news Operational riskCompliance & regulation Splash247
Attackers are using ever more sophisticated approaches to infiltrate a sector that is increasingly within reach, writes Nicolas Furgé, president of digital at Marlink. Cyber risk is seen by many as a fact of life but for a long time, the shipping industry’s comparative isolation from threats was its greatest advantage. Small volumes of low bandwidth traffic meant shipping presented a moving target of comparatively low value. The advent of high throughout, low latency LEO services alongside VSAT and 4/5G connectivity have brought shipping into the mainstream of digitalisation. The threat level has risen accordingly and so has the need for regulation that will go some way to managing the risk. Such rules have so far been a patchwork approach but they are becoming increasingly joined up as statutory guidance, voluntary systems and industry standards are supplemented by European Union regulation that threatens punitive fines for non-compliance. The rise of the regulators is timely, as the threats from cyber-criminals continue to increase, growing in volume and sophistication. The latest global maritime cyber threat report produced by the Marlink Security Operations Centre (SOC) demonstrates the changing tactics of cyber criminals, who are increasingly attempting to bypass previously effective security controls using new tools. Marlink’s unique maritime SOC actively monitored more than 1,800 vessels in the first half of 2024 and the data show that malicious activity in this period increased significantly compared to the previous year. Analysts observed a continued rise in common threats using Command and Control (C&C) infrastructure to create botnet threats, which are growing in number and complexity. Phishing continues to be the leading tactic used by attackers to gain access to corporate networks, though the SOC also detected an increase in blacklisted malicious traffic. This highlights the importance of maintaining up-to-date threat intelligence feeds and applying strict security policies to prevent unauthorised connections to high-risk sites. Increased visibility into events from endpoint protection solutions (EDR), firewalls and e-mail security, along with the context provided by intelligence capabilities, has allowed SOC analysts to gain deeper insight into the evolving threat landscape. Malicious actors are evolving their attack patterns and launching fraudulent campaigns that bypass previously effective security controls, such as two-factor authentication, forcing defenders to react and raise the security level to ensure operations are safeguarded. During the first half of 2024, a significant portion of the threats neutralised by the SOC have continued to follow the most common attack vector seen since 2022: phishing. However, in this period, there has been a notable increase in a more advanced form known as ‘reverse proxy phishing’. Phishing is a classic cyberattack method where attackers impersonate legitimate entities (like banks or service providers) to trick users into providing sensitive information, such as login credentials or financial data. Traditional phishing often relies on fake websites or fraudulent e-mails to capture user data. ‘Reverse proxy phishing’, on the other hand, is a more sophisticated version. Instead of simply creating a fake website, the attacker sets up a ‘proxy’ that sits between the legitimate website and the victim. This proxy captures the user’s credentials and, in real-time, forwards them to the act
RATS, bots and reverse proxy phishing: why cyber criminals have shipping in their sights
Splash247
Read full article at Splash247 →
Opens Splash247 in a new tab