CSIDB logo
Incident

Porto de São Francisco do Sul

Incident posture

Attack window
May 2024
Location
Brazil
Status
Historical
CIA posture
Available to members
Updated
2025-12-31 12:16

Linked entities

Victim
Porto de São Francisco do Sul
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Porto de São Francisco do Sul experienced a cyberattack involving server compromise and data encryption, prompting temporary system deactivation to contain the incident. Partial system functionality was restored within a day, enabling full operational resumption while security controls—including automated license plate recognition, biometrics, and CCTV—remained under gradual restoration. The organization continues investigating the scope of compromised data and notified relevant authorities including the Federal Revenue Service, National Waterway Transportation Agency, and data protection regulators.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 6, 2024, the Port of São Francisco do Sul experienced a cyberattack targeting its servers, resulting in the encryption of an unspecified portion of its data. The port's technical team immediately disabled affected systems to contain the attack's propagation, initiating emergency response protocols. By May 7, partial system functionality had been restored through coordinated efforts between the port's internal IT staff and external service providers. This partial recovery enabled the full resumption of port operations within 24 hours of the initial disruption, minimizing operational downtime. The port's official statement confirmed ongoing forensic analysis to determine the full scope of compromised data, though no specific datasets were publicly identified as breached during the incident's initial phase.

Security and access control systems—including automated license plate recognition, biometric authentication, and closed-circuit television monitoring—underwent gradual restoration following core operational recovery. The port formally notified Brazil's Federal Revenue Service (Receita Federal), which authorized operational restart contingent upon enhanced contingency measures. Parallel notifications were submitted to the National Waterway Transportation Agency (Antaq) and the National Data Protection Authority (ANPD) in compliance with regulatory obligations. No operational delays or cargo processing interruptions were reported after systems resumed, though the port emphasized continued evaluation of technical impacts. Restoration priorities focused on maintaining maritime logistics continuity while investigators worked to establish the attack's origin and full technical consequences.

Sources

Sources available to members: 1 source.

CSIDB