Recent reports highlight the increasing cybersecurity risks facing critical infrastructure and industrial sectors, with a particular focus on manufacturing and maritime operations. In manufacturing, attackers are shifting tactics, with a Sophos survey revealing that exploited vulnerabilities and malicious emails remain primary entry points. While the rate of ransomware attacks resulting in data encryption has decreased, there is a notable rise in data theft and extortion, with attackers leveraging the threat of disclosure rather than just encryption. The financial and operational impact remains severe, with median ransom payments reaching $1 million and average recovery costs at $1.3 million, underscoring the need for layered defenses and continuous visibility.
In the maritime sector, vulnerabilities in port infrastructure pose significant risks to supply chains and national security. The example of the Orange Star vessel at Port Elizabeth illustrates how a single cyber incident could disrupt the supply of essential goods to millions. The expiration of the Cybersecurity Information Sharing Act and recent ransomware attacks, such as the one at the Port of Seattle, have exacerbated concerns. New regulatory requirements are prompting some ports to enhance their cybersecurity posture, but many facilities remain underprepared, creating a "perfect storm of vulnerability" that could be exploited by nation-state actors with pre-positioned malware.

See the actors and campaigns active against you right now.
4 events from the most recent confirmed update back to the earliest known activity.
Sophos released a report based on a global survey of 332 IT and security leaders, finding that manufacturing ransomware attacks increasingly exploit vulnerabilities and malicious emails while data theft and extortion without encryption are rising.
New Title 33 CFR cybersecurity regulations were introduced requiring roughly 3,000 MTSA-regulated facilities to designate cybersecurity officers, marking a significant regulatory response to maritime cyber risk.
In late 2024, the Port of Seattle suffered a ransomware attack, underscoring the growing cyber risk facing port infrastructure and maritime supply chains.
In 2023, a LockBit ransomware incident affected the Port of Nagoya in Japan, demonstrating the potential for cyberattacks to disrupt major maritime logistics and supply chains.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.