A ransomware attack targeting a major port authority on the Adriatic Sea has exposed the severe and converging risks of cyber and physical threats in the maritime sector. The attack, claimed by the Anubis ransomware group, not only crippled port operations and led to a $10 million ransom demand but also resulted in the exfiltration of highly sensitive documents. According to analysis by Resecurity, the stolen data included port safety plans and details of security operations. This type of information is a goldmine for organized crime, potentially enabling smuggling, theft, or even terrorist activities. The incident, which originated from a simple spear-phishing email, demonstrates how a single cyber intrusion can compromise the physical security and integrity of critical national infrastructure.
The attack was initiated on December 11, 2025, and publicly claimed by the Anubis ransomware group in January 2026. Anubis operates a ransomware-as-a-service (RaaS) model and should not be confused with the older Android malware of the same name. The attack had several components:
Resecurity's investigation revealed a classic attack chain that bypassed the need to directly target hardened Operational Technology (OT) systems.
T1566.002 - Spearphishing Link to target staff at the company managing the port. A malicious link in an email likely led to credential harvesting.T1078.004 - Cloud Accounts).T1530 - Data from Cloud Storage Object). They then deployed the ransomware payload across the accessible IT network (T1486 - Data Encrypted for Impact).This 'cloud-first' compromise path highlights a modern attack vector where threat actors can cause massive disruption without ever touching an OT network directly.
The impact of this attack extends far beyond financial loss or operational downtime. The theft of port safety and security plans represents a catastrophic failure of information security with direct physical world consequences. This information is invaluable to:
This incident is a textbook example of how cyberattacks can serve as a precursor or enabler for physical crimes and threats to national security. The $10 million ransom demand is almost secondary to the value of the exfiltrated intelligence.
D3-ITF - Inbound Traffic Filtering).D3-UGLPA - User Geolocation Logon Pattern Analysis).M1017 - User Training).M1032 - Multi-factor Authentication). Regularly audit IAM roles and permissions to enforce the principle of least privilege.M1022 - Restrict File and Directory Permissions). Access should be logged and reviewed regularly.New report confirms Anubis ransomware data leak from Adriatic Port after ransom non-payment, revealing specific port name and new hunting hints.
A new Resecurity report identifies the target as the Italian port of Ancona and confirms the stolen port safety plans were leaked in January 2026 after the $10 million ransom was not paid. This escalation from data theft to public leak significantly increases the national security risk. The report also provides new technical details, including 'Cyber Observables' for hunting, such as monitoring for vssadmin.exe delete shadows and large data egress, and adds network segmentation and immutable backups to mitigation strategies. The attack is now explicitly described as a double-extortion campaign.
The ransomware attack on the Adriatic port authority is initiated.
The Anubis ransomware group publicly claims responsibility for the attack.
Resecurity publishes its analysis of the incident.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.