DP World Australia halts four container ports after network intrusion

Organization
DP World Australia
Exploit
Hacking
Industry
Ports and Logistics

DP World Australia detected unauthorised access to its Australian corporate network on Friday, November 10, 2023. To contain the intrusion the operator disconnected the network from the internet, a step that stopped land-side operations at its container terminals in Melbourne, Sydney, Brisbane and Fremantle and left containers and cargo stranded on the docks.

Those terminals handle roughly 40 percent of freight movement at Australian ports, so the shutdown had national reach. Writing for The Conversation, Edith Cowan University's Flavio Macau noted it held up imports such as appliances and pharmaceuticals along with exports of perishable goods. One exporter reported around 300 containers stuck at a terminal.

Operations restarted on Monday, November 13, with Brisbane and Fremantle moving imports and exports first while Sydney and Melbourne initially handled imports only. DP World Australia said it cleared the full backlog of 30,137 containers by November 20, ten days after detection.

The company's later account contradicted early descriptions of the incident as ransomware. DP World Australia said no ransomware executables, encrypted files or ransom demands were found on its network. Files were accessed and data was exfiltrated, but the company said customer data was not affected and that the records taken were personal information belonging to current and former employees, in some cases phone numbers, addresses or copies of driver's licences. The Australian Signals Directorate, the National Cyber Security Coordinator, the Australian Federal Police and the Office of the Australian Information Commissioner were among the agencies involved. No attacker had been identified as of late November 2023.

Sources