Menu
Browse

Cyber Incident Victim: Corsica Ferries

Date:

Oct 2023

Location:

France

Summary

A cyberattack disrupted Corsica Ferries' online reservation systems, rendering the company's website inaccessible for over a day and displaying maintenance notifications. Customers were temporarily unable to book tickets online, though maritime operations continued unaffected, with passengers able to purchase tickets dockside. Existing reservations remained valid throughout the incident. The company confirmed server interruptions via its website and social media channels, attributing the outage to malicious activity. Service restoration occurred after approximately 30 hours, though technical resolution details and attribution were not publicly disclosed. No broader operational impacts beyond digital booking platforms were reported.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On October 27, 2023, Corsica Ferries experienced a cyber attack that disrupted its online reservation system. The company’s website displayed a maintenance message by midday, preventing customers from making new bookings. Corsica Ferries confirmed via uniform statements on its website, Facebook page, and Twitter account that the interruption resulted from compromised servers. Maritime operations continued unaffected, with passengers able to purchase tickets directly at docks. Existing reservations remained valid, and the company emphasized its teams were working to restore services promptly. The attack caused no reported impact on vessel schedules or physical operations.

Cyber Incident Image

The incident persisted for approximately 30 hours, forcing the company to keep its e-commerce platform offline until resolution on Saturday evening. Corsica Ferries did not disclose technical details of the attack, mitigation measures, or threat actor involvement. Authorities collaborated with the company to end the disruption, though the specific methods used to neutralize the attack remained unclear post-resolution. Customer communications focused on service restoration efforts without addressing data compromise or long-term consequences. The company resumed normal online operations following the server recovery but provided no additional public updates regarding forensic findings or attacker attribution.

Sources
Sources available to members
1 source