Tag: ports

  • Anubis Ransomware Hit on Adriatic Port Authority Exposes Maritime OT Risk

    Anubis Ransomware Hit on Adriatic Port Authority Exposes Maritime OT Risk

    Cybersecurity firm Resecurity has published research detailing a ransomware attack by the Anubis group against an Adriatic Port Authority, as reported by Industrial Cyber on June 16, 2026. The disclosure is being framed as a detailed look at how ransomware operators are reaching into maritime critical infrastructure — a sector where information technology (IT) systems and operational technology (OT, the systems that control physical processes like cranes, gates, and cargo handling) are increasingly intertwined.

    Executive Summary

    According to the report, threat-intelligence firm Resecurity has documented an intrusion attributed to Anubis — a ransomware-as-a-service operation that surfaced in underground markets in late 2024 and drew attention for pairing conventional encryption with a destructive file-wiping capability — against a port authority on the Adriatic coast. Port authorities are the public bodies that govern harbor operations, vessel traffic, and often the digital systems that commercial terminals depend on, which makes them an unusually consequential ransomware target.

    The significance is less the individual incident than what it illustrates: ports sit at the junction of national logistics, customs, energy imports, and military mobility, and a single compromised authority can ripple across all of them. Vendor research that documents such an attack in technical detail is valuable to defenders — though, as with any single-vendor disclosure, the claims that matter most (scope of access, operational impact, and how the intrusion happened) deserve independent confirmation, and the public reporting available at publication is thin on those specifics.

    Why Ports Are Ransomware’s Ideal Target

    Modern ports run on software to a degree that surprises outsiders. Terminal operating systems schedule every container move; gate systems decide which trucks enter; berth management coordinates vessel arrivals; customs and port-community platforms link the authority to shippers, freight forwarders, and government agencies. When ransomware locks those systems, cargo does not merely slow — it physically stops, because cranes and yard equipment have nowhere to be told to go. That is why the sector’s precedents are so costly: the 2017 NotPetya incident forced Maersk to rebuild its global IT estate at a cost the company put in the hundreds of millions of dollars, and ransomware halted container operations at Japan’s Port of Nagoya in 2023. An Adriatic port authority fits the same profile: high downtime costs, public-sector budget constraints, and a web of third-party connections that widens the attack surface.

    The OT dimension raises the stakes further. Even when attackers only encrypt IT systems, operators frequently shut down OT as a precaution because the boundary between the two is porous. The practical lesson for infrastructure operators of every kind — ports, data centers, utilities — is that segmentation between business networks and control networks is not a compliance checkbox; it is the difference between an expensive IT incident and a physical-operations outage.

    Anubis and the Economics of Destructive Ransomware

    Anubis is a relatively young ransomware-as-a-service brand — a model in which core developers lease their malware and infrastructure to affiliates who conduct the actual intrusions in exchange for a revenue share. What set Anubis apart in earlier security-industry reporting was a so-called wipe mode: the ability to destroy file contents outright rather than merely encrypt them. That capability changes the victim’s calculus. Classic ransomware is, in a grim sense, a negotiation with a counterparty that wants its decryptor to work; a wiper-equipped operator can credibly threaten permanent destruction, which increases pressure to pay quickly and raises the ceiling of potential damage if talks collapse.

    For a critical-infrastructure victim, that threat profile pushes the incident out of the purely financial category and toward something closer to sabotage risk. It also strengthens the case for offline, regularly tested backups — the one control that removes most of a wiper’s leverage — and for incident-response planning that assumes data may be unrecoverable from the attacker regardless of payment.

    What Vendor Research Does — and Doesn’t — Establish

    This disclosure comes from Resecurity, a commercial threat-intelligence firm, relayed through trade press. Vendor research is a legitimate and often essential channel — private firms frequently see intrusion details that victims and governments do not publish — but it also serves a marketing function, and readers should hold it to the same evidentiary standard as any other claim. The fair questions cut in every direction: Has the affected port authority confirmed the incident? Do the technical indicators trace to Anubis with high confidence, or by resemblance to known tooling? Was operational technology actually touched, or is OT exposure an inference from network architecture? The public reporting available at the time of writing — an aggregated headline and summary — does not settle any of these, and it would be a mistake to treat the incident’s most dramatic possible reading as established fact.

    The Regulatory Tide Meets the Waterline

    If the affected authority sits in an EU member state — as most Adriatic port authorities do — the incident lands squarely inside the NIS2 directive’s remit, the EU regime that designates ports as essential entities and imposes incident-reporting deadlines and management-level accountability for cyber risk. The International Maritime Organization has likewise required cyber risk to be addressed in ship and port safety-management systems since 2021. An incident like this one becomes a live test of whether those frameworks produce faster disclosure and better resilience in practice, or whether public understanding of critical-infrastructure attacks continues to depend on third-party security researchers publishing what victims will not.

    Background

    Anubis appeared in cybercrime markets around late 2024 as a ransomware-as-a-service brand and was flagged by multiple security researchers in 2025 for combining data-theft extortion with an optional file-destruction mode — an escalation from the encrypt-and-negotiate model that has dominated ransomware for a decade. Maritime targets have figured in ransomware history since NotPetya crippled Maersk in 2017, and attacks on the ports of Lisbon (2022) and Nagoya (2023) demonstrated that both port authorities and terminal operators are viable victims.

    The Adriatic coastline hosts significant EU trade gateways in Italy, Slovenia, and Croatia, making its port authorities essential entities under the EU’s NIS2 cybersecurity directive. Resecurity, the firm behind this disclosure, is a commercial threat-intelligence company that regularly publishes intrusion research on ransomware groups and critical-infrastructure targeting.

    Source: Resecurity details Anubis ransomware attack on Adriatic Port Authority, exposing maritime infrastructure risks — Industrial Cyber, reporting on Resecurity threat research into a ransomware intrusion at an Adriatic port authority, published June 16, 2026.

  • Offshore Nuclear Barges Eye California Ports and Data Centers

    Offshore Nuclear Barges Eye California Ports and Data Centers

    A concept for floating, offshore nuclear power barges is being pitched as a way to supply electricity to California ports and data centers, with proponents arguing that siting reactors in federal waters could avoid the state’s long-standing prohibition on new onshore nuclear plants. Fortune reported the proposal on June 16, 2026.

    Executive Summary

    The pitch pairs two trends: a resurgent interest in small, modular nuclear reactors and an acute shortage of firm, carbon-free power for AI-era data centers and electrified ports. By mounting reactors on barges moored offshore, developers argue they can deliver power directly to coastal customers behind the meter — meaning the electricity flows to the buyer without traversing the public grid — while operating under federal rather than state jurisdiction.

    The stakes are significant for California, where data center operators and port electrification programs are competing for the same constrained grid capacity, and where the state’s 1976 moratorium on new nuclear construction has effectively frozen a category of firm, low-carbon generation. Whether an offshore barge genuinely sits outside that moratorium — legally, politically, and practically — is the central question the proposal raises.

    Why Offshore, and Why Now

    The appeal is straightforward on paper. California data center demand is rising with generative AI workloads, and the state’s largest ports — Los Angeles, Long Beach, and Oakland — are under pressure to electrify cargo handling and shore power for docked ships. Both need round-the-clock electricity that solar and wind alone cannot provide without significant storage. A barge-mounted reactor delivered to a mooring can, in principle, be built in a shipyard, towed into place, and connected to a single large customer, compressing the multi-year permitting and construction timelines that plague land-based projects.

    Offshore siting also reframes the political map. State moratoria on new nuclear plants apply on land; federal waters begin three nautical miles from shore in most of California. A vessel-based reactor could plausibly be regulated primarily by federal agencies — the Nuclear Regulatory Commission and, for a marine platform, the Coast Guard — rather than the state. That is the crux of the sidestep argument, and it will be tested by lawyers long before it is tested by engineers.

    The Behind-the-Meter Economics

    Behind-the-meter power arrangements let a generator sell electricity directly to a co-located customer, bypassing utility tariffs and, often, transmission queues that now stretch years. For hyperscale data center operators, that shortcut has become the single most valuable feature of any new generation project, which is why they have signed deals for restarted nuclear plants and are exploring small modular reactors on their own campuses. An offshore barge extends the same logic to sites that lack the land for on-site generation.

    The economics still have to close. Marine nuclear platforms carry costs that land plants do not: marinization of equipment, mooring and undersea cable systems, corrosion management, and specialized crews. They also inherit the industry’s chronic problem — first-of-a-kind small reactors have consistently come in above their initial cost estimates. Whether the shipyard-build efficiencies proponents cite can offset those headwinds is unproven at commercial scale.

    Regulation, Siting, and the Politics of a Workaround

    Framing a project as a jurisdictional workaround invites the jurisdiction being worked around to push back. California has other levers even if the reactor sits in federal waters: the California Coastal Commission reviews activities affecting the coastal zone, cable landings require state and local permits, and the electricity buyer on shore is a regulated entity. A project marketed primarily as a way to avoid state law is likely to draw sharper scrutiny than one that engages the state on its merits.

    There are also legitimate questions to ask of critics as well as proponents. Opposition to nuclear in California has historically blended safety, seismic, and waste concerns with broader anti-industrial sentiment, and the coalition that upheld the 1976 moratorium is not monolithic. A fair debate requires pressing both sides: proponents on safety, security, and decommissioning of a marine reactor; opponents on what alternative firm, low-carbon supply they propose for the same coastal loads on the same timeline.

    Background

    California enacted its moratorium on new nuclear construction in 1976, tying future approvals to a federal solution for high-level radioactive waste that has not materialized. The state’s last operating commercial nuclear plant, Diablo Canyon, was scheduled to retire but received a life extension amid grid reliability concerns. Meanwhile, AI-driven data center demand and port electrification are straining coastal grid capacity.

    Interest in small modular reactors and factory-built nuclear designs has revived globally, with hyperscale technology companies signing power deals for restarted plants and exploring on-site reactors. Marine nuclear propulsion has decades of naval history, and Russia has operated a civilian floating nuclear plant since 2020, but no comparable commercial offshore reactor has been deployed in U.S. waters.

    Source: Offshore nuclear barges could power ports and data centers—starting with California, where nuclear is banned — Fortune reports on a proposal to moor small reactors offshore to serve California ports and data centers.