8Base ransomware group claimed a data theft at Croatia's Port of Rijeka
- Organization
- Luka Rijeka d.d. (Port of Rijeka)
- Exploit
- Ransomware
- Industry
- Logistics & Transport
Luka Rijeka d.d., the company that operates Croatia's largest dry cargo port at Rijeka, detected an intrusion on November 30, 2024. Its IT staff shut down the entire IT system as a precaution, and Help Net Security reported that operations were restored from backups by December 2.
The 8Base ransomware group listed the company on its leak site in early December, claiming it had taken invoices and receipts, accounting documents, personal data, certificates, employment contracts and a large volume of confidential material including non-disclosure agreements. The group set December 10, 2024 as the deadline for publishing the files.
Chief executive Duško Grabovac confirmed to Croatian media that data had been stolen, said no ransom would be paid and stated that the port's systems were functioning normally again thanks to the backup. Management board member Marko Mišković described the damage as non-existent for the time being, noting that as a listed company much of Luka Rijeka's financial information was already public. Help Net Security reported that the company never received a formal ransom demand.
Board member Marina Cesarac Dorčić said the operator had raised its data protection to the highest possible level after an earlier attack in 2019, which the company credited with limiting the harm this time. 8Base has operated since 2022 as a ransomware-as-a-service crew running a customized version of Phobos and using double extortion tactics.