Cyber Incident Victim: Port of Longview
Date:
Feb 2018
Location:
United States of America
Summary
The Port of Longview experienced a significant cyberattack potentially compromising data belonging to hundreds of current and former employees as well as dozens of vendors. The FBI notified the organization of the breach, though classified details limited public disclosure of the investigation's specifics. Forensic analysis traced the attack's origins to internet service provider addresses linked to Russia, Liberia, and Kazakhstan. The incident prompted engagement with legal counsel, though this approach drew criticism regarding transparency given the attack's foreign attribution and potential implications for critical infrastructure security.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The Port of Longview in Washington State experienced a significant cyberattack discovered on February 1, 2018, when the FBI notified port officials of the breach. According to an internal memo obtained by The Daily News, the attack potentially compromised the personal information of hundreds of current and former employees along with data from dozens of vendors connected to the port. The FBI declined to share specific details about the intrusion with port leadership, citing classified information related to the investigation. While the exact method of initial compromise remains undisclosed, investigators identified internet service provider addresses linked to Russia, Liberia, and Kazakhstan as the source locations for the malicious activity. Port authorities engaged a law firm to manage the legal aspects of the incident, a decision that limited public disclosure of technical details under attorney-client privilege protections.

The cyberattack disrupted normal port operations, though the specific duration and severity of operational impacts were not quantified in available records. No explicit confirmation exists regarding whether ransomware deployment, data exfiltration, or system destruction occurred during the incident. The port's response focused on coordinating with federal investigators while maintaining confidentiality around forensic findings. Public concern arose regarding the lack of transparency, particularly given the port's critical infrastructure role and the foreign-linked nature of the attack. The incident highlighted tensions between organizational privacy during investigations and public interest in understanding threats to vital transportation assets. No subsequent disclosures clarified whether employee or vendor data was definitively accessed or misused as a result of the breach.
