Thursday, September 11, 2025
HomeCyber SecurityPort of Seattle hit by Rhysida ransomware in August assault

Port of Seattle hit by Rhysida ransomware in August assault


Port of Seattle hit by Rhysida ransomware in August assault

Picture: Midjourney

Port of Seattle, america authorities company overseeing Seattle’s seaport and airport, confirmed on Friday that the Rhysida ransomware operation was behind a cyberattack impacting its methods during the last three weeks.

The company revealed on August 24 that the assault pressured it to isolate a few of its important methods to include the influence. The ensuing IT outage disrupted reservation check-in methods and delayed flights at Seattle-Tacoma Worldwide Airport.

At present, three weeks after the preliminary disclosure, the Port formally confirmed that the August breach was a ransomware assault coordinated by Rhysida ransomware associates.

“This incident was a “ransomware” assault by the prison group referred to as Rhysida. There was no new unauthorized exercise on Port methods since that day. It stays secure to journey from Seattle-Tacoma Worldwide Airport and use the Port of Seattle’s maritime services,” it mentioned in a press launch.

“Our investigation has decided that the unauthorized actor was capable of achieve entry to sure components of our pc methods and was capable of encrypt entry to some information.”

The Port’s determination to take methods offline and the ransomware gang encrypting people who weren’t remoted in time induced outages impacting a number of providers and methods, together with baggage, check-in kiosks, ticketing, Wi-Fi, passenger show boards, the Port of Seattle web site, the flySEA app, and reserved parking.

Port of Seattle Rhysida data theft

Whereas the Port has already introduced most affected methods again on-line inside the week, it is nonetheless engaged on restoring different key providers, just like the Port of Seattle web site, SEA Customer Go, TSA wait instances, and flySEA app entry (until downloaded earlier than the August ransomware assault).

The Port has additionally determined to not give into the ransomware gang’s calls for to pay for a decryptor although the attackers would doubtless publish information stolen in mid-to-late August on their darkish internet leak web site.

“The Port of Seattle has no intent of paying the perpetrators behind the cyberattack on our community,” mentioned Steve Metruck, Govt Director of the Port of Seattle. “Paying the prison group wouldn’t replicate Port values or our pledge to be an excellent steward of taxpayer {dollars}.”

Rhysida is a comparatively new ransomware-as-a-service (RaaS) operation that surfaced in Might 2023 and shortly gained notoriety after breaching the British Library and the Chilean Military (Ejército de Chile).

The U.S. Division of Well being and Human Providers (HHS) linked Rhysida to assaults towards healthcare organizations. On the identical time, CISA and the FBI warned that this cybercrime gang was additionally behind many opportunistic assaults focusing on victims throughout a variety of different business sectors.

As an example, in November, Rhysida breached Sony subsidiary Insomniac Video games and leaked 1,67 TB of paperwork on the darkish internet after the sport studio refused to pay a $2 million ransom.

Its associates have additionally breached the Metropolis of Columbus, Ohio, MarineMax (the world’s largest leisure boat and yacht retailer), and the Singing River Well being System. The latter warned virtually 900,000 folks that their information had been stolen in an August 2023 Rhysida ransomware assault.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments