The Port of Seattle, the United States government agency that oversees the Seattle port and airport, confirmed that the Rhysida ransomware was behind a cyberattack that hit systems about a month ago.

In late August, the attack forced the airline to isolate some of its critical systems to limit the impact. As a result, it disrupted reservation check-in systems and delayed flights at Seattle-Tacoma International Airport.
Three weeks after the initial disclosure, it was officially confirmed that the breach was a ransomware attack coordinated by affiliates of the Rhysida ransomware.
See also: Healthcare provider LVHN pays $65 million after Ransomware attack
“This incident was a ransomware attack by the criminal organization known as Rhysida. There has been no new unauthorized activity on the systems since that day. It remains safe to travel from Seattle-Tacoma International Airport and use the Port of Seattle’s marine facilities,” the government agency said in a press release. It also said that some systems were was encrypted data.
The encryption of some systems and the Port of Seattle's decision to take the systems offline to prevent the attack from spreading caused outages that affected many services and systems, including baggage handling, check-in kiosks, ticketing, Wi-Fi, passenger display boards, the Port of Seattle website, the flySEA app, and parking.
Most affected systems have come back online, however the agency is still working to restore other essential services, such as the Port of Seattle website, SEA Visitor Pass, TSA wait times, and access to the flySEA app (unless downloaded prior to the ransomware attack).
The Port of Seattle has decided not to give in to the Rhysida ransomware gang's demands for ransom, even though the attackers are threatening to release data.
See also: Hazard Ransomware: The story of a failed decryption
“The Port of Seattle has no intention of paying the perpetrators behind the cyberattack,” said Steve Metruck, Port of Seattle’s Executive Director. “Paying the criminal organization does not reflect the values of the service or our commitment to being good stewards of taxpayer dollars.
Ransomware protection
Back up your data: One of the most effective ways to protect yourself from a attack is to regularly back up your data. This ensures that even if your data is encrypted by ransomware, you will have a safe copy that can be restored without paying the ransom.
Update your operating system and software: Out-of-date operating systems and software are vulnerable to cyberattacks. It is important to regularly update your devices with the latest security and software updates to prevent any vulnerabilities that could be exploited by ransomware.

Beware of suspicious emails and links: Ransomware attacks often start with a phishing email or malicious link. It is important to be cautious when opening emails from unknown senders. Also, do not click on suspicious links. These could lead to ransomware being installed on your device.
Use antivirus software: Installing reputable antivirus software on your devices can help you detect and prevent attacks . Be sure to update your antivirus software to ensure it is equipped to handle new threats.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: NoName ransomware: “Collaboration” with the RansomHub group?
Education: One of the most important steps to protect against ransomware is education. It is important to stay up to date on the latest types of ransomware and how they work. Organizations should also train their employees on how to identify and avoid potential attacks.
Implement strong passwords: Weak or easy passwords can make it easier for hackers to gain access to your devices and install ransomware. It's important to use strong and unique passwords and enable two-factor authentication whenever possible.
Use a VPN: A VPN encrypts your internet connection and provides an extra layer of security against ransomware attacks. This is especially important when using public Wi-Fi networks, which are often unsecured and vulnerable to cyberattacks.
Source: www.bleepingcomputer.com
