EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30 22:00 UTCTLP:CLEAR
incidenthighcontained
Rotterdam & Antwerp Maritime Terminal Automation Freeze
EXECUTIVE INTELLIGENCE SUMMARY
Disruption of automated container crane telemetry and berth allocation SCADA controllers via malicious IEC-104 protocol packet floods.
Sandworm (Unit 74455) targeted port logistics orchestration systems across Western Europe. Utilizing custom living-off-the-land industrial control scripts, attackers forged automated mooring relay commands, forcing container cranes into failsafe emergency stop states and creating 48-hour container backlog congestion.
PHASED INCIDENT CHRONOLOGY
PHASE: Exploitation•2026-08-24 03:10 UTC
OT Network Segment Ingress via Compromised VPN
Attackers pivot from administrative subnet into terminal SCADA VLAN.
PHASE: Mitigation•2026-08-25 09:45 UTC
Manual Air-Gapping & Terminal Failover
Port operations transitioned to isolated manual loading manifests while PLC memory was verified.
VERIFIED PROVENANCE TRAIL1 INDEPENDENT ATTESTATIONS
“Direct manipulation of IEC 60870-5-104 telemetry commands.”
security_lab•2026-08-25•97% CONFIDENCE
Mandiant ICS Threat Team
Identified crafted APDU commands sent to ABB and Siemens RTU relays.
SOURCE CITATIONS & ATTESTATIONS (1)
ENISA Industrial Cybersecurity BulletinENISA
Maritime Port Automation Cyber Resilience Review
TELEMETRY CARDID: inc-2026-0809
ENTITY TYPE
incident
COORDINATES
51.9244, 4.4777 (Netherlands)
INDEXED TAGS
#maritime#scada#ics#sandworm#logistics#port_automation
CONNECTED ENTITIES (2)VIEW IN GRAPH →