Ransomware halted container operations at Japan's Port of Nagoya

Organization
Port of Nagoya
Exploit
Ransomware
Industry
Ports and Logistics

Japan's Port of Nagoya, the country's largest and busiest cargo port, lost the use of its terminal management system on July 4, 2023 in a ransomware attack that stopped container handling for roughly two days.

The outage began at about 6:30 a.m. local time, when a member of staff could not start a computer. The affected system was the Nagoya United Terminal System, known as NUTS, which coordinates work across the port's container terminals. Loading and unloading of containers onto and off trailers was suspended once the incident was identified. A ransom message printed on an office printer confirmed the systems had been encrypted, and the LockBit 3.0 group was widely reported to be responsible.

The port handles about 10 percent of Japan's trade and roughly 2.68 million containers a year, and is a significant route for Toyota parts. Toyota said imports and exports of parts were disrupted, while shipments of finished vehicles continued and the company held sufficient inventory to absorb the delay.

Operators isolated the affected servers, shut down networks to prevent spread and rebuilt the system from backups. The Nagoya Harbor Transportation Association targeted a 7:30 a.m. restart on July 6, but it slipped because of the volume of data to be recovered and checked for viruses. One cargo terminal resumed at about 3 p.m., and the others restarted later that day. The port did not say whether a ransom was paid.

Sources