate the risks of such attacks.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.