Cyber Incident Victim: CMA CGM
Date:
Sep 2020
Location:
China
Summary
CMA CGM suffered a ransomware attack involving the Ragnar Locker variant, prompting hackers to demand contact via live chat and payment for a decryption key, though no specific ransom amount was disclosed. The French container line initially attributed disruptions to an internal IT issue before confirming the cyberattack, which impacted several Chinese offices and led to network shutdowns to contain the malware's spread.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
CMA CGM initially attributed disruptions to its booking system to an internal IT infrastructure issue before confirming on September 28, 2020, that it had suffered a ransomware attack. The attackers deployed Ragnar Locker ransomware and issued a demand instructing the French container shipping company to establish contact via live chat within two days to negotiate payment for a decryption key. No specific ransom amount was disclosed in the initial extortion attempt. The cyberattack impacted multiple CMA CGM office locations in China, disrupting operational systems. Upon detecting the ransomware intrusion, the company implemented emergency network shutdown procedures to isolate infected systems and prevent further propagation of the malware across its global infrastructure.

The containment strategy resulted in deliberate service interruptions as part of incident response measures. While the booking system was confirmed as disabled during the attack, the company did not disclose additional compromised systems or data exfiltration details. CMA CGM's public statements emphasized containment efforts focused on Chinese operations without confirming whether other regional offices experienced secondary infections. No further technical specifics regarding attack vectors, initial access methods, or decryption success rates were released by the carrier. The incident represented a confirmed ransomware event targeting critical shipping infrastructure with operational disruption as the primary immediate consequence.
