DP World Australia disconnects its network after a cyber incident
DP World Australia disconnects its network after a cyber incident. The disruption ran from 2023-11-10 (10 November 2023) to 2023-11-13 (13 November 2023), 4 days, affecting Melbourne, Sydney (AU), Brisbane, Fremantle. Melbourne averaged 2.0 calls per day during the event window against an expected 2.8 (-0.8). Sydney (AU) averaged 0.0 calls per day during the event window against an expected 0.0 (0.0). Brisbane averaged 2.8 calls per day during the event window against an expected 2.4 (+0.4). Fremantle averaged 1.5 calls per day during the event window against an expected 1.0 (+0.5).
Key facts
- Started
- 2023-11-10 (10 November 2023)
- Ended
- 2023-11-13 (13 November 2023)
- Status
- ended
- Type
- Cyber incident
- Severity
- 2 Moderate
- Scope
- regional
- Chokepoints
- None
- Ports
- Melbourne, Sydney (AU), Brisbane, Fremantle
- Lanes
- None
- Countries
- Australia
- Confidence
- high: The detection date, the disconnection, the resumption on 2023-11-13 and the backlog figure come from DP World Australia's own statement, with consistent reporting by ABC News and CNN.
- First reported
- 2023-11-12 (12 November 2023)
- Severity basis: Terminal closure over 72 hours; landside operations at the DP World terminals in four ports stopped from 2023-11-10 to 2023-11-13.
What happened
On 2023-11-10 (10 November 2023) DP World Australia detected unauthorised access to its Australian corporate network and disconnected that network from the internet, which stopped landside operations at its container terminals in Melbourne, Sydney, Brisbane and Fremantle. The operator handles about 40 percent of Australian container freight, and the National Cyber Security Coordinator said the interruption would affect the movement of goods into and out of the country for a number of days. Operations restarted on 2023-11-13 (13 November 2023), and the company said the resumption did not mean the incident had concluded. DP World Australia reported on 2023-11-28 that it had cleared a backlog of 30,137 containers by 2023-11-20, that no ransomware was found, and that a small amount of data had been taken.
Measured effect
Container ship port calls, Melbourne
- Baseline (expected)
- 2.8 calls per day
- Observed
- 2.0 calls per day
- Change
- -0.8 (percent omitted, baseline too small)
- Standardised score
- -0.4
- Event window
- 2023-11-10 to 2023-11-13 (4 days)
- Baseline window
- 2023-09-08 to 2023-11-02 (56 valid days)
- Method
- wfm-effect-1.0
- Computed
- 2026-09-19 (19 September 2026), data revision 1:930fa3b896de
Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.
This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.
Container ship port calls, Sydney (AU)
- Baseline (expected)
- 0.0 calls per day
- Observed
- 0.0 calls per day
- Change
- 0.0 (percent omitted, baseline too small)
- Standardised score
- 0.0
- Event window
- 2023-11-10 to 2023-11-13 (4 days)
- Baseline window
- 2023-09-08 to 2023-11-02 (56 valid days)
- Method
- wfm-effect-1.0
- Computed
- 2026-09-19 (19 September 2026), data revision 1:c90e9eae2818
Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.
This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.
Container ship port calls, Brisbane
- Baseline (expected)
- 2.4 calls per day
- Observed
- 2.8 calls per day
- Change
- +0.4 (percent omitted, baseline too small)
- Standardised score
- +0.2
- Event window
- 2023-11-10 to 2023-11-13 (4 days)
- Baseline window
- 2023-09-08 to 2023-11-02 (56 valid days)
- Method
- wfm-effect-1.0
- Computed
- 2026-09-19 (19 September 2026), data revision 1:4a06c2f3731e
Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.
This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.
Container ship port calls, Fremantle
- Baseline (expected)
- 1.0 calls per day
- Observed
- 1.5 calls per day
- Change
- +0.5 (percent omitted, baseline too small)
- Standardised score
- +0.5
- Event window
- 2023-11-10 to 2023-11-13 (4 days)
- Baseline window
- 2023-09-08 to 2023-11-02 (56 valid days)
- Method
- wfm-effect-1.0
- Computed
- 2026-09-19 (19 September 2026), data revision 1:d835aac37d0d
Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.
This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.
Timeline
- DP World Australia detects unauthorised access to its Australian corporate network and disconnects the network from the internet, stopping landside operations at its four container terminals. [s1] [s2]
- The National Cyber Security Coordinator describes the incident as nationally significant and says the interruption is likely to last days rather than weeks. The Australian Federal Police opens an investigation. [s2]
- Operations restart at 09:00 local time at the Melbourne, Sydney, Brisbane and Fremantle terminals after overnight testing of key systems, with about 30,000 containers waiting at the four sites. [s1] [s3] [s4]
- DP World Australia reports that the container backlog was cleared by 2023-11-20, that no ransomware was found or deployed, and that some employee data was taken. [s1]
Cause
DP World Australia said it detected unauthorised access to its Australian corporate network and disconnected the network to contain it. No party has been publicly identified as responsible, and the Australian Federal Police opened an investigation. Attributed by: Australian Federal Police. [s1] [s2]
The cause is under investigation.
Resolution
Corrections
No corrections to this record as of 2026-09-16 (16 September 2026).
Sources
- [s1] DP World, Media Statement: Update on Cybersecurity Incident, published 2023-11-28 (28 November 2023), accessed 2026-09-15. Archived copy. (official)
- [s2] ABC News, Government doesn't know details behind cyber hack that shut down port operator DP World, published 2023-11-12 (12 November 2023), accessed 2026-09-15. Archived copy. (press)
- [s3] ABC News, Freight giant DP World recovers from cyber attack, but warns investigation and remediation is 'ongoing', published 2023-11-13 (13 November 2023), accessed 2026-09-15. Archived copy. (press)
- [s4] CNN, DP World cyberattack: Australian ports restart some operations, published 2023-11-13 (13 November 2023), accessed 2026-09-15. Archived copy. (press)