Port of Seattle Confirms Rhysida Ransomware Behind Late August Cyberattack
The Port of Seattle confirms that the Rhysida ransomware group is responsible for the late August cyberattack that disrupted operations at Seattle-Tacoma International Airport. The Port refuses to pay the ransom and warns that the hackers may leak stolen data on the dark web.
The Port of Seattle officially confirms that a late August cyberattack targeting its systems is a ransomware incident orchestrated by the criminal group known as Rhysida. The attack, which occurs on August 24, causes significant system outages across the Port's network, including operations at the Seattle-Tacoma International Airport. This is the same hacking group that conducts the high-profile cyberattack on the British Library last year.
Officials state that the Port refuses to pay the demanded ransom to the hackers. As a result, Rhysida threatens to publish the stolen information on its dark web site. The Port's investigation reveals that the attackers successfully obtain some Port data during the mid-to-late August timeframe, though the exact scope of the compromised files remains under active review.
The cyberattack causes noticeable disruptions for travelers, with many airport systems remaining offline days after the initial intrusion. The Port promises to directly notify any employees or passengers if investigators discover that their personal information is included in the stolen data. Meanwhile, cybersecurity teams continue working to secure the network and restore all affected services to full functionality.