Cyber Incident Victim: Corsica Ferries
Date:
Oct 2023
Location:
France
Summary
A cyberattack disrupted Corsica Ferries' online reservation systems, rendering the company's website inaccessible for over a day and displaying maintenance notifications. Customers were temporarily unable to book tickets online, though maritime operations continued unaffected, with passengers able to purchase tickets dockside. Existing reservations remained valid throughout the incident. The company confirmed server interruptions via its website and social media channels, attributing the outage to malicious activity. Service restoration occurred after approximately 30 hours, though technical resolution details and attribution were not publicly disclosed. No broader operational impacts beyond digital booking platforms were reported.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On October 27, 2023, Corsica Ferries experienced a cyber attack that disrupted its online reservation system. The company’s website displayed a maintenance message by midday, preventing customers from making new bookings. Corsica Ferries confirmed via uniform statements on its website, Facebook page, and Twitter account that the interruption resulted from compromised servers. Maritime operations continued unaffected, with passengers able to purchase tickets directly at docks. Existing reservations remained valid, and the company emphasized its teams were working to restore services promptly. The attack caused no reported impact on vessel schedules or physical operations.

The incident persisted for approximately 30 hours, forcing the company to keep its e-commerce platform offline until resolution on Saturday evening. Corsica Ferries did not disclose technical details of the attack, mitigation measures, or threat actor involvement. Authorities collaborated with the company to end the disruption, though the specific methods used to neutralize the attack remained unclear post-resolution. Customer communications focused on service restoration efforts without addressing data compromise or long-term consequences. The company resumed normal online operations following the server recovery but provided no additional public updates regarding forensic findings or attacker attribution.
