Ransomware stops container handling at the Port of Nagoya
Ransomware stops container handling at the Port of Nagoya. The disruption ran from 2023-07-04 (4 July 2023) to 2023-07-06 (6 July 2023), 3 days, affecting Nagoya. Nagoya averaged 7.7 calls per day during the event window against an expected 10.3 (-25.8%).
Key facts
- Started
- 2023-07-04 (4 July 2023)
- Ended
- 2023-07-06 (6 July 2023)
- Status
- ended
- Type
- Cyber incident
- Severity
- 2 Moderate
- Scope
- port
- Chokepoints
- None
- Ports
- Nagoya
- Lanes
- None
- Countries
- Japan
- Confidence
- high: The timeline, the cause and the restart times come from the incident report published by the Nagoya Harbor Transportation Association, with consistent reporting by two technology outlets.
- First reported
- 2023-07-05 (5 July 2023)
- Severity basis: Port wide stoppage of 24 hours to 7 days; container work stopped at every Nagoya terminal from 2023-07-04 until 2023-07-06.
What happened
On 2023-07-04 (4 July 2023) the Nagoya Port Unified Terminal System stopped working at about 06:30 local time, and container work stopped at every terminal in the port. The Nagoya Harbor Transportation Association reported that a ransom note printed from a system printer at about 07:30, that the servers were found encrypted that afternoon, and that the Aichi Prefectural Police and the system maintenance company assessed the cause as a ransomware infection. Restoration from backups finished on 2023-07-06 (6 July 2023) and terminals restarted in sequence from 15:00, with the last resuming at 18:15. The association said no ransom amount was stated and that it did not contact the attackers. Press reports attributed the attack to the LockBit group.
Measured effect
Container ship port calls, Nagoya
- Baseline (expected)
- 10.3 calls per day
- Observed
- 7.7 calls per day
- Change
- -2.7 (-25.8%)
- Standardised score
- -0.8
- Event window
- 2023-07-04 to 2023-07-06 (3 days)
- Baseline window
- 2023-05-02 to 2023-06-26 (56 valid days)
- Method
- wfm-effect-1.0
- Computed
- 2026-09-16 (16 September 2026), data revision 1:86c331405645
Source: IMF PortWatch (portwatch.imf.org), International Monetary Fund, using UN Global Platform AIS data. Statistics derived by World Freight Monitor. Terms.
This is a measured change in public data during the event window, compared with a baseline before it. It shows timing, not cause. We describe an event as causing a change only when an official source says so.
Timeline
- The terminal system stops at about 06:30. A ransom note prints at about 07:30, servers cannot restart, and by about 14:00 the physical and virtual servers are found encrypted. The police cyber attack unit is notified. [s1]
- The association states publicly that the cause is a ransomware infection and sets a target of restarting terminal work on the morning of 2023-07-06. A virus is then found in backup data, delaying restoration. [s1] [s2]
- Backup restoration finishes at about 07:15, a network fault is cleared at about 14:15, and terminals restart from 15:00, with the last terminals resuming at 18:15. [s1] [s3]
Cause
The Nagoya Harbor Transportation Association reported that the Aichi Prefectural Police and the system maintenance company assessed the cause as a ransomware infection, entering through a vulnerability in a remote access device. Press reports attributed the attack to the LockBit group. Attributed by: Nagoya Harbor Transportation Association. [s1] [s2] [s3]
Resolution
2023-07-06 (6 July 2023): Systems were restored from backups and terminal work resumed in sequence on 2023-07-06, with the final terminals restarting at 18:15. The association said it found no evidence of data leaving the organisation. [s1]
Corrections
No corrections to this record as of 2026-09-16 (16 September 2026).
Sources
- [s1] Nagoya Harbor Transportation Association, NUTS システム障害の経緯報告, published 2023-07-26 (26 July 2023), accessed 2026-09-15. Archived copy. (official)
- [s2] The Record, Major Japanese port suspends operation following ransomware attack, published 2023-07-05 (5 July 2023), accessed 2026-09-15. Archived copy. (press)
- [s3] The Register, LockBit ransomware infection hits Japan's top cargo port, published 2023-07-06 (6 July 2023), accessed 2026-09-15. Archived copy. (press)