
Education:Universities and Educational Institutions, an Increasingly Attractive Target
17 de September de 2026Transport (air, maritime, rail and road) is one of the infrastructures with the least margin for failure: when it stops, there is no functional “limited performance” mode. A stationary truck means a delivery that does not arrive, a train that does not run means people who do not get to work, and a blocked port means an entire supply chain is brought to a standstill. This extreme dependence makes the sector a particularly attractive target for all kinds of attackers. This post explains why this happens, who is behind these attacks, what real-world consequences they have had, and what transport or logistics companies can do to protect themselves.
Why transport is such an attractive target
For decades, transport operated with isolated systems: traffic control, billing, fleet management and physical operations barely communicated with one another. Today, they are all connected. A single cyber incident can simultaneously affect ticket sales, route planning, terminal access control and communications with suppliers.
Added to this is the fact that much of the transport infrastructure combines IT systems (corporate networks, billing, websites) with OT systems (rail signalling control, fuel management, port automation) that have often been in operation for decades and were not designed with today’s cybersecurity requirements in mind. When these two worlds are connected without clear separation, a problem that begins on an office computer can ultimately affect physical operations.
According to ENISA’s first report dedicated to the sector, ransomware is the main threat in the rail segment, accounting for 45% of the incidents analysed, followed by data theft-related attacks and denial-of-service (DoS/DDoS) attacks, at around 25% each.
Who attacks and why
Not all attackers are looking for the same thing, and understanding their motivation helps anticipate the type of attack:
Economically motivated ransomware groups. They are by far the most active. Their goal is to encrypt a company’s systems and demand a ransom, or steal data and threaten to publish it. They do not usually choose a victim specifically because it is a transport company, but because it presents an exploitable vulnerability: a weak credential, an unpatched server or a misconfigured remote access point. The Akira group, responsible for the attack on British company KNP Logistics in 2023, is a representative example of this profile.
Geopolitically motivated actors or hacktivists. They attack transport and energy infrastructure as a means of exerting political pressure or causing disruption, often in the context of a broader conflict. The attacks on Iran’s railway system (July 2021) and the country’s petrol station network (October 2021), both attributed by Tehran to actors linked to foreign powers, fit this pattern: the objective was not money, but to generate chaos and social disruption.
Groups focused on data theft and extortion. They seek customer, employee or payment information to resell it or use it for fraud. The 2024 attack on Transport for London, attributed to the group known as Scattered Spider, compromised the personal data of millions of users and disrupted functions such as journey refunds, resulting in recovery costs amounting to tens of millions of pounds.
What are the real-world consequences?
The consequences are not limited to IT systems, and it is important to distinguish between several types of impact:
Direct operational disruption. In May 2021, DarkSide gained access to Colonial Pipeline’s corporate network through an inactive VPN account with a reused password. The ransomware never reached the pipeline’s control system, but after losing visibility over billing, the company decided as a precaution to shut down a pipeline that transports around 45% of the fuel consumed on the US East Coast. The result: six days of disruption, shortages and emergency declarations in 18 states.
Knock-on effects across the global supply chain. In June 2017, the NotPetya malware disabled Maersk’s IT infrastructure within hours, including the management systems of 76 port terminals. For days, ports could not reliably identify which containers should enter or leave. The direct cost to the shipping company was estimated at between $200 million and $300 million, and the impact spread to other companies that depended on its routes.
Bankruptcy of the company itself. The most extreme case is KNP Logistics, a British transport company with a 158-year history and 700 employees. In 2023, the Akira group gained access to its systems by guessing a single employee’s password, encrypted its operational and financial data, and demanded a ransom of around £5 million, which the company was unable to pay. Without access to its own records, KNP went into liquidation months later.
Direct impact on people’s mobility. The 2024 attack on Transport for London disrupted real-time train arrival information, suspended the issuance of new travel cards and blocked refunds for days. Transport services continued to operate, but the digital layer that makes them usable stopped working.
The most common entry vectors
Almost all of the incidents above share a very similar initial access pattern, and understanding it makes a significant part of the protection challenge easier:
- Weak or reused credentials, as in the Colonial Pipeline and KNP Logistics incidents.
- Poorly segmented remote or third-party access, typical of environments where suppliers, carriers or maintenance providers need to connect to internal systems.
- IT/OT convergence without effective isolation, allowing a compromise on the office network to reach operational control systems.
- Software supply chains, as in the case of NotPetya, which spread through a legitimate vendor update.
- Social engineering and phishing, which are involved in a significant proportion of the initial access incidents reported by ENISA.
How to protect against these threats
None of these measures is unusual, but applying them consistently makes the difference between a contained incident and a catastrophic one:
- Rigorous Privileged Access Management (PAM): no one —employee, supplier or automated system— should have more access than strictly necessary, nor should privileged access be permanent.
- Effective segmentation between IT and OT, so that a compromised endpoint on the corporate network has no direct path to physical control systems.
- Multi-factor authentication for all remote and administrative access, with no exceptions for “trusted” accounts.
- Tested backups isolated from the primary network, so that encryption cannot reach them as well.
- Third-party access control, with visibility and traceability over what each supplier connected to the systems does.
- Continuous staff training, as a significant proportion of initial compromises still depend on preventable human error.
How to respond during an incident
Once an attack has occurred, the speed and order in which actions are taken matter just as much as the tools being used:
- Immediately isolate affected systems to stop lateral movement, without shutting down equipment that may contain useful forensic evidence.
- Activate the predefined incident response plan, with clear roles and alternative communication channels in case corporate email has been compromised.
- Notify the competent authorities (in Spain, INCIBE-CERT and, depending on the sector, CCN-CERT) and, if personal data has been affected, notify the AEPD within the statutory deadlines.
- Assess restoration from backups before considering any ransom payment, which guarantees neither data recovery nor that the stolen information will not subsequently be leaked.
- Review and strengthen the access points that enabled the intrusion to prevent the same vector from being exploited again while operations are being restored.
The key lesson
In all the cases above, the attacker did not need to compromise the physical machinery —a train, a port crane or a fuel pump. It was enough to gain access to the surrounding management, billing or control systems. The question every transport operator should be asking is not simply “Is the connection encrypted?”, but rather “What permissions does that access have once it is inside?”
Endurance’s RSW (Remote Shielded Workspace) approach is based precisely on this principle: isolating the critical asset, not merely the endpoint connecting to it. Even if an operator’s, driver’s or supplier’s device is compromised, that compromise does not spread to the control system or the data it manages, because there is an air gap between the access point and the asset. These policies are applied equally to every requester, with each access request evaluated before access is granted.
In a sector where an IT failure can result in a stationary train or a country without fuel, protecting access to the asset —rather than trusting that the connecting device will always be clean— ceases to be merely a technical issue and becomes a matter of business continuity.
Frequently asked questions
Why do attackers target small transport companies if their main objective is usually money?
Because most attacks do not select victims based on whether they are large or strategically important, but on whether they are vulnerable. Ransomware groups conduct large-scale scans for weak credentials, misconfigured remote access or unpatched software, and attack whoever they find exposed. KNP Logistics was not a national critical infrastructure operator: it was a company with a weak password.
Is protecting OT systems (operational control) the same as protecting IT systems (corporate networks)?
No. OT systems —rail signalling, port automation, fuel management— often have lifecycles measured in decades and do not always support conventional patches or antivirus software. Effective protection involves isolating them from the corporate network rather than attempting to secure them using the same tools as an office computer.
Is paying the ransom a reasonable option if the attack brings operations to a standstill?
Paying does not guarantee full data recovery or prevent the data from being leaked anyway, and it funds the attacking group’s next victim. For this reason, authorities (INCIBE, NCSC, CISA) recommend exhausting restoration options from backups first and considering payment only as a last resort, with legal and technical advice.
How do I know whether my transport company is a likely target?
Any company with remote access for employees or suppliers, unpatched legacy systems, or stored customer data is a potential target. The sector itself is not the decisive factor: the exposed attack surface is.
Are antivirus software and a firewall enough?
No. Most of the incidents described were not caused by the absence of these tools, but by uncontrolled privileged access: a reused credential, an inactive VPN account or a supplier with more permissions than necessary. Access management is just as important as perimeter security.
What should I do in the first few hours of an attack?
Isolate the affected systems without abruptly shutting them down (to preserve evidence), activate the incident response plan, notify INCIBE-CERT or CCN-CERT as appropriate, and avoid making ransom payment decisions under pressure before assessing restoration alternatives.
Sources
ENISA Threat Landscape: Transport Sector (2023) — First report by the EU Agency for Cybersecurity on threats, threat actors and trends in aviation, maritime, rail and road transport (2021–2022). ENISAhttps://www.enisa.europa.eu/publications/enisa-transport-threat-landscape
DarkSide Ransomware: Colonial Pipeline Advisory — Official advisory from the US Cybersecurity and Infrastructure Security Agency (CISA) on the May 2021 ransomware attack against Colonial Pipeline. CISAhttps://www.cisa.gov/news-events/cybersecurity-advisories/aa21-131a
How a hacker’s typo helped bring down a 158-year-old firm — Report on the Akira ransomware attack that led to the collapse of transport company KNP Logistics. BBC News
NotPetya ransomware caused $300m losses to Maersk — Coverage of the financial and operational impact of NotPetya on shipping company Maersk in 2017. Security Affairshttps://securityaffairs.com/62085/malware/maersk-notpetya-losses.html
Cyberattack paralyses all petrol stations in Iran — Report on the 2021 cyberattack that disrupted thousands of petrol stations across Iran. AsiaNewshttps://www.asianews.it/es/oriente-medio/iran/ataque-de-piratas-informaticos-anonimos-paraliza-todas-las-gasolineras-de-iran
TfL admits 2024 cyberattack may have affected over 10 million people — Coverage of the full scope of the 2024 cyberattack on Transport for London and the user data compromised. TechRadar





