Dear Valued Customers,
We hope this message finds you well.
Recently, there has been an increase in phishing emails (HTML emails) targeting ships by exploiting browser vulnerabilities. We urge all personnel to remain vigilant.
Email Content
The sender’s address is spoofed, often pretending to be “Email System Administrator” or “Accounting Manager.” The purpose of these emails is to trick recipients into clicking links under the pretext of “account suspension” or “payment issues.” These emails are in HTML format rather than plain text. Clicking the link redirects to a dummy server prepared by the sender, where browser vulnerabilities are exploited to steal information from the PC (IDs, passwords, and other data). Simply clicking the link is extremely dangerous.
At-Risk Ships
The risk varies depending on the ship’s communication setup, so please review the following carefully.
1.Ships that Prohibit HTML Emails in Mail Communication
These ships are not at risk. The problematic content is in the HTML part of the email, which is removed if the settings are configured to strip HTML content.
2.Ships that Allow HTML Emails in Mail Communication
These ships are further categorized into the following conditions:
a. Ships with Email Only, No Web Browsing Capability
There is minimal risk, but the harmful code is still present in the email. If such an email is received, delete it immediately.
b. Ships with Web Browsing Capability via FX, VSAT, 4G, etc.
Receiving these emails and clicking the link poses a risk of information theft. Be cautious of suspicious emails, and do not click on URLs in the email body without thorough verification.
Moreover, ships with web browsing capabilities are constantly at risk of encountering web pages exploiting browser vulnerabilities. Carrier-based harmful site blocks alone may not suffice. Accessing these pages with unpatched OS or outdated browsers can compromise PC information.
To prevent this, it is crucial to keep browsers and OS updated. Ships unable to secure sufficient update bandwidth via satellite should ensure 4G connectivity when docked to update OS and software.
The spread of FX and VSAT has improved ships’ internet connectivity, introducing new risks. IT risk management that adapts to these changes is essential.
If you have any concerns, please do not hesitate to contact us.
Thank you for your attention and cooperation.