Port Ransomware Reaches Through Cloud Identity

A port can be forced into disruption without anyone touching cranes or other industrial gear. The weak point here is ordinary IT access: phishing and cloud-admin accounts can give attackers a path into core systems, so restoring files from backup does not erase the leverage they already gained. Resecurity says Anubis got into the Adriatic Port Authority through staff phishing and then moved through cloud and office accounts tied to Office 365 and Azure. The port authority says the breach dates to December 11, 2025, with about 2% of data lost and most of the rest preserved from backups; Resecurity says the attack still caused vessel rerouting, a $10 million ransom demand, and theft of port safety plans, security details, and employee records. That shifts the threat from data loss to operational pressure. If identity systems and admin accounts are the doorway, a port can be disrupted, extorted, and mined for sensitive logistics data even when the physical-control systems stay untouched.

Part of the PlainSec briefing for 2026-06-18

Sources