www.resecurity.com Anubis Ransomware Attack Disrupts Adriatic Port Authority Operations
Article Content
- •Anubis ransomware attacked the Adriatic Port Authority, demanding a $10 million ransom.
- •The attack began on December 11, 2025, and was confirmed by Anubis in January 2026.
- •Exploited vulnerabilities included insecure cloud accounts and spear-phishing tactics.
The Anubis ransomware group launched a cyberattack on the Adriatic Port Authority, crippling operations and causing significant disruptions in maritime logistics. The attack, attributed to Anubis in January 2026, reportedly began on December 11, 2025, and resulted in a $10 million Bitcoin ransom demand. Resecurity noted that the attack compromised 2% of the port's data, with backups preserving the majority. Stolen information included contracts, employee records, and sensitive port safety plans. The attackers gained access through a spear-phishing email targeting port management staff, exploiting IT vulnerabilities rather than operational technology. This incident highlights the growing threat to maritime infrastructure amid increasing digitalization. Resecurity predicts a rise in similar attacks through 2030 due to geopolitical tensions and the expanding attack surface in the sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track Anubis, Adriatic Port Authority and CVE-2025-26399 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Ransomware Attacks Target Companies in September 2026 On September 15, 2026, the ransomware group ShadowByt3$ claimed to have compromised HandyTrac, a company in Greystar Litchfield Park, AZ, alleging access to sensitive data including employee credentials and financial records. The group demanded negotiation within 72 hours to avoid publishing the data. On the same day…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…