In 2017, Maersk was infected by the NotPetya malware that brought down the vast majority of Maersk’s critical network and took hostage of most end-user clients and applications rendering them useless. Moreover, the malware damaged the fixed-line phones and wiped out Outlook contacts which disrupted the entire corporate communication and put the global operation to a halt. In fact, almost the entire Maersk fleet was out of operation for about two weeks.
Being faced with a malicious cyberattack, Maersk learned the hard way that their backup plan did not include images of their network setup. Fortunately, the company was able to retrieve an uninfected copy of its Active Directory from a Maersk office in Nigeria. The copy had been secure thanks to a power outage in the local area that had taken the server offline while the malware was spreading.
By gaining access to that copy and through a huge effort from the Maersk task team, they were able to successfully restore the core access to the essential data. The Maersk team even established contact with the NotPetya creator and gained valuable insight into this dangerous malware. Maersk became the first corporate in the world to reverse engineer the malware.
An interesting opinion of the leader of Maersk’s IT team who won over the cyberattack: “Automated detection and response are key. Automated protection is worth its weight in gold. And Privileged Access Management (PAM) takes on increasing importance. With a more limited number of privileged accounts, it is reasonable to assume that a much lower number of machines would have been infected, something like 5,000 rather than the 55,000 seen at Maersk," Adam Banks – Chief Technology and Information Officer of Maersk.
Norsk Hydro CaseIn 2019, Norsk Hydro experienced a disruptive attack known as LockerGoga, which brought the giant Norwegian aluminum business down to its knees. LockerGoga is ransomware more sophisticated than NotPetya. Basically, LockerGoga can log existing users off, change their passwords, encrypt the files on servers in the network, and also post ransom messages on the screens of infected computers demanding the company to pay a ransom in bitcoins to gain back the control.
From the investigation review, it turned out that the LockerGoga ransomware was able to enter the Norsk Hydro system when an employee opened an infected email sent by a trusted customer. This attack forced Norsk Hydro to switch to manual operations with pen and paper and the company suffered losses of tens of millions of dollars in damage. Even so, Norsk Hydro refused to pay the ransom and chose to be transparent about the cyberattack while actively seeking help from internal and external sources.
The attack is currently attributed to criminal hackers, but it remains under investigation. Norsk Hydro has recovered by gradually rebuilding its systems, improving its disaster recovery backup plans, and putting more focus on cybersecurity threat mitigation.
Tower Semiconductor LTD. (TSEM) CaseIn 2020, TESM was targeted with a ransomware cyberattack which forced the corporate to halt its operations in certain manufacturing facilities as a preventive strategy. TSEM reported having paid the ransom (approximately $250,000 in Bitcoin) in an attempt to resume normal operations. Tower semiconductor also was implementing measures to prevent the attack from expanding wider. After paying the ransom, TSEM expects to return to normal operation almost immediately.
Florida Water Treatment Plant CaseIn early 2021, a hacker was able to access a Florida water treatment plant monitor software that can adjust the level of sodium hydroxide (lye) in water via remote access.
The attacker attempted to adjust the lye level up to 11,100 ppm which potentially could have severely impacted the health of 15,000 citizens living in the area. Luckily, an employee noticed the suspicious remote access when the bad actor was operating the mouse on the screen to adjust the lye setting. He quickly changed the systems back to the normal settings and informed the management about disabling all remote access.
This attack is particularly serious since it could have potentially caused physical harm or even casualties, had it not been stopped. There are two key elements in this case: the water treatment plant used an outdated operating system (Windows 7) which is no longer supported by Microsoft. This opened backdoors to the attacker.
Another reason was the use of ungoverned shared accounts among the staff for remote access via the TeamViewer application.
Colonial Pipeline CaseColonial Pipeline is responsible for gasoline supply in the East Coast, USA; also known as the largest petroleum pipeline in the US. In 2021, the system of Colonial Pipeline went down for several days due to the cyberattack from a group of criminal hackers based in Eastern Europe called DarkSide.
When the attack happened, it caused chaos in the gasoline supply chain on the East Coast, causing consumers to hoard gas and creating spikes in gas prices. This is considered the largest cyberattack in the energy industry in the United States. As a result of the ransomware attack, the company ended up paying at least 4,4 million USD in bitcoin to restore operations.
Under investigation, they found out that the breach may originate from a leaked password to an old account that had access to the virtual private network (VPN), which is used to make the remote access the corporate’s servers.
The account didn’t have multifactor authentication, so the username and password were the only two things the hacker needed to gain the access to the largest petroleum supplier in the USA. Intriguingly, Colonial Pipeline was able to recover part of its bitcoin deposit by following the trail from the hacker’s wallet. The Colonial Pipeline was able to resume normal operations without a prolonged disruption to its fuel supply.
SSH's solutions for OT PrivX OT Editioncan provide secure access Management for Critical Operational Technology (OT)Just-in-Time (JIT) and Zero Trust access for on and off-site operators and maintenance engineers with PrivX OT Edition. References
https://www.cyberscoop.com/norsk-hydro-lockergoga-ransomware/
https://www.i-cio.com/management/insight/item/maersk-springing-back-from-a-catastrophic-cyber-attack
https://www.calcalistech.com/ctech/articles/0,7340,L-3848490,00.html
https://www.vox.com/recode/22428774/ransomeware-pipeline-colonial-darkside-gas-prices
SSH is a leading defensive cybersecurity company that secures communications between humans, systems, and networks. We specialize in Zero Trust Privileged Access Controls and Quantum Safe Network Security. Our customers include a diverse range of enterprises, from multiple Fortune 500 companies to SMBs across various sectors such as Finance, Retail, Technology, Industrial, Healthcare, and Government. 25% of Fortune 100 companies rely on SSH’s solutions. Recent strategic focus has expanded SSH business to Defence, Critical Infrastructure Operators, Manufacturing OT Security and Public Safety. Leonardo S.p.A invests 20.0 million EUR in SSH, becoming the largest shareholder of the company. SSH solutions form a Center of Excellence for Zero Trust privileged access management and quantum-safe network encryption in Leonardo - a global industrial group that creates multi-domain technological capabilities in the Aerospace, Defence and Security sector with 17.8 billion EUR revenue in 2024. SSH company’s shares (SSH1V) are listed on Nasdaq Helsinki. Solutions Zero Trust Suite Zero Trust Suite & Entra ID Integration Quantum-Safe Cryptography (QSC) SalaX Secure Collaboration Security Risk Mitigation OT security MSP Security Device Trust Monitoring & Threat Intelligence Credentials & Secrets Management IT Audits & Compliance Products PrivX™ Hybrid PAM PrivX Key Manager Tectia SSH Client/Server™ Tectia™ z/OS Secure Messaging Secure Mail Secure Sign NQX™ Quantum-Safe Services SSH Risk Assessment™ Professional Services Support Resources Careers References Downloads Manuals Events & Webinars Blog Company About us Contact Investors Partners Press Stay on top of the latest in cybersecurity Be the first to know about SSH’s new solutions, product updates, new features, and other SSH news! Thanks for submitting the form. © Copyright SSH • 2025 • Legal智能索引记录
-
2026-02-27 00:50:12
综合
成功
标题:LoveEvent 27.11.03 - Poppen bis der ... [Archiv] - BW7 Forum
简介:... Arzt kommt? Warum nicht? Hi liebe BW7ler, dem ein od
-
2026-02-27 06:33:33
综合
成功
标题:roaming文件夹可以删除吗 c盘roaming文件清理方法-驱动人生
简介:Roaming文件夹是Windows系统中用于存储用户配置文件的一部分,其中包含了应用程序的设置、偏好以及其他个性化数据
-
2026-02-27 00:47:51
综合
成功
标题:Das Sexforum und Erotikforum für Baden-Württemberg
简介:Das große Pay6, Huren und Rotlicht Rating Forum für Baden Wü
-
2026-02-26 23:52:04
综合
成功
标题:NVE Corp - Sensor Boards and Eval Kits
简介:This is Sensor Boards and Eval Kits.
-
2026-02-27 02:15:30
综合
成功
标题:SSH Blog Defensive Cybersecurity compliance
简介:compliance Read about secure communications between people
-
2026-02-27 04:24:35
综合
成功
标题:Request a Quote or Sample Products PCA Electronics
简介:Get a quote or request a sample custom magenetics products a
-
2026-02-27 09:16:35
综合
成功
标题:Frage: Hobby-Hure und Briefkasten-Werbung??
简介:Hallo! Wir wohnen in einem Hochhaus (ca. 60 Wohnungen) un
-
2026-02-27 09:29:13
综合
成功
标题:Listening for Important Details: Definition, Significance, Comparisons, Rules and Examples EDU.COM
简介:Listening for Important Details: The skill of recognizing an
-
2026-02-27 04:42:25
综合
成功
标题:性格轮廓分析模板-果果圈模板
简介:性格轮廓分析模板,为你的Office加点料!
-
2026-02-27 06:47:10
综合
成功
标题:阿富汗首都喀布尔传出爆炸巨响-新华网
简介:阿富汗首都喀布尔传出爆炸巨响-
-
2026-02-27 08:57:30
综合
成功
标题:Blog PIP - PIP Anchorage, AK
简介:Track our weekly updates in interesting information with PIP
-
2026-02-26 23:51:55
综合
成功
标题:《星刃》PS5容量30.4GB 预载19日开启_3DM单机
简介:推主PlayStation Game Size曝光了《星刃》PS5版容量:30.448GB,版本号1.001.000。《
-
2026-02-27 06:23:59
综合
成功
标题:JSCL Pakistan Financial ServicesJSCL Pakistan Financial Services
简介:Pakistan Financial Services
-
2026-02-27 08:23:05
综合
成功
标题:洪鑫凯仁供应链招聘-泉州洪鑫凯仁供应链管理有限责任公司招聘-597直聘
简介:597直聘为您提供洪鑫凯仁供应链招聘信息、公司简介、公司地址、公司福利等详细信息,让您在选择洪鑫凯仁供应链前有一个全面的
-
2026-02-27 01:58:50
综合
成功
标题:2010福建福克斯10大富豪榜 - 豆丁网
简介:福克斯评出2010福建10大富豪,看看他们都是谁:陈发树、丁世忠家族、曹德旺夫妇等!
-
2026-02-27 00:15:37
综合
成功
标题:495015267-1150 Heater Jacket
简介:The 495015267-1150 Polyimide Heater Jacket is designed for u
-
2026-02-27 09:36:41
综合
成功
标题:† Worral. World English Historical Dictionary
简介:† Worral. World English Historical Dictionary
-
2026-02-27 09:34:57
综合
成功
标题:Products - HTS Commercial & Industrial HVAC Systems, Parts, & Services Company
简介:We are a solution-based company, providing mechanical equipm
-
2026-02-27 07:43:10
游戏
成功
标题:三人跳绳,三人跳绳小游戏,4399小游戏 www.4399.com
简介:三人跳绳在线玩,三人跳绳下载, 三人跳绳攻略秘籍.更多三人跳绳游戏尽在4399小游戏,好玩记得告诉你的朋友哦!
-
2026-02-27 05:19:17
综合
成功
标题:人妻女医 性奴隷の悦び
简介:人妻女医 性奴隷の悦び
-
2026-02-27 00:51:47
综合
成功
标题:Schaeffler Germany
简介:Schaeffler has been driving forward groundbreaking invention
-
2026-02-27 03:13:50
游戏
成功
标题:《星刃》开发商Shift Up将继续开发单人游戏_3DM单机
简介:《星刃》背后的开发商Shift Up成功吸引了所有玩家的注意,不管是女主Eve的性感设计还是游戏强势的预购表现,《星刃》
-
2026-02-27 09:48:32
综合
成功
标题:Startseite - VTE-FILTER GmbH
简介:VTE ist einer der weltweit führenden Experten für Ersatzteil
-
2026-02-27 09:14:35
综合
成功
标题:Direct Speech: Definition, Significance, Rules, Common Mistakes and Examples EDU.COM
简介:Direct Speech: The exact words spoken by someone, enclosed i
-
2026-02-27 02:36:35
综合
成功
标题:Come Ridurre la Non Conformità
简介:Molti programmi di compliance tradizionali si basano su perc
-
2026-02-27 06:02:35
综合
成功
标题:ILSC Language Schools Programs Family Camp Summer Vancouver
简介:ILSC Language Schools
-
2026-02-27 06:50:06
综合
成功
标题:Diving in a sublime small world ...
简介:1x.com is the world
-
2026-02-27 08:42:48
综合
成功
标题:継続は力なり!作曲レッスン - 森音楽教室
简介:「作曲は才能ではなく、継続という習慣でできていく。」作曲レッスンは“継続”が上達のカギ作曲は、ひらめきだけで完成するもの
-
2026-02-27 08:27:06
综合
成功
标题:一年就看这一盒!-阵容最强的超级大礼包完全解析!!.
简介:一年就看这一盒!-阵容最强的超级大礼包完全解析!!.
-
2026-02-27 05:15:03
综合
成功
标题:「みんなの楽譜屋さん」の紹介-子供の作曲 - 森音楽教室
简介:「子供の作曲」のテキストの紹介ページを作りました。https://www.on105.com/index.php/ont