<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="https://www.jain.com/assets/img/6adafce5-1.1"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anubis &#8211; Jain.com</title>
	<atom:link href="/tag/anubis/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Data centers, connectivity, and security — news and analysis</description>
	<lastBuildDate>Tue, 16 Jun 2026 16:00:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2026/08/jain-com-icon-512-150x150.png</url>
	<title>Anubis &#8211; Jain.com</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Anubis Ransomware Hit on Adriatic Port Authority Exposes Maritime OT Risk</title>
		<link>/anubis-ransomware-adriatic-port-authority-maritime-ot-risk/</link>
		
		<dc:creator><![CDATA[Deepak Jain]]></dc:creator>
		<pubDate>Tue, 16 Jun 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Anubis]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[maritime cybersecurity]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OT security]]></category>
		<category><![CDATA[ports]]></category>
		<category><![CDATA[ransomware]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">/anubis-ransomware-adriatic-port-authority-maritime-ot-risk/</guid>

					<description><![CDATA[Anubis ransomware struck an Adriatic Port Authority, according to Resecurity research detailed in June 2026 — a case study in maritime cyber exposure. We examine what the report substantiates, why ports concentrate IT and OT risk, and the material questions the disclosure leaves unanswered.]]></description>
										<content:encoded><![CDATA[<div class="jain-post-grid">
<div class="jain-post-main">
<p>Cybersecurity firm Resecurity has published research detailing a ransomware attack by the Anubis group against an Adriatic Port Authority, as reported by Industrial Cyber on June 16, 2026. The disclosure is being framed as a detailed look at how ransomware operators are reaching into maritime critical infrastructure — a sector where information technology (IT) systems and operational technology (OT, the systems that control physical processes like cranes, gates, and cargo handling) are increasingly intertwined.</p>
<h2>Executive Summary</h2>
<p>According to the report, threat-intelligence firm Resecurity has documented an intrusion attributed to Anubis — a ransomware-as-a-service operation that surfaced in underground markets in late 2024 and drew attention for pairing conventional encryption with a destructive file-wiping capability — against a port authority on the Adriatic coast. Port authorities are the public bodies that govern harbor operations, vessel traffic, and often the digital systems that commercial terminals depend on, which makes them an unusually consequential ransomware target.</p>
<p>The significance is less the individual incident than what it illustrates: ports sit at the junction of national logistics, customs, energy imports, and military mobility, and a single compromised authority can ripple across all of them. Vendor research that documents such an attack in technical detail is valuable to defenders — though, as with any single-vendor disclosure, the claims that matter most (scope of access, operational impact, and how the intrusion happened) deserve independent confirmation, and the public reporting available at publication is thin on those specifics.</p>
<h2>Why Ports Are Ransomware&#8217;s Ideal Target</h2>
<p>Modern ports run on software to a degree that surprises outsiders. Terminal operating systems schedule every container move; gate systems decide which trucks enter; berth management coordinates vessel arrivals; customs and port-community platforms link the authority to shippers, freight forwarders, and government agencies. When ransomware locks those systems, cargo does not merely slow — it physically stops, because cranes and yard equipment have nowhere to be told to go. That is why the sector&#8217;s precedents are so costly: the 2017 NotPetya incident forced Maersk to rebuild its global IT estate at a cost the company put in the hundreds of millions of dollars, and ransomware halted container operations at Japan&#8217;s Port of Nagoya in 2023. An Adriatic port authority fits the same profile: high downtime costs, public-sector budget constraints, and a web of third-party connections that widens the attack surface.</p>
<p>The OT dimension raises the stakes further. Even when attackers only encrypt IT systems, operators frequently shut down OT as a precaution because the boundary between the two is porous. The practical lesson for infrastructure operators of every kind — ports, data centers, utilities — is that segmentation between business networks and control networks is not a compliance checkbox; it is the difference between an expensive IT incident and a physical-operations outage.</p>
<h2>Anubis and the Economics of Destructive Ransomware</h2>
<p>Anubis is a relatively young ransomware-as-a-service brand — a model in which core developers lease their malware and infrastructure to affiliates who conduct the actual intrusions in exchange for a revenue share. What set Anubis apart in earlier security-industry reporting was a so-called wipe mode: the ability to destroy file contents outright rather than merely encrypt them. That capability changes the victim&#8217;s calculus. Classic ransomware is, in a grim sense, a negotiation with a counterparty that wants its decryptor to work; a wiper-equipped operator can credibly threaten permanent destruction, which increases pressure to pay quickly and raises the ceiling of potential damage if talks collapse.</p>
<p>For a critical-infrastructure victim, that threat profile pushes the incident out of the purely financial category and toward something closer to sabotage risk. It also strengthens the case for offline, regularly tested backups — the one control that removes most of a wiper&#8217;s leverage — and for incident-response planning that assumes data may be unrecoverable from the attacker regardless of payment.</p>
<h2>What Vendor Research Does — and Doesn&#8217;t — Establish</h2>
<p>This disclosure comes from Resecurity, a commercial threat-intelligence firm, relayed through trade press. Vendor research is a legitimate and often essential channel — private firms frequently see intrusion details that victims and governments do not publish — but it also serves a marketing function, and readers should hold it to the same evidentiary standard as any other claim. The fair questions cut in every direction: Has the affected port authority confirmed the incident? Do the technical indicators trace to Anubis with high confidence, or by resemblance to known tooling? Was operational technology actually touched, or is OT exposure an inference from network architecture? The public reporting available at the time of writing — an aggregated headline and summary — does not settle any of these, and it would be a mistake to treat the incident&#8217;s most dramatic possible reading as established fact.</p>
<h2>The Regulatory Tide Meets the Waterline</h2>
<p>If the affected authority sits in an EU member state — as most Adriatic port authorities do — the incident lands squarely inside the NIS2 directive&#8217;s remit, the EU regime that designates ports as essential entities and imposes incident-reporting deadlines and management-level accountability for cyber risk. The International Maritime Organization has likewise required cyber risk to be addressed in ship and port safety-management systems since 2021. An incident like this one becomes a live test of whether those frameworks produce faster disclosure and better resilience in practice, or whether public understanding of critical-infrastructure attacks continues to depend on third-party security researchers publishing what victims will not.</p>
<h2>Background</h2>
<p>Anubis appeared in cybercrime markets around late 2024 as a ransomware-as-a-service brand and was flagged by multiple security researchers in 2025 for combining data-theft extortion with an optional file-destruction mode — an escalation from the encrypt-and-negotiate model that has dominated ransomware for a decade. Maritime targets have figured in ransomware history since NotPetya crippled Maersk in 2017, and attacks on the ports of Lisbon (2022) and Nagoya (2023) demonstrated that both port authorities and terminal operators are viable victims.</p>
<p>The Adriatic coastline hosts significant EU trade gateways in Italy, Slovenia, and Croatia, making its port authorities essential entities under the EU&#8217;s NIS2 cybersecurity directive. Resecurity, the firm behind this disclosure, is a commercial threat-intelligence company that regularly publishes intrusion research on ransomware groups and critical-infrastructure targeting.</p>
<p>Source: <a href="https://news.google.com/rss/articles/CBMi4AFBVV95cUxPZ3UxMWNUd1ZLUmktbmh1TTBTOEdULTZBVmFzamEzODJGVkpWVkd2RUk2emh0R3lxZTBLSmNvM1l3Y2hPeXc1T1VicGNoNEZFN0ZBTXlvTWwxQy1NbHB4Vm9tY0E0YXIzdloyZVEyeGl0OUxlWFJTdmZ6YnYwejFJMWFMMjlLdDNKNUFwSjgyQzFJM09BYkhpLXd2ZXFHeTdIU2JiVWYwYXRsWlJYMk1PaEgxUGFHMnhpVUF4WUo1UWQwdFhpZ0hoYmlxekJSWVd2M25WQWVGa0hkbWJKbWJYQg?oc=5">Resecurity details Anubis ransomware attack on Adriatic Port Authority, exposing maritime infrastructure risks — Industrial Cyber</a>, reporting on Resecurity threat research into a ransomware intrusion at an Adriatic port authority, published June 16, 2026.</p>
</div>
<aside class="jain-rail">
<section class="jain-gaps" aria-label="What the release does not say">
<p class="jain-gaps-kicker"><img src="https://www.jain.com/assets/img/dbaaff79-26a0.png" alt="⚠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> What They Aren’t Saying</p>
<h2>What the Release Doesn&#8217;t Say</h2>
<ul>
<li><strong>Victim identity and confirmation:</strong> the reporting names an &#8220;Adriatic Port Authority&#8221; without specifying which port or country, and there is no indication of confirmation from the victim organization or a national authority.</li>
<li><strong>Operational impact:</strong> it is unclear whether cargo handling, vessel traffic, or other port operations were disrupted, for how long, or whether OT systems were directly affected versus IT systems only.</li>
<li><strong>Intrusion specifics:</strong> the initial access vector, dwell time, data exfiltration, any ransom demand, and whether payment occurred are all unaddressed in the available public summary.</li>
<li><strong>Attribution confidence:</strong> the basis for attributing the attack to Anubis — shared infrastructure, malware samples, or leak-site claims — is not described in the aggregated reporting, nor is whether regulators were notified under applicable EU rules.</li>
</ul>
</section>
<section class="jain-faq">
<h2>Frequently Asked Questions</h2>
<h3>What happened to the Adriatic Port Authority?</h3>
<p>According to research by cybersecurity firm Resecurity, reported by Industrial Cyber on June 16, 2026, the port authority was hit by ransomware attributed to the Anubis group. The publicly available summary does not specify which Adriatic port was affected or whether operations were disrupted.</p>
<h3>What is Anubis ransomware?</h3>
<p>Anubis is a ransomware-as-a-service operation that emerged in underground forums around late 2024. It leases its malware to affiliate attackers and drew particular attention for a destructive wipe mode that can permanently destroy file contents rather than only encrypting them.</p>
<h3>What makes a wiper-capable ransomware more dangerous than ordinary ransomware?</h3>
<p>Ordinary ransomware relies on the victim believing files can be recovered after payment. A wiper-equipped operator can credibly threaten irreversible destruction, which raises pressure on victims, increases worst-case damage, and pushes incidents closer to sabotage than extortion.</p>
<h3>Who is Resecurity?</h3>
<p>Resecurity is a commercial cybersecurity and threat-intelligence firm that publishes research on cybercrime groups and intrusions. Its report is the source of this disclosure; like all single-vendor research, its most consequential claims benefit from independent confirmation.</p>
<h3>What is a port authority and why does it matter as a cyber target?</h3>
<p>A port authority is the public body that governs a harbor — vessel traffic, berths, gates, and often shared digital platforms that terminals, customs, and shippers depend on. Compromising one can ripple across an entire regional supply chain, which is what makes it an attractive target.</p>
<h3>What is OT, and how does it differ from IT?</h3>
<p>Operational technology (OT) refers to systems that control physical processes — cranes, gates, sensors, industrial equipment — while IT covers business computing like email and databases. In ports the two are increasingly connected, so an IT breach can force precautionary OT shutdowns.</p>
<h3>Did the attack disrupt port operations?</h3>
<p>The publicly available reporting does not say. Neither operational impact, downtime, nor whether OT systems were directly affected is described in the aggregated summary, and no confirmation from the port authority itself appears in the available material.</p>
<h3>Has ransomware hit ports before?</h3>
<p>Yes. The 2017 NotPetya attack cost shipping giant Maersk hundreds of millions of dollars, ransomware halted container operations at Japan&#8217;s Port of Nagoya in 2023, and the Port of Lisbon was attacked in 2022. Maritime logistics has a well-established ransomware track record.</p>
<h3>Why are ports considered critical infrastructure?</h3>
<p>Ports concentrate national logistics, energy imports, customs revenue, and in many countries military mobility. A prolonged outage at a major port cascades into shortages, shipping delays, and economic losses far beyond the port itself, which is why governments regulate their security.</p>
<h3>What EU rules apply to a cyberattack on a European port?</h3>
<p>The NIS2 directive designates ports as essential entities, requiring risk management, management accountability, and rapid incident reporting to national authorities. The IMO has also required cyber risk to be addressed in maritime safety-management systems since 2021.</p>
<h3>How confident is the attribution to Anubis?</h3>
<p>The available summary does not describe the evidentiary basis — such as malware samples, shared infrastructure, or a leak-site posting. Attribution by resemblance to known tooling is weaker than attribution from direct forensic evidence, and the report&#8217;s detail level is not publicly clear.</p>
<h3>What is ransomware-as-a-service?</h3>
<p>It is a criminal business model in which core developers build the malware, payment infrastructure, and leak sites, then lease them to affiliates who carry out intrusions in exchange for a share of ransom proceeds. It lowers the skill barrier and multiplies the number of active attackers.</p>
<h3>What should infrastructure operators take away from this incident?</h3>
<p>Segment business IT from operational networks, maintain offline and regularly tested backups that neutralize wiper leverage, harden third-party and remote-access connections, and rehearse incident response that assumes attacker-held data is unrecoverable regardless of payment.</p>
<h3>Why does so much critical-infrastructure incident reporting come from security vendors?</h3>
<p>Victims and governments often disclose little, while commercial threat-intelligence firms see technical details through their monitoring and publish them — partly as a public service, partly as marketing. That makes vendor research valuable but worth reading with independent scrutiny.</p>
</section>
</aside>
</div>
<p><script type="application/ld+json">{"@context": "https://schema.org", "@graph": [{"@type": "NewsArticle", "headline": "Anubis Ransomware Hit on Adriatic Port Authority Exposes Maritime OT Risk", "description": "Anubis ransomware struck an Adriatic Port Authority, according to Resecurity research detailed in June 2026 \u2014 a case study in maritime cyber exposure. We examine what the report substantiates, why ports concentrate IT and OT risk, and the material questions the disclosure leaves unanswered.", "image": ["/wp-content/uploads/2026/08/anubis-ransomware-adriatic-port-maritime-infrastructure.png"], "author": {"@type": "Organization", "name": "jain.com Editorial"}, "datePublished": "2026-08-23T05:29:39.131515+00:00"}, {"@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What happened to the Adriatic Port Authority?", "acceptedAnswer": {"@type": "Answer", "text": "According to research by cybersecurity firm Resecurity, reported by Industrial Cyber on June 16, 2026, the port authority was hit by ransomware attributed to the Anubis group. The publicly available summary does not specify which Adriatic port was affected or whether operations were disrupted."}}, {"@type": "Question", "name": "What is Anubis ransomware?", "acceptedAnswer": {"@type": "Answer", "text": "Anubis is a ransomware-as-a-service operation that emerged in underground forums around late 2024. It leases its malware to affiliate attackers and drew particular attention for a destructive wipe mode that can permanently destroy file contents rather than only encrypting them."}}, {"@type": "Question", "name": "What makes a wiper-capable ransomware more dangerous than ordinary ransomware?", "acceptedAnswer": {"@type": "Answer", "text": "Ordinary ransomware relies on the victim believing files can be recovered after payment. A wiper-equipped operator can credibly threaten irreversible destruction, which raises pressure on victims, increases worst-case damage, and pushes incidents closer to sabotage than extortion."}}, {"@type": "Question", "name": "Who is Resecurity?", "acceptedAnswer": {"@type": "Answer", "text": "Resecurity is a commercial cybersecurity and threat-intelligence firm that publishes research on cybercrime groups and intrusions. Its report is the source of this disclosure; like all single-vendor research, its most consequential claims benefit from independent confirmation."}}, {"@type": "Question", "name": "What is a port authority and why does it matter as a cyber target?", "acceptedAnswer": {"@type": "Answer", "text": "A port authority is the public body that governs a harbor \u2014 vessel traffic, berths, gates, and often shared digital platforms that terminals, customs, and shippers depend on. Compromising one can ripple across an entire regional supply chain, which is what makes it an attractive target."}}, {"@type": "Question", "name": "What is OT, and how does it differ from IT?", "acceptedAnswer": {"@type": "Answer", "text": "Operational technology (OT) refers to systems that control physical processes \u2014 cranes, gates, sensors, industrial equipment \u2014 while IT covers business computing like email and databases. In ports the two are increasingly connected, so an IT breach can force precautionary OT shutdowns."}}, {"@type": "Question", "name": "Did the attack disrupt port operations?", "acceptedAnswer": {"@type": "Answer", "text": "The publicly available reporting does not say. Neither operational impact, downtime, nor whether OT systems were directly affected is described in the aggregated summary, and no confirmation from the port authority itself appears in the available material."}}, {"@type": "Question", "name": "Has ransomware hit ports before?", "acceptedAnswer": {"@type": "Answer", "text": "Yes. The 2017 NotPetya attack cost shipping giant Maersk hundreds of millions of dollars, ransomware halted container operations at Japan's Port of Nagoya in 2023, and the Port of Lisbon was attacked in 2022. Maritime logistics has a well-established ransomware track record."}}, {"@type": "Question", "name": "Why are ports considered critical infrastructure?", "acceptedAnswer": {"@type": "Answer", "text": "Ports concentrate national logistics, energy imports, customs revenue, and in many countries military mobility. A prolonged outage at a major port cascades into shortages, shipping delays, and economic losses far beyond the port itself, which is why governments regulate their security."}}, {"@type": "Question", "name": "What EU rules apply to a cyberattack on a European port?", "acceptedAnswer": {"@type": "Answer", "text": "The NIS2 directive designates ports as essential entities, requiring risk management, management accountability, and rapid incident reporting to national authorities. The IMO has also required cyber risk to be addressed in maritime safety-management systems since 2021."}}, {"@type": "Question", "name": "How confident is the attribution to Anubis?", "acceptedAnswer": {"@type": "Answer", "text": "The available summary does not describe the evidentiary basis \u2014 such as malware samples, shared infrastructure, or a leak-site posting. Attribution by resemblance to known tooling is weaker than attribution from direct forensic evidence, and the report's detail level is not publicly clear."}}, {"@type": "Question", "name": "What is ransomware-as-a-service?", "acceptedAnswer": {"@type": "Answer", "text": "It is a criminal business model in which core developers build the malware, payment infrastructure, and leak sites, then lease them to affiliates who carry out intrusions in exchange for a share of ransom proceeds. It lowers the skill barrier and multiplies the number of active attackers."}}, {"@type": "Question", "name": "What should infrastructure operators take away from this incident?", "acceptedAnswer": {"@type": "Answer", "text": "Segment business IT from operational networks, maintain offline and regularly tested backups that neutralize wiper leverage, harden third-party and remote-access connections, and rehearse incident response that assumes attacker-held data is unrecoverable regardless of payment."}}, {"@type": "Question", "name": "Why does so much critical-infrastructure incident reporting come from security vendors?", "acceptedAnswer": {"@type": "Answer", "text": "Victims and governments often disclose little, while commercial threat-intelligence firms see technical details through their monitoring and publish them \u2014 partly as a public service, partly as marketing. That makes vendor research valuable but worth reading with independent scrutiny."}}]}]}</script></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
