The Anubis ransomware group breached the Adriatic Port Authority, which operates the Italian port of Ancona, in an intrusion that reportedly began with a spear-phishing attack on December 11, 2025 and was publicly attributed after the victim appeared on the gang’s leak site in January 2026. Reporting indicates the attackers moved through the authority’s IT environment rather than operational technology systems and exfiltrated a limited set of data, including employee records and sensitive port security-related documents.
Security researchers said the compromise may have been enabled by weak cloud account protections in Office 365 and Azure, alongside broader exposure to unpatched internet-facing systems commonly exploited by ransomware-as-a-service operators. The incident has been highlighted as a warning for the maritime sector, where aging IT infrastructure and comparatively low cyber maturity continue to leave port authorities vulnerable to disruptive and data-theft-focused attacks.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Resecurity published an analysis examining the Anubis attack on the Adriatic Port Authority. The report described operational disruption, vessel rerouting, a reported $10 million bitcoin ransom demand, and likely weaknesses involving Office 365 and Azure accounts.
The attack was attributed to Anubis in January 2026 after the group listed the Adriatic Port Authority on its leak site and leaked stolen data. Reported stolen material included employee records, contracts, and sensitive port security-related documents.
The Adriatic Port Authority said the breach dated back to December 11, 2025. Resecurity assessed the intrusion likely began with a spear-phishing email and later spread through core IT systems.
Anubis launched an affiliate program as part of its ransomware-as-a-service operation. The group reportedly offered different revenue shares for ransomware deployment, data extortion, and initial access brokering.
The Anubis ransomware group emerged as a new threat actor. The reporting notes it is distinct from the older Android banking malware that used the same name.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.