Arab Maritime Petroleum Transport Company Data Breach

Alleged

Ransomware claim involving Arab Maritime Petroleum Transport Company

Published: Sep 1, 2026 Krybit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Arab Maritime Petroleum Transport Company
Industry
Logistics
Threat Actor
Krybit
Date of Incident
Sep 1, 2026

Executive Summary

On September 1, 2026, the krybit ransomware group listed Arab Maritime Petroleum Transport Company (AMPTC) on its dark web portal. SOCRadar Dark Web Monitoring identified this listing. AMPTC operates within the maritime petroleum transport sector, providing essential tanker and marine logistics services to the petroleum industry. The nature of its operations and the critical infrastructure it manages may attract ransomware and extortion activities. In the preceding 60 days, krybit had claimed 58 other victims, with a primary focus on the Professional Services, Other, and Technology industries. Geographically, the group has shown concentration in India, Thailand, and Brazil. Previous targets in the technology and maritime/transport sectors by krybit include DMT Consulting Private Limited, Syscon (Thailand) Co., Ltd., Actini Group, and CH. Karnchang Public Company Limited. AMPTC’s targeting aligns with krybit’s recent activity in these sectors.

Technical Analysis

A stealer-log query for amptc[.]net revealed 25 records spanning February through August 2026, with 16 of those classified as employee credentials. Key endpoints identified include Microsoft 365 identity provider (multiple records), Lloyd’s Register B2C authentication (a maritime-sector identity platform), International Association of Ports and Harbors (IAPH) authentication service, and a Maritime Stevedoring and Cargo Handling platform. This credential exposure profile indicates a significant corporate intrusion risk for AMPTC. The presence of multiple distinct corporate usernames across various high-value identity endpoints over a six-month period, with no evidence of credential rotation, presents a substantial risk. Specifically, the exposure of credentials related to Lloyd’s Register and IAPH authentication services provides a threat actor with potential access to critical industry platforms used for vessel registration, inspection records, and port logistics coordination. Combined with the Microsoft 365 exposure and the six-month window of unrotated access, this presents a high-risk scenario for a petroleum transport operator. Immediate actions should include rotating all Microsoft 365 credentials and conducting a thorough audit of all sector-platform access since February 2026.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.