Anubis Ransomware Attack Disrupts Adriatic Port Authority, Exposing Critical Infrastructure Vulnerabilities
In a high-profile cyberattack, the Anubis ransomware group targeted the Adriatic Port Authority (Autorità di Sistema Portuale del Mare Adriatico Centrale), which oversees Italy’s Port of Ancona, disrupting maritime logistics and exposing systemic risks in critical transportation infrastructure. The breach, which began in December 2025 and was attributed to the group in January 2026, paralyzed key operations, including cargo tracking, shipping schedules, and customs processing, while exfiltrating sensitive data such as contracts and employee records.
The attackers gained initial access via a spear-phishing email containing a malicious attachment, then moved laterally through the network by exploiting unpatched vulnerabilities and escalating privileges. Once inside, they encrypted thousands of files, crippling the port’s digital systems. The group demanded a $10 million Bitcoin ransom, threatening to leak stolen data if payment wasn’t made within seven days.
The attack had far-reaching operational consequences, forcing vessels to reroute to alternative ports and causing millions in economic losses due to shipment delays. The incident highlighted the growing threat to cyber-physical sectors, where IT breaches can disrupt physical operations without directly targeting operational technology (OT) systems. Researchers noted that the attackers exploited insecure accounts managing Office 365/Azure, demonstrating how vulnerabilities in IT environments can cascade into real-world disruptions.
The Adriatic Port Authority worked with cybersecurity firms and law enforcement to contain the breach, isolating affected systems and restoring data from backups though outdated protocols slowed recovery. While authorities discouraged ransom payments, reports suggested negotiations may have occurred to buy time. The attack underscored the attractiveness of ports as targets, given their digitalization, interconnected logistics platforms, and often weak cybersecurity defenses.
Beyond financial and operational damage, the breach eroded confidence in the port’s resilience, raising concerns about nation-state actors adopting similar tactics in geopolitical conflicts. The incident also reflected broader trends, as ransomware groups increasingly target critical infrastructure, from agriculture (e.g., Australia’s Mackay Sugar) to healthcare (e.g., Novo Nordisk’s clinical trial data theft) and utilities (e.g., Iran-linked Handala’s breach of California Water Service).
The attack serves as a stark example of how aging infrastructure, limited cybersecurity maturity, and IT-OT convergence create high-value opportunities for cybercriminals with experts warning that such threats will intensify through the decade.
California Association of Port Authorities (CAPA) cybersecurity rating report: https://www.rankiteo.com/company/californiaports
Autorità di Sistema Portuale del Mare Adriatico centro settentrionale cybersecurity rating report: https://www.rankiteo.com/company/adspmacs
"id": "CALADS1781691953",
"linkid": "californiaports, adspmacs",
"type": "Ransomware",
"date": "12/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Maritime/Transportation',
'location': 'Italy (Port of Ancona)',
'name': 'Adriatic Port Authority (Autorità di Sistema '
'Portuale del Mare Adriatico Centrale)',
'type': 'Port Authority'}],
'attack_vector': 'Spear-phishing email with malicious attachment',
'data_breach': {'data_encryption': True,
'data_exfiltration': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Contracts', 'Employee records']},
'date_detected': '2025-12-01',
'date_publicly_disclosed': '2026-01-01',
'description': 'In a high-profile cyberattack, the Anubis ransomware group '
'targeted the Adriatic Port Authority (Autorità di Sistema '
'Portuale del Mare Adriatico Centrale), which oversees Italy’s '
'Port of Ancona, disrupting maritime logistics and exposing '
'systemic risks in critical transportation infrastructure. The '
'breach paralyzed key operations, including cargo tracking, '
'shipping schedules, and customs processing, while '
'exfiltrating sensitive data such as contracts and employee '
'records.',
'impact': {'brand_reputation_impact': 'Eroded confidence in the port’s '
'resilience',
'data_compromised': 'Contracts, employee records',
'financial_loss': 'Millions in economic losses',
'operational_impact': 'Vessels rerouted to alternative ports, '
'shipment delays',
'systems_affected': ['Cargo tracking',
'Shipping schedules',
'Customs processing']},
'initial_access_broker': {'entry_point': 'Spear-phishing email'},
'lessons_learned': 'The attack highlighted the growing threat to '
'cyber-physical sectors, where IT breaches can disrupt '
'physical operations. It underscored the attractiveness of '
'ports as targets due to digitalization, interconnected '
'logistics platforms, and often weak cybersecurity '
'defenses. Aging infrastructure, limited cybersecurity '
'maturity, and IT-OT convergence create high-value '
'opportunities for cybercriminals.',
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': ['Insecure accounts managing Office '
'365/Azure',
'Unpatched vulnerabilities',
'Privilege escalation']},
'ransomware': {'data_encryption': True,
'data_exfiltration': True,
'ransom_demanded': '$10 million (Bitcoin)',
'ransomware_strain': 'Anubis'},
'response': {'containment_measures': 'Isolating affected systems',
'law_enforcement_notified': True,
'remediation_measures': 'Restoring data from backups',
'third_party_assistance': 'Cybersecurity firms'},
'threat_actor': 'Anubis ransomware group',
'title': 'Anubis Ransomware Attack Disrupts Adriatic Port Authority, Exposing '
'Critical Infrastructure Vulnerabilities',
'type': 'Ransomware',
'vulnerability_exploited': ['Unpatched vulnerabilities',
'Privilege escalation']}