DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30 22:00 UTC
incidenthighcontained

Rotterdam & Antwerp Maritime Terminal Automation Freeze

EXECUTIVE INTELLIGENCE SUMMARY

Disruption of automated container crane telemetry and berth allocation SCADA controllers via malicious IEC-104 protocol packet floods.

Sandworm (Unit 74455) targeted port logistics orchestration systems across Western Europe. Utilizing custom living-off-the-land industrial control scripts, attackers forged automated mooring relay commands, forcing container cranes into failsafe emergency stop states and creating 48-hour container backlog congestion.

PHASED INCIDENT CHRONOLOGY
PHASE: Exploitation2026-08-24 03:10 UTC
OT Network Segment Ingress via Compromised VPN

Attackers pivot from administrative subnet into terminal SCADA VLAN.

PHASE: Mitigation2026-08-25 09:45 UTC
Manual Air-Gapping & Terminal Failover

Port operations transitioned to isolated manual loading manifests while PLC memory was verified.

VERIFIED PROVENANCE TRAIL1 INDEPENDENT ATTESTATIONS
Direct manipulation of IEC 60870-5-104 telemetry commands.
security_lab2026-08-2597% CONFIDENCE
Mandiant ICS Threat Team

Identified crafted APDU commands sent to ABB and Siemens RTU relays.

SOURCE CITATIONS & ATTESTATIONS (1)
ENISA Industrial Cybersecurity BulletinENISA

Maritime Port Automation Cyber Resilience Review

TELEMETRY CARDID: inc-2026-0809
ENTITY TYPE
incident
COORDINATES
51.9244, 4.4777 (Netherlands)
INDEXED TAGS
#maritime#scada#ics#sandworm#logistics#port_automation