In May 2004, the UK Maritime Coastguard Agency (MCA) fell victim to the Sasser Worm, a malware attack orchestrated by German hacker Sven Jaschan. The worm exploited a critical vulnerability in Windows operating systems, spreading rapidly across unpatched machines. The attack severely disrupted the MCA’s operations, crippling its IT infrastructure. All coastguard stations except Milford Haven lost access to essential digital services, including email communications, computer-generated nautical charts, and a key weather information system. The outage impaired the agency’s ability to log maritime incidents, coordinate search-and-rescue operations, and provide real-time navigational safety updates to vessels. While no direct loss of life was reported, the disruption posed significant risks to maritime safety, as coastguard teams had to rely on manual, less efficient methods for tracking and responding to emergencies. The incident highlighted vulnerabilities in critical national infrastructure and the potential for cyberattacks to disrupt public safety services. The MCA had to implement emergency protocols and accelerate system patches to restore functionality, but the attack exposed gaps in cybersecurity preparedness for government-operated emergency response systems.
Source: http://news.bbc.co.uk/2/hi/technology/4649361.stm
TPRM report: https://www.rankiteo.com/company/maritime-and-coastguard-agency
"id": "mar302092125",
"linkid": "maritime-and-coastguard-agency",
"type": "Cyber Attack",
"date": "5/2004",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization’s existence"
{'affected_entities': [{'industry': 'maritime safety and search & rescue',
'location': 'United Kingdom',
'name': 'UK Maritime Coastguard Agency',
'type': 'government agency'}],
'attack_vector': 'exploitation of Windows OS vulnerability (programming bug)',
'date_detected': '2004-05',
'description': 'In May 2004, the UK Maritime Coastguard Agency was hit by a '
'malware attack. Sven Jaschan (Germany) damaged the systems '
'through the Sasser Worm Virus. It exploited a programming bug '
'in Windows operating systems, disrupting coastguard logging '
'operations. All coastguard stations except Milford Haven were '
'unable to access e-mails, computer-generated charts, and one '
'source of weather information.',
'impact': {'operational_impact': 'disruption of coastguard logging '
'operations; most stations (except Milford '
'Haven) lost access to critical systems',
'systems_affected': ['e-mail systems',
'computer-generated charts',
'weather information systems']},
'initial_access_broker': {'entry_point': 'Windows OS vulnerability (Sasser '
'Worm)'},
'post_incident_analysis': {'root_causes': 'exploitation of unpatched Windows '
'OS vulnerability by Sasser Worm'},
'threat_actor': 'Sven Jaschan',
'title': 'UK Maritime Coastguard Agency Malware Attack (Sasser Worm)',
'type': 'malware',
'vulnerability_exploited': 'Windows OS vulnerability (unspecified programming '
'bug)'}