CSIDB logo
Incident

Port of Ostend

Incident posture

Attack window
Feb 2025
Location
Belgium
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 15:55

Linked entities

Victim
Port of Ostend
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Undetermined
Disclosed
Feb 2025
Resolved
Pending

Summary

A cyberattack was launched against the Port of Ostend on a Monday night, targeting its community system known as Ensor. This system contained data related to ship arrivals and departures, including crew lists, but no critical data was held within it. Other systems remained unaffected, and port operations continued without disruption. A response team from the port, supported by external experts, worked to restore the affected system and resolve the issue.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Port of Ostend was targeted by a cyberattack on the night of Monday, February 10, 2025, with the incident first being reported publicly by the Port the following day, Tuesday, February 11, 2025. The attack specifically targeted the Port community system known as "Ensor." This system is a centralized platform used within the Port community and contains operational data related to the maritime activities at the facility, including information concerning the arrival and departure of ships, as well as crew lists associated with those vessels. The Port of Ostend, upon confirming the incident, moved quickly to communicate that no critical data is found within the Ensor system, suggesting that while the platform holds routine operational and personnel data, it does not contain information classified as critical or highly sensitive to broader security or port continuity.

Despite the cyberattack on the Ensor system, the Port of Ostend reported that other systems within its infrastructure remained unaffected by the incident, and the overall operations of the port were not disrupted. This indicates that the attack was contained to the specific Ensor platform without spreading laterally to other operational, administrative, or logistical systems that are essential to the day-to-day functioning of the port. The fact that ship arrivals, departures, and cargo handling continued without interruption suggests that these functions either rely on separate, unaffected systems or fall outside the scope of the Ensor platform's role within the port's broader operational ecosystem. As a result, there were no immediate reports of shipping delays, logistical backlogs, or operational downtime stemming from the cyberattack.

In response to the incident, a response team from the Port of Ostend was mobilized, supported by external cybersecurity experts, to address the breach and initiate recovery efforts. These combined internal and external resources are working to take the necessary measures to restore the Ensor system to normal operation as quickly as possible. While the specific nature of the technical measures being implemented, the identity of the external experts involved, and the timeline for full restoration have not been publicly disclosed, the Port's immediate focus appears to be on system recovery and ensuring that the Ensor platform can be brought back online securely. The collaborative response between the Port's own personnel and outside specialists reflects a standard approach to incident handling, drawing on additional expertise to manage both the immediate containment and the longer-term remediation of the affected system.

Sources

Sources available to members: 1 source.

CSIDB