CSIDB logo
Incident

Hapag-Lloyd

Incident posture

Attack window
Mar 2022
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-10-21 00:00

Linked entities

Victim
Hapag-Lloyd
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hapag-Lloyd experienced a spear phishing attack involving a fraudulent replica of its website designed to harvest user login credentials. The company's security team identified the fake site, though its creation timeline remained unclear, and advised customers to manually verify URLs, avoid clicking email links, and reset passwords as a precaution. While the incident's potential connection to geopolitical tensions, such as the Russia-Ukraine conflict, was noted as a broader industry concern, no direct link was confirmed. The attack exemplified a trend of low-sophistication methods being used to mask disruptive objectives, with the primary impact being unauthorized data collection targeting user accounts.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On or around March 6, 2022, Hapag-Lloyd identified a spear phishing attack involving a fraudulent replica of its official website designed to harvest user credentials. The attackers uploaded this counterfeit site and directed users to log in through deceptive communications, enabling unauthorized data collection. The company’s security team discovered the fake website on March 6, though the exact creation date remained undetermined. Hapag-Lloyd promptly issued advisories instructing customers to manually enter the company’s official URL instead of clicking email links and to scrutinize email links for authenticity before submitting personal access credentials. Affected users were urged to change their passwords immediately. The attack coincided with broader cybersecurity warnings about threat actors disguising disruptive operations, such as wiper-malware campaigns, as low-sophistication incidents.

The incident occurred amid heightened cyber-risk awareness linked to the Russia-Ukraine conflict, though no direct connection to geopolitical events was confirmed. Hapag-Lloyd had recently suspended services to Russia and closed its Ukrainian offices, operational since mid-2021, as part of industry-wide sanctions compliance. Cybersecurity consultancy CyberCX had previously cautioned organizations about targeted attacks masquerading as rudimentary threats, noting that some campaigns aimed to destroy data rather than extract ransoms. Hapag-Lloyd’s response emphasized procedural safeguards, recommending customers utilize organizational phishing mail analyzers if available and report suspicious emails. The company did not disclose the scale of compromised accounts or specific operational disruptions resulting from the attack. Its communications focused exclusively on credential security and verification protocols to prevent further unauthorized access.

Sources

Sources available to members: 1 source.

CSIDB