Several Greek shipping companies have been hit by a ransomware attack that spread through the systems of a popular IT consulting firm, according to Greek news agency Mononews. Danaos Management Consultants, the IT services provider whose services were affected by the hack, confirmed the cyberattack and the company said that Danaos’ own shipping operations were not affected and that the ransomware attack had encrypted the files of 10 percent of its external clients.
See also: Clop ransomware: More information revealed

An independent cybersecurity firm has been contracted to investigate the incident and determine how the ransomware entered Danaos' customer-facing systems. In the meantime, the company is helping affected customers restore systems .
Danaos Management Consultants has been providing IT solutions to the shipping industry since 1986, making it one of the oldest companies in the industry. It builds software tools for ship management, including applications for chartering, payroll, crew, AI analytics, ISM, document management and procurement.
See also: USA: Reward for information on the Darkside ransomware gang
"A cyberattack incident cannot ruin the image we have created for 36 years," CEO Dimitris Theodosiou told Mononews.
A cybersecurity expert contacted by TME said the attack highlights the reality of the IT supply chain risk for shipowners and operators. Most maritime IT professionals are aware of the risks that remote third-party maintenance poses to operational technology (OT) on their ships, but few are concerned about how vulnerable their offshore corporate systems could be to an attack delivered via a vendor’s software.

“The readiness to deal with a supply chain attack is very low across the [shipping] sector,” the cyber expert said. “While some of the companies [we surveyed] have conducted cyber exercises to prepare for incident preparedness and resilience, none of them involve their suppliers in these exercises.”
See also: Phishing emails infect victims with MirCop ransomware
A vendor software update was the “vehicle” that delivered the devastating NotPetya virus to Maersk’s IT servers in 2017. That attack resulted in “100 percent destruction of anything Microsoft-based that was connected to the network,” including 49,000 laptops and 3,500 servers, according to Maersk’s chief information officer Adam Banks. The resulting disruption cost the world’s largest shipping company an estimated $350 million in financial losses.
Source of information: maritime-executive.com
