The supply chain attack on Toyota1 last February 2022 is only one example of how such an attack could be detrimental to an organization. Therefore, a phishing and impersonation campaign2 targeting one of the largest container shipping lines is quite concerning.
To see how widespread the impersonation is, WhoisXML API researchers searched the DNS for digital properties related to Maersk and nine other shipping companies. These are CMA-CGM, COSCO, Hapag-Lloyd, YangMing Marine Transport Corp., Matson, Unifeeder, Wanhai Lines, Ocean Network Express (ONE), and Arkas Container Transport.
Among our key findings are:
- 1,100+ domains and subdomains added since 1 March 2022 containing the names of 10 of the largest shipping companies
- Only two of these properties could be publicly attributed to legitimate shipping companies
- 980+ cybersquatting resources resolved to 1,000+ unique IP addresses
- Dozens of domains hosted suspicious login pages that mimicked legitimate sites
- Some of the properties have been flagged as malicious, most of which are newly registered domains (NRDs)
Download a sample of the threat research materials now or contact us to access the complete set of research materials.
—
- [1] https://circleid.com/posts/20220325-are-cybersquatters-going-after-the-car-manufacturing-sector
- [2] https://www.vadesecure.com/en/blog/phishers-impersonate-maersk-to-exploit-global-supply-chain-chaos