Ransomware
DP World Australia Port Operations Cyberattack β 3-Day Freight Disruption
Primary Source βIncident Details
On 10 November 2023, DP World Australia β one of Australia’s largest port operators, managing approximately 40% of Australian container port operations across Port Botany (Sydney), Port Melbourne, Brisbane, and Fremantle β discovered a cyberattack that forced the shutdown of its Australian port operations. DP World disconnected its systems from the internet and halted port operations for approximately 3 days (10-13 November 2023) to contain the attack. The disruption stranded approximately 30,000 shipping containers that could not be loaded or unloaded. The Australian National Cyber Security Coordinator (NCSC) coordinated the government response, with the Australian Federal Police and Australian Signals Directorate providing assistance. DP World confirmed that some data was exfiltrated. Operations gradually resumed from 13 November 2023 but delays persisted for weeks as backlogs were cleared. The incident highlighted the critical importance of port operations to the Australian economy and supply chain, and the severe economic impact of operational technology attacks on maritime infrastructure. The Coordinator acknowledged that DP World handles approximately 40% of Australia’s containerised goods. The attack prompted the Australian Government to accelerate development of its Cyber Security Strategy for critical infrastructure operators.
Technical Details
- Initial Attack Vector
- Unknown attacker (ALPHV/BlackCat ransomware suspected) gained access to DP World Australia's internal IT network by exploiting a vulnerability in internet-facing systems; the attack disrupted the operational technology systems managing container movements
- Vendor / Product
- DP World Australia port operations technology
Timeline
- 2023-11-10 Breach occurred
- 2023-11-13 Publicly disclosed