Ransomware

DP World Australia Port Operations Cyberattack β€” 3-Day Freight Disruption

πŸ“… 2023-11-10 🏒 DP World Australia port operations technology
Primary Source β†—

Incident Details

On 10 November 2023, DP World Australia β€” one of Australia’s largest port operators, managing approximately 40% of Australian container port operations across Port Botany (Sydney), Port Melbourne, Brisbane, and Fremantle β€” discovered a cyberattack that forced the shutdown of its Australian port operations. DP World disconnected its systems from the internet and halted port operations for approximately 3 days (10-13 November 2023) to contain the attack. The disruption stranded approximately 30,000 shipping containers that could not be loaded or unloaded. The Australian National Cyber Security Coordinator (NCSC) coordinated the government response, with the Australian Federal Police and Australian Signals Directorate providing assistance. DP World confirmed that some data was exfiltrated. Operations gradually resumed from 13 November 2023 but delays persisted for weeks as backlogs were cleared. The incident highlighted the critical importance of port operations to the Australian economy and supply chain, and the severe economic impact of operational technology attacks on maritime infrastructure. The Coordinator acknowledged that DP World handles approximately 40% of Australia’s containerised goods. The attack prompted the Australian Government to accelerate development of its Cyber Security Strategy for critical infrastructure operators.

Technical Details

Initial Attack Vector
Unknown attacker (ALPHV/BlackCat ransomware suspected) gained access to DP World Australia's internal IT network by exploiting a vulnerability in internet-facing systems; the attack disrupted the operational technology systems managing container movements
Vendor / Product
DP World Australia port operations technology

Timeline

  1. 2023-11-10 Breach occurred
  2. 2023-11-13 Publicly disclosed