Ransomware attack halted work at Fincantieri Marine Group's Wisconsin shipyard

Organization
Fincantieri Marine Group
Exploit
Ransomware
Industry
Shipbuilding

Fincantieri Marine Group, the US arm of Italian shipbuilder Fincantieri and a contractor to the US Navy, said in April 2023 that a cybersecurity incident was causing a temporary disruption to certain computer systems on its network, affecting its Marinette Marine yard in Wisconsin. USNI News reported the incident as ransomware and the trade press followed. The company said it became aware of the attack on April 12.

The attack rendered data held on network servers unusable and affected email and network operations. Reporting at the time noted that the affected data feeds instructions to the yard's computer numerical control machines, leaving welders, cutters, bending machines and other computer-controlled tools offline for several days. Fincantieri Marine Group builds the Freedom-variant Littoral Combat Ship and the Constellation-class frigate, and the outage caused short-term delays to that work.

A company spokesperson said security staff isolated the affected systems immediately and reported the incident to relevant agencies and partners, and that the firm was working to restore full functionality as quickly as possible. At the time, Fincantieri Marine Group said it had no evidence that employees' personal information had been affected.

That position did not hold. In notification letters and regulatory filings submitted in January 2024, the company said the attack it became aware of on April 12, 2023 was one 'that included the encryption of certain files', and disclosed that unauthorized access had run from April 6 to April 12, 2023, and that data belonging to 16,769 people, including names and Social Security numbers, had been acquired. It offered two years of credit monitoring to those notified.

Sources