Anubis Ransomware Attack Disrupts Adriatic Port Authority Operations

Anubis Ransomware Attack Disrupts Adriatic Port Authority Operations

First seen 15 Jun 2026, 16:37 UTC Infosecurity-MagazineIndustrialcyber.Cowww.porto.ancona.itMbtmagThedefensepost+3 89% similarity 69.5

Article Content

Browse articles
ThreatCluster

The Anubis ransomware group launched a cyberattack on the Adriatic Port Authority, crippling operations and causing significant disruptions in maritime logistics. The attack, attributed to Anubis in January 2026, reportedly began on December 11, 2025, and resulted in a $10 million Bitcoin ransom demand. Resecurity noted that the attack compromised 2% of the port's data, with backups preserving the majority. Stolen information included contracts, employee records, and sensitive port safety plans. The attackers gained access through a spear-phishing email targeting port management staff, exploiting IT vulnerabilities rather than operational technology. This incident highlights the growing threat to maritime infrastructure amid increasing digitalization. Resecurity predicts a rise in similar attacks through 2030 due to geopolitical tensions and the expanding attack surface in the sector.

Key Points: • Anubis ransomware attacked the Adriatic Port Authority, demanding a $10 million ransom. • The attack began on December 11, 2025, and was confirmed by Anubis in January 2026. • Exploited vulnerabilities included insecure cloud accounts and spear-phishing tactics.

ThreatCluster AI How this analysis works

Timeline

2025-05-27
Public exploit for CVE-2025-5777 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2025-09-23
CVE-2025-26399 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-11
Anubis ransomware attack initiated
The cyberattack on the Adriatic Port Authority began, leading to operational disruptions.
Infosecurity-Magazine
2026-01-01
Anubis claims responsibility
The Anubis group claimed the attack and leaked data on their site, revealing sensitive information.
Infosecurity-Magazine
2026-06-15
Resecurity analysis published
Resecurity released a detailed analysis of the attack, highlighting operational impacts and vulnerabilities exploited.
www.resecurity.com

Community

Browse all →