Archive for Cyberattack

Cyberattack disrupts operations at North Carolina Ports

Posted in Commentary with tags on August 6, 2026 by itnerd

North Carolina Ports is recovering from a cyberattack that disrupted operations at the Port of Wilmington, Port of Morehead City and the Charlotte Inland Port.

The organization said it detected the attack on August 4 and immediately activated its Cybersecurity Contingency Plan to contain the incident. As a result, gates at all three facilities opened late on August 5, and officials warned customers and truck drivers to expect operational delays.

North Carolina Ports said the breach has been contained and recovery efforts are underway with support from the North Carolina Department of Transportation, the North Carolina Department of Information Technology and the U.S. Coast Guard.

Denis Calderone, CTO, Suzu Labs:

“We’ve been tracking port cyberattacks over the last few years. Nagoya went down for two days in July 2023. DP World stranded 30,000 containers in Australia for three days in November 2023. The Port of Seattle lost administrative systems for weeks after an attack in August 2024. It’s good to see in this case that NC Ports’ incident preparedness seems to have paid off. They activated their contingency plan the very same night of the attack and were processing manually by the next morning.

“That said, the attack itself is the signal every port operator in the country should be paying attention to. This is the fourth significant port cyberattack globally in three years. Port terminal operating systems, automated gate processing, crane control networks, these are all systems that have been rapidly digitized over the last decade, and attackers have clearly noticed. NC Ports handles 4.4 million tons of cargo annually and supports nearly 90,000 jobs across the state. A longer outage at a facility like that doesn’t just delay trucks, it backs up supply chains across the Southeast and beyond.

“The Coast Guard’s maritime cybersecurity rule went into effect in July 2025, and what we’re seeing in NC Ports’ response maps directly to what that regulation is trying to produce: a designated cybersecurity contingency plan, rapid detection, coordinated response with federal partners. The problem is that most MTSA-regulated port facilities don’t have to submit their full Cybersecurity Plans until July 2027. We’re in the gap period right now, and attacks are not waiting for compliance deadlines.

“For any port operator watching this: the playbook hasn’t changed but the urgency has. Segment your OT networks from your IT environment. Make sure your terminal operating system can’t be reached from the same network segment as your email. Test your manual gate processing procedures with actual crews, not just on paper. Inventory every communication path into your control systems, including the cellular links and the vendor remote access channels. And don’t wait for the 2027 Cybersecurity Plan deadline to do the work. NC Ports has been investing in this kind of preparedness for years and it paid off this week. If your port can’t replicate that response tomorrow, you’re already behind.”

This is going to be more of a thing given the state of play. By that I mean Iran or other cyber threats as it is a safe assupmtion that if you are not under attack now, you will be.

Major Wall Street firms targeted in wave of cyberattack attempts 

Posted in Commentary with tags on August 6, 2026 by itnerd

Hackers have launched a series of sophisticated cyberattack attempts targeting major Wall Street financial firms, including Point72 Asset Management, Citadel, Millennium Management and Two Sigma Investments with attackers attempting to gain access to internal information systems through voice phishing (vishing) and other social engineering techniques, according to Bloomberg.

Point72 notified investors that it was investigating the incident but said there were no initial indications that client information had been compromised.

   “Our security team responded quickly to an attempted vishing campaign targeting Two Sigma and other investment managers, and we have no indication of any impact to our data or our systems,” a Two Sigma spokesperson said in a statement.

The Financial Industry Regulatory Authority (FINRA) has contacted member firms regarding the recent attempted cyberattacks. Earlier this year, FINRA launched its Financial Intelligence Fusion Center, a secure platform for sharing cyber threat intelligence and coordinating responses to increasingly sophisticated cyber and fraud threats targeting financial services firms.

Phil Wylie, Senior Consultant & Evangelist, Suzu Labs:

“These attacks demonstrate that social engineering remains one of the most effective ways to bypass technical security controls. As attackers increasingly leverage AI and publicly available information to make vishing campaigns more convincing, organizations must strengthen identity verification processes and ensure employees are trained to verify requests rather than simply trust a familiar voice. The firms’ rapid detection also shows why layered defenses and intelligence sharing are critical for stopping these campaigns before they become breaches.”

Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:

“Modern phishing campaigns often start with publicly available information and can be combined with previous data exposures to build a targeted profile on potential victims. AI can analyze massive amounts of data quickly to build profiles that would take a skilled human days or weeks. AI has lowered the barrier for cybercrime. What once required years of experience can now be done with very little effort or technical knowledge. Humans are the weakest link in both data incidents and social engineering and as voice impersonation become more convincing, we will reach a point where we cannot trust what we hear or what we see.

   “Cybersecurity is no longer only about protecting networks and endpoints. It’s increasingly about protecting decision making and the primary defense starts with education and changing the culture of data protection. AI powered social engineering is designed to manipulate human judgment, and organizations must recognize that their workforce is now a primary attack surface. When the goal of cyber criminals if financial gain it is only logical that investment firms that manage sensitive financial information are attractive targets.”

You have to assume that you’re a target. Thus you need your defences are set up to repel that threat. Otherwise, you need to assume that you are going to get pwned. It is that simple.

Historic Black College Closed Due To Cyberattack And Other Reasons

Posted in Commentary with tags on May 10, 2022 by itnerd

The news is out that historic Black college Lincoln College is shutting down following financial woes amidst the pandemic which were magnified by a cyberattack attack last December:

Lincoln College has notified the Illinois Department of Higher Education and Higher Learning Commission of permanent closure, effective May 13, 2022. The Board of Trustees has voted to cease all academic programming at the end of the spring semester.

Lincoln College has survived many difficult and challenging times – the economic crisis of 1887, a major campus fire in 1912, the Spanish flu of 1918, the Great Depression, World War II, the 2008 global financial crisis, and more, but this is different. Lincoln College needs help to survive.

The institution experienced record-breaking student enrollment in Fall 2019, with residence halls at maximum capacity. Unfortunately, the coronavirus pandemic dramatically impacted recruitment and fundraising efforts, sporting events, and all campus life activities. The economic burdens initiated by the pandemic required large investments in technology and campus safety measures, as well as a significant drop in enrollment with students choosing to postpone college or take a leave of absence, which impacted the institution’s financial position.

Furthermore, Lincoln College was a victim of a cyberattack in December 2021 that thwarted admissions activities and hindered access to all institutional data, creating an unclear picture of Fall 2022 enrollment projections. All systems required for recruitment, retention, and fundraising efforts were inoperable. Fortunately, no personal identifying information was exposed. Once fully restored in March 2022, the projections displayed significant enrollment shortfalls, requiring a transformational donation or partnership to sustain Lincoln College beyond the current semester.

This illustrates the sort of damage that cyberattacks can have.

Saryu Nayyar, CEO and Founder of Gurucul had this to say about this unfortunate news:

“The impact of ransomware on relatively smaller organizations can be catastrophic. A 157-year-old institution already hampered by the impact of the pandemic having to shut down during a critical period due to ransomware is tragic. Ransomware has a much broader impact to business than simply the payment to restore services. There are plenty of other costs related to stolen and resold data, business availability and employee downtime that are virtually impossible to predict upfront but with no less impact. Organizations need to invest in the latest threat detection, investigation and response tools that can empower even smaller teams to rapidly detect attack campaigns such as ransomware early in the kill chain. This requires advanced analytics and trained machine learning (ML) with out-of-the-box detection capabilities to automate manual tasks and accelerate security analyst or engineer efforts before data is stolen and/or encrypted as a precursor to ransomware detonation.”

I hope that someone or some organization steps in to help them as it would be a shame if this historic Black college were allowed to close under these circumstances.