Extortion crews turn on ports and fuel terminals

Published

Over the past month, four separate extortion crews have posted claims against port and maritime companies. Among the organizations named are a Philippine government agency, a container port in Malaysia, and a fuel storage terminal described on its listing as the largest independent facility of its kind in the Mediterranean.

None of them has publicly confirmed a breach. IntelFusions has recorded no corroborating disclosure from any of the organizations named, and every one of these entries rests on a single source: the gang's own leak site.

Two Philippine port operators, nine days apart

The clearest cluster is in the Philippines. On 27 August the Qilin ransomware operation listed Globalport Terminals, a private terminal operator. Nine days later, on 5 September, the same crew listed the Philippine Ports Authority, the state agency that oversees public ports across the country. Two port entities in one country, from one crew, inside a fortnight.

The rest of the listings come from different groups. Dire Wolf posted the Port of Tanjung Pelepas, a container port in Malaysia's Johor state, on 11 September. Deadlock posted Global Terminal Services on 19 August. Krybit posted the Arab Maritime Petroleum Transport Company, a shipping line its listing dates to 1972, on 1 September.

The suppliers are on the list too

The pattern does not stop at the terminals. Eclipse listed Moscord, a procurement marketplace serving maritime and oil and gas buyers, on 16 August. Akira listed Kyodo USA, a distributor of marine engine spares and ship operation equipment, on 9 September. Qilin also listed WIS Logistics, recorded as a Singapore operation, and the Taichung branch of Panda Logistics, both in August.

Read together, the victim list looks less like ports than like the paperwork layer around them: the agencies, brokers, marketplaces and parts suppliers that move documentation rather than containers.

Nobody is claiming the cranes stopped

This is worth saying plainly, because port incidents invite assumptions. Not one of these listings asserts that terminal operations were disrupted. They are data theft and extortion claims of the ordinary kind: the crew says it holds files and threatens to publish them. Whether that data exists, and what is in it, is unverified in every case.

That shapes how the claims should be read. A leak-site entry is an allegation made by a criminal group with an incentive to exaggerate. Our own ingestion pipeline carries filters for fake, duplicated and placeholder listings for exactly that reason, and we covered a related run of Southeast Asian listed companies earlier this month.

Check your freight partners before your firewall

For organizations in this supply chain, the practical reading follows the victim list rather than any single intrusion. Most of the entities being named are intermediaries, which puts the exposure with a third party rather than with a port operator directly. Ask which brokers, marketplaces and parts suppliers hold your shipping documentation, what they keep, and for how long.

If your organization turns up on one of these sites, treat the entry as a lead and not a verdict. Confirm independently before saying anything publicly, and preserve logs covering the period the crew claims. IntelFusions tracks these listings continuously, including the Qilin operation and activity affecting the Philippines.

What makes this month's set worth flagging is not the volume, which is small. It is that a national ports authority and a regional fuel terminal sat on leak sites for weeks with nobody involved saying a word.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions