Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Data Privacy Weekly: Your Industry News Series

success-story

Data Privacy Weekly is Encryption Consulting’s recurring roundup of the data-privacy and security stories that mattered that week. This edition covers the Port of Nagoya ransomware attack, NHS patient data stolen via the University of Manchester, Shell’s Clop/MOVEit breach, Smartpay’s ransomware incident, and TSMC’s LockBit-linked supplier breach. The one action to prioritize: confirm which of your vendors or file-transfer tools could expose you the way MOVEit exposed Shell and hundreds of others.

Key Takeaways

  • A ransomware attack halted container processing at the Port of Nagoya, Japan’s largest port and a hub for roughly 10% of the country’s trade volume, disrupting Toyota’s export flow.
  • A ransomware attack on the University of Manchester exposed NHS trauma-patient data, including NHS numbers and partial postcodes, from more than 200 hospitals.
  • Shell confirmed it was hit by the Clop group’s mass exploitation of a MOVEit zero-day; by the time reporting on this incident concluded later in 2023, the campaign had affected more than 2,600 organizations and over 77 million individuals globally.
  • New Zealand eftpos provider Smartpay disclosed a ransomware attack with customer data theft, though it said card data itself was not compromised.
  • Apple supplier TSMC was drawn into a $70 million LockBit ransomware extortion attempt after the gang breached one of TSMC’s suppliers, Kinmax Technology.

What Is Data Privacy Weekly, and Why Does This Edition Matter?

Data Privacy Weekly is a curated recap of the week’s most consequential data-privacy, encryption, and security-incident news, each item paired with a plain-language note on what it means for enterprise security teams. Stories are selected from named primary reporting at the time of original publication (July 2023); this edition was reviewed in September 2026, with the MOVEit/Clop story specifically updated to reflect the campaign’s eventual full scale, which was still unfolding when this was first written.

This week is unusually concentrated: four of five stories are ransomware, hitting a port, a university handling health data, an oil major through a third-party tool, and a payments provider, in the same seven days. That density is itself the lesson: ransomware in 2023 (and today) is a supply-chain and OT problem as much as an endpoint problem.

This Week’s Data Privacy and Security Headlines

01. Japan’s Largest Port Grinds to a Halt in Ransomware Attack

What happened: A ransomware attack on July 4 hit the container-terminal systems at the Port of Nagoya, Japan’s largest port, halting container processing. The port handles over two million containers a year, roughly 10% of Japan’s trade volume, and is a key export point for Toyota vehicles. The port authority worked to restore systems and resume operations within about a day.

Why this matters for enterprises: This was an attack on operational technology (OT), the systems that physically move containers, not just office IT. Any organization running logistics, manufacturing, or industrial control systems needs IT/OT network segmentation and an incident response plan specifically for OT downtime, since a ransomware payload doesn’t need to touch the OT network directly to force it offline as a precaution.

02. NHS Data Stolen in University Cyberattack, Patient Information Compromised!

What happened: A ransomware attack on the University of Manchester exposed NHS trauma-patient data, including NHS numbers and partial home postcodes, drawn from more than 200 hospitals that had shared data with the university for research purposes. The university notified NHS Trusts and warned affected patients about the risk of follow-on attacks while forensics teams assessed the damage.

Why this matters for enterprises: Universities and research institutions often hold sensitive third-party data (health records, in this case) under data-sharing agreements that weren’t designed with the same security rigor as the originating healthcare system. Any organization sharing regulated data with an academic or research partner should confirm that partner’s security posture matches the sensitivity of what’s being shared, not just its own.

03. Shell Confirms Impact by Clop Ransomware Attack on File Transfer Tool

What happened: Shell confirmed the Clop ransomware gang’s breach of the MOVEit file-transfer tool affected it, and Clop listed Shell on its extortion site. Shell said core IT systems were unaffected. Other named UK victims of the same MOVEit campaign included the BBC, British Airways, Aer Lingus, Boots, Ofcom, and Transport for London.

Where this stands now: This was one of the earlier disclosures in what became one of the largest data-theft campaigns on record. As reporting continued through the rest of 2023, independent trackers put the final known tally above 2,600 organizations and roughly 77 million individuals affected, spanning education, healthcare, and financial services as the hardest-hit sectors.

Why this matters for enterprises: A single zero-day in one widely used file-transfer product created blast radius across thousands of unrelated organizations, regardless of their own security maturity, because they depended on a vendor or partner running the same software. Third-party and fourth-party risk management now has to include the specific software your vendors run, not just their general security posture.

04. Eftpos Provider Smartpay Hit by Ransomware Attack, Customer Data Stolen

What happened: NZX-listed eftpos provider Smartpay disclosed a ransomware attack resulting in stolen customer data, primarily affecting retailer clients. Smartpay said no card data was compromised, since it does not store card information, and its payment systems remained fully operational throughout. The company engaged cybersecurity specialists and government authorities while investigating the scope of the theft.

Why this matters for enterprises: “No card data was stolen” is a meaningfully narrower claim than “no data was stolen,” and both should be communicated separately in breach notifications. Payment providers should be able to state precisely what data categories they do and don’t retain, because that scoping directly determines both regulatory exposure and what customers actually need to do next.

05. Apple Supplier Faces $70 Million Ransomware Attack by LockBit Gang

What happened: Taiwan Semiconductor Manufacturing Company (TSMC), an Apple chip supplier, was drawn into a data breach after the Russian-speaking LockBit ransomware gang breached one of TSMC’s own suppliers, Kinmax Technology, and demanded $70 million from TSMC to prevent publication of stolen data. TSMC said the breach mainly involved server setup information and that its own operations and customer data were unaffected; Kinmax apologized to customers without detailing the full impact.

Why this matters for enterprises: Attackers increasingly go after the smaller, less-defended supplier to reach a larger, better-defended target’s name and leverage; the ransom demand here was aimed at TSMC’s brand exposure, not Kinmax’s own ability to pay. Supply-chain risk assessments need to account for what a supplier’s breach could be used to extort from you, not just what data the supplier itself holds.

Story-to-Action Decision Table

StoryRisk CategoryBusiness ImpactRecommended Action
Port of NagoyaOT / operational disruptionSevere: halted physical operations, trade impactSegment IT/OT networks; build an OT-specific incident response and downtime plan
NHS / University of ManchesterThird-party data-sharing riskHigh: regulated health data, patient notification dutyAudit security posture of any research or academic partner holding shared regulated data
Shell / Clop / MOVEitSupply-chain software vulnerabilitySevere at scale: affected 2,600+ organizations globallyInventory which vendors run which file-transfer and third-party software; patch on vendor disclosure, don’t wait
SmartpayPayment provider data theftMedium: no card data, but customer data exposurePrecisely scope and communicate what data categories were and weren’t affected
TSMC / Kinmax / LockBitSupply-chain extortion leverageHigh: reputational and financial extortion risk via a smaller supplierAssess suppliers for what a breach of them could be used to extort from you, not just their own data holdings

How to Turn This Week’s Headlines Into Action

  1. Map each story to your own exposure. Identify your OT/logistics systems, any third parties holding regulated data on your behalf, the file-transfer and vendor software you depend on, and your smaller, less-defended suppliers.
  2. Check current control coverage. Confirm IT/OT segmentation, vendor security assessments, patch cadence on third-party software, and supplier risk scoring are actually in place, not assumed.
  3. Prioritize by likelihood and impact. A known, exploited zero-day in software you run should outrank a hypothetical supplier risk that hasn’t materialized.
  4. Assign an owner and a deadline. Ransomware and supply-chain risk usually cross IT, legal, and procurement; name a single owner who coordinates across them.
  5. Verify the fix. Confirm patches were actually applied across every affected instance (not just the ones you knew about), and that offline backups for OT systems are tested, not just present.

Encryption Consulting’s Take

The MOVEit/Clop campaign is the story that grew the most between original publication and this review, and it’s the one worth re-reading with that growth in mind. What looked in July 2023 like “Shell and a handful of others hit by a file-transfer bug” became, by the time the dust settled, one of the largest data-theft campaigns ever recorded, driven by a single vulnerability in software almost none of the ultimate victims chose or controlled directly. The Port of Nagoya and TSMC/Kinmax stories make the same point from a different angle: ransomware operators are deliberately targeting the physical and supply-chain layer, not just data, because that’s where the leverage and disruption are highest.

Limitations of This Roundup

This edition reflects public reporting available at the time each story was originally covered (July 2023), reviewed and fact-checked in September 2026. The MOVEit/Clop victim and individual counts cited here come from independent trackers reporting as of November 2023 and may not reflect the absolute final tally, as some notifications continued afterward. This roundup is informational, not legal, compliance, or incident-response advice.

Key Terms in This Edition

  • Ransomware: malware that encrypts or disrupts systems and demands payment, often combined with data theft (double extortion).
  • OT (operational technology): the systems and networks that control physical processes, such as container handling or manufacturing equipment.
  • Zero-day vulnerability: a flaw exploited before the vendor has released a patch.
  • Clop: a ransomware and data-extortion group known for exploiting file-transfer software zero-days at mass scale.
  • LockBit: a ransomware-as-a-service operation associated with high-value extortion demands.
  • Eftpos: electronic funds transfer at point of sale, a common term in Australia/New Zealand for card payment terminals.

Frequently Asked Questions

How big did the MOVEit/Clop breach ultimately get?
Far bigger than it looked in July 2023, when Shell’s exposure was first confirmed. As victim organizations continued reporting through the rest of 2023, independent trackers put the final known tally at more than 2,600 organizations and over 77 million individuals affected, making it one of the largest supply-chain data-theft campaigns on record.

Why did one vulnerability in MOVEit affect so many unrelated companies?
MOVEit is file-transfer software used by thousands of organizations and their vendors to move sensitive files. The Clop group exploited a single zero-day vulnerability in the software itself, so any organization running an unpatched MOVEit instance, or relying on a third party that did, was exposed regardless of its own security posture.

Does a ransomware attack always mean data was also stolen?
No, but it increasingly does. Modern ransomware operations, including the Clop group behind the Shell and MOVEit incidents, routinely combine encryption or disruption with data exfiltration, then threaten to publish the stolen data (double extortion) whether or not the victim can restore from backup.

What should a manufacturer or logistics operator take from the Port of Nagoya attack?
That operational technology tied to physical logistics, container processing, in this case, is now a direct ransomware target, not just back-office IT. Segmentation between IT and OT networks, offline backups, and a tested incident response plan for OT downtime matter as much as endpoint protection on office laptops.

How Encryption Consulting Can Help

Supply-chain and OT-adjacent ransomware, the theme running through this edition, is fundamentally a crypto-agility and inventory problem: you can’t protect what you can’t see. CBOM Secure discovers and inventories cryptographic assets and dependencies across your environment and vendor software, surfacing exactly the kind of hidden exposure a MOVEit-style third-party vulnerability creates. For the supply-chain integrity angle in stories like TSMC/Kinmax, CodeSign Secure ensures software and firmware releases are signed and verifiable end to end, so a compromised link in the chain can’t silently ship tampered code.

Talk to an expert about CBOM Secure, or see CodeSign Secure in action.

Conclusion

Four ransomware stories in one week, hitting a port, a university’s health-data partner, an oil major through a vendor’s software, and a payments provider, isn’t a coincidence of timing. It’s what ransomware looked like in mid-2023, and largely still looks like today: a supply-chain and OT problem that spreads through dependencies you may not fully control, which is exactly why visibility into those dependencies matters as much as the controls on your own network.

Continue the series with the next edition, or go back to the previous edition of Data Privacy Weekly.