MAT cyber threats
A recent report from the European Union Agency for Cybersecurity (ENISA) highlights that ransomware attacks have become the most prominent cyber threats facing the maritime, aviation, railway and road transport sectors.
ENISS Threat Landscape: Transport Sector, the first analysis conducted by ENISA of the cyber threat landscape of the transport sector in the EU, aims to bring new insights into the reality of the transport sector by mapping and studying cyber incidents from January 2021 to October 2022. It identifies prime threats, actors and trends based on the analysis of cyberattacks targeting aviation, maritime, railway and road transport over a period of almost two years.
During this period, the prime threats identified include: ransomware attacks (38%); data related threats (30%); malware (17%); denial-of-service (DoS); distributed denial-of-service (DDoS) and ransom denial-of-service (RDoS) attacks (16%); phishing / spear phishing (10%); and supply-chain attacks (10%).
During the reporting period, the threat actors with the biggest impact on the sector were state-sponsored actors, cybercriminals and hacktivists. According to ENISA, ransomware attacks became the prominent threat against the sector in 2022. Ransomware has been steadily increasing and the transport sector has been affected similarly to the other sectors.
Key points
- Cybercriminals are responsible for the majority of attacks on the transport sector (54%), and they target all subsectors.
- Threat actors will increasingly conduct ransomware attacks with not only monetary motivations.
- The increased hacktivist activity targeting the transport sector is likely to continue.
- The increasing rate of DDoS attacks targeting the transport sector is likely to continue.
- The main targets of DDoS attacks by hacktivists are European airports, railways and transport authorities.
- During this reporting period, we did not receive reliable information on a cyberattack affecting the safety of transport.
- The majority of attacks on the transport sector target information technology (IT) systems. Operational disruptions can occur as a consequence of these attacks, but the operational technology (OT) systems are rarely being targeted.
- Ransomware groups will likely target and disrupt OT operations in the foreseeable future.
Aviation
According to the report, the aviation sector is facing multiple threats, with data-related threats being the most prominent, coupled by ransomware and malware. Customer data of airlines and proprietary information of original equipment manufacturers (OEM) are the prime targeted assets of the sector. In 2022, there has been a rise in the number of ransomware attacks affecting airports. Fraudulent websites impersonating airlines have become a significant threat in 2022.
Maritime
The maritime sector experiences ransomware, malware, and phishing attacks targeted towards port authorities, port operators, and manufacturers. State-sponsored attackers often carry out politically motivated attacks leading to operational disruptions at ports and vessels.
Railway
The railway sector also experiences ransomware and data-related threats primarily targeting IT systems like passenger services, ticketing systems, and mobile applications, causing service disruptions. Hacktivist groups have been conducting DDoS attacks against railway companies with an increasing rate, primarily due to Russia’s invasion of Ukraine.
Road transport
The road transport sector faces predominantly ransomware attacks, followed by data-related threats and malware. Automotive industry, especially OEM and tier-X suppliers, has been targeted by ransomware leading to production disruptions. Data-related threats primarily target IT systems to acquire customer and employee data as well as proprietary information.
There is a limited number of cyber incidents that cannot be placed in one specific sub-sector. These include general campaigns targeting the whole transportation sector in particular countries. These campaigns are often attributed to hacktivists and state-sponsored actors and are linked to geopolitical tensions.
The report also highlights issues with the reporting of cyber incidents and the fact that we still have limited knowledge and information regarding such incidents. The analysis in this report indicates that publicly disclosed incidents are just the tip of the iceberg.
ENISA executive director Juhan Lepassaar comments: “Transport is a key sector of our economy that we depend on in both our personal and professional lives. Understanding the distribution of cyber threats, motivations, trends and patterns as well as their potential impact, is crucial if we want to improve the cybersecurity of the critical infrastructures involved.”
Data
In a section that will be warmly welcomed by underwriters, the report also makes a plea for better data: “The lack of reliable data from targeted organisations makes it very hard to fully understand the problem or even know how many cyberattacks on the transport sector actually occur. Even using the data from the web pages of threat actors (an undeniably unreliable source), it is very hard to keep track of the actual number of attacks.”
“The most important information that is missing is the technical explanation as to how the attackers obtained access to the targets. This is usually private data that describes the security posture of the target, so it is never shared with the public. As a consequence, our learning as a community of the problems to be solved remains fragmented and isolated.”
According to the report, the aviation sector is facing multiple threats, with data-related threats being the most prominent, coupled by ransomware and malware. Customer data of airlines and proprietary information of original equipment manufacturers (OEM) are the prime targeted assets of the sector.








https://ccfe.ukaea.uk