Infiltration of the Port of Seattle's systems enabled the theft of people's names, birthdates, Social Security numbers, government ID card numbers or driver's license numbers, and certain medical details, according to a notice from the Port, which detailed free credit monitoring services for all of those whose information had been impacted. "The threat actors accessed and downloaded some personal information from previously used Port systems for employee, contractor, and parking data. The Port holds very little information about airport or maritime passengers, and systems processing payments were not affected," said the notice, which also emphasized the absence of any untoward cyber activity against the Port's systems since late August. Such a disclosure comes as Rhysida has been continuously targeting various sectors since its emergence in May 2023.
An In-Depth Guide to Ransomware
Get essential knowledge and practical strategies to protect your organization from ransomware attacks.
The user, operating under the name Sadpainy, released code intended to replicate Stuxnet, the malware that reportedly destroyed a fifth of Iran's uranium enrichment centrifuges.
The malware, which has been active since at least 2023, adopted MQTT for its command-and-control (C2) communications in variants developed between 2024 and 2025, according to a report by Black Lotus Labs.