Virtual Event: CodeSecCon - Learn to Secure Your Software > View Sessions
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Port of Seattle Says 90,000 People Impacted by Ransomware Attack

The Port of Seattle says the personal information of 90,000 individuals was stolen in an August 2024 ransomware attack.

Port of Seattle ransomware

The Port of Seattle is notifying 90,000 individuals that their personal information was compromised in an August 2024 data breach resulting from a ransomware attack.

The incident occurred on August 24 and forced the Port to isolate critical systems, which impacted the Seattle-Tacoma International Airport (SEA Airport), Fishermen’s Terminal, and public marinas it operates.

In mid-September, the Port confirmed that ransomware was used in the attack, blaming the Rhysida group for the intrusion and announcing that it refused to pay a ransom. The threat actor was demanding a $6 million ransom to be paid.

Rhysida added the Port to its Tor-based website a couple of days later, claiming the theft of over 3 TB of data that was offered for auction. The ransomware group has since made some of the data available publicly.

On April 3, the Port revealed that personal information such as names, dates of birth, Social Security numbers, driver’s license numbers, other government ID numbers, and medical information was stolen in the attack.

“The threat actors accessed and downloaded some personal information from Port systems, primarily legacy ones used for employee, contractor, and parking data. The Port holds very little information about airport or maritime passengers, and systems processing payments were not affected,” the Port said.

Advertisement. Scroll to continue reading.

According to the Port, 90,000 individuals were affected, most of which are “current and former Port and other airport employees and contractors. Roughly 71,000 of the impacted people live in Washington state.

The Port is providing the impacted individuals with one year of free credit monitoring and identity theft protection services.

It also underlines that the incident did not affect the proprietary systems of airlines, cruise, and federal partners, and that the attack did not “affect the ability to safely travel to or from Seattle-Tacoma International Airport or safely use the Port’s maritime facilities”.

Related: State Bar of Texas Says Personal Information Stolen in Ransomware Attack

Related: Hunters International Ransomware Gang Rebranding, Shifting Focus

Related: Ransomware Group Takes Credit for National Presto Industries Attack

Related: Russian Espionage Group Using Ransomware in Attacks

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

UltraViolet Cyber has named Andrew Park Chief Information Security Officer.

Glow has appointed Patti Degnan as Chief Information Security Officer.

Daniel Dubowski has been named Senior Vice President and Chief Information Security Officer at Marriott International.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.