Maritime Cybersecurity: Threats, Defenses, and Regulations

Why ships and ports are cyber targets: ransomware, GPS and AIS spoofing, the NotPetya attack on Maersk, IMO and USCG rules, and how the maritime sector defends.
Published on
Saturday, September 5, 2026
Updated on
September 5, 2026

Maritime cybersecurity protects the digital and operational systems that move global trade by sea, spanning a ship's onboard technology, a port's terminal operations, and the software supply chain that links them. With roughly 90 percent of world trade carried on water, an attack that stops a vessel or a port reaches far beyond a single company.

The threat is climbing fast. Maritime cyber incidents rose 103 percent in 2025, from 408 to 828, with ransomware cases more than doubling, according to the CYTUR maritime threat report. What once meant a corrupted email system now means halted ports, spoofed navigation, and ships steered off course.

Regulators have answered. Since 2021, the International Maritime Organization has required shipping companies to address cyber risk within their safety management systems. 

Understanding why attackers target maritime infrastructure, recognizing where risks reside across vessels and ports, and learning from the industry's defining cyberattacks is now essential. By combining this knowledge with a strong grasp of current regulations and defense strategies, the maritime sector can effectively prevent cyber threats.

Why Shipping and Ports Have Become Cyber Targets

Attackers target shipping because the sea carries the economy. Ports and shipping lines sit at the chokepoints of global trade, so paralyzing one terminal ripples outward into delayed cargo, stranded vessels, and higher prices. That leverage makes ransomware against ports unusually profitable. A single paralyzed hub can back up vessels for miles and ripple into fuel prices and inflation.

Cybersecurity in the maritime industry has lagged its digitization, since the sector connected its systems faster than it secured them. Vessels built around decades-old operational technology now carry satellite links, remote monitoring, and shoreside connections, eroding the isolation that once protected them. Every new connection widens the attack surface across a fleet. Attacks on maritime operational technology jumped 150 percent in 2025, hitting the systems whose failure can put a vessel and its crew at risk.

Geopolitics sharpens the danger. Nation-states jam and spoof navigation signals in conflict zones, and ransomware crews increasingly operate as proxies for them. The physical stakes set maritime apart from most industries, since a compromised navigation or control system can cause collisions, groundings, and environmental disasters.

Accountability is divided. A single voyage can involve owners, operators, charterers, flag states, and dozens of vendors, leaving security gaps that no one party fully owns.

Where the Risk Lives: Ships, Ports, and the Supply Chain

Maritime cyber risk does not sit in one place. It spreads across three connected domains, each with its own systems and its own exposures.

Onboard Ship Systems

A modern vessel runs two technology worlds that increasingly overlap. Operational technology drives navigation, propulsion, steering, ballast, and cargo, including ECDIS electronic charts, GNSS positioning, and AIS tracking. Information technology handles administration, crew systems, and the satellite links that connect ship to shore, and malware often crosses between the two through an infected USB drive or a software update. As the two worlds converge, an intrusion that begins in email or crew Wi-Fi can reach the systems that steer the ship.

Port and Terminal Operations

Ports are dense clusters of automation. Terminal Operating Systems schedule and track every container, while cranes, gates, and vessel traffic services run on networked controllers. A single ransomware infection in a Terminal Operating System can stop a port from loading or unloading ships, which is why major hubs have become prime ransomware targets.

The Shipping Supply Chain

The wider supply chain extends risk far past any one hull. Shipping lines depend on software vendors, ship-management platforms, classification societies, and logistics partners, so a single compromised supplier can reach thousands of vessels at once. This is the supply chain attack route that turned a software update into a global shipping crisis in 2017. As remote maintenance and software updates spread across fleets, these trusted pathways have become one of the most dangerous routes of attack.

The Threat Landscape at Sea and in Port

Maritime attacks range from familiar ransomware to threats found almost nowhere else, such as the spoofing of satellite navigation. The table summarizes the main categories, and the sections after it examine the threats unique to the sector.

Threat Main Target Potential Impact
Ransomware Port systems, ship-management software Halted cargo and fleet operations
GPS / GNSS spoofing Vessel navigation False position, collision, or seizure risk
AIS manipulation Vessel identity and tracking Concealment, deception, false signals
OT malware ECDIS, engine, ballast, cargo systems Navigation and propulsion disruption
Phishing Crew and shore staff Stolen credentials, network access
Supply chain compromise Software and service providers Mass compromise across vessels
Data theft Ship designs, cargo, and crew data Espionage, targeted piracy

Phishing remains the most common way in, with social engineering aimed at crews and shore staff opening the door to the systems behind them. Beyond it, malware slips onto onboard operational technology through infected USB drives and unpatched updates, corrupting ECDIS charts or disabling alarms, and ransomware crews increasingly steal ship designs and technical documents before encrypting, raising espionage and national security concerns. The three threats below are the ones that make maritime security distinct.

GPS and GNSS Spoofing and Jamming

Ships depend on satellite signals to know where they are, and attackers exploit that trust. Spoofing broadcasts counterfeit signals that place a vessel in a false position, and jamming blocks the signal entirely. The scale has turned industrial: more than 12,000 spoofing incidents struck over 3,000 vessels in a two-week span of June 2025, concentrated in the Black Sea and the Persian Gulf, where manipulated positions have nudged ships toward territorial waters and raised the risk of collision.

Cross-checking position against radar, inertial systems, and paper charts, and training bridge teams to recognize signal anomalies, keeps a spoofed fix from becoming a grounding.

AIS Manipulation

The Automatic Identification System broadcasts a vessel's identity, position, and course so nearby ships can avoid collision. Because the signal carries no encryption, it can be forged: vessels have transmitted false identities, faked their locations, or disappeared from screens to evade sanctions and mask movements. Manipulated AIS data then misleads the port and traffic systems that depend on it.

Treating AIS as one input rather than ground truth, and correlating it with radar and other sources, limits how far a forged signal can mislead.

Ransomware on Ports and Ship Management

Ransomware is the most disruptive threat the sector faces, because it strikes the systems that keep cargo and fleets moving. Attackers encrypt a port's Terminal Operating System or a shipping line's management platform, then demand payment while operations sit frozen, and crews fall back on manual and paper processes for days. The average maritime cyberattack now costs more than $550,000, and a single major port outage cascades into the wider supply chain.

Segmented networks, tested offline backups, and a rehearsed recovery plan, backed by malware and ransomware monitoring, keep an infection from halting the business.

Incidents That Defined Maritime Cyber Risk

A handful of attacks turned maritime cybersecurity from a theoretical worry into a board-level priority.

The reference point remains NotPetya. In 2017, Russian military malware spread through a compromised Ukrainian accounting program and crippled the shipping giant Maersk within minutes, wiping more than 45,000 computers and 4,000 servers and shutting 76 port terminals. Recovery cost around $300 million, and for days the company ran its global operations on phone calls and spreadsheets.

Software platforms carry the same cascade risk. A January 2023 ransomware attack on the DNV ShipManager system forced roughly 1,000 vessels across 70 operators back to manual processes, a reminder that one shared platform can link the fate of many fleets.

Ports have proven just as exposed. The 2023 ransomware attack on the Port of Nagoya, Japan's busiest, halted container handling for days, and comparable attacks have struck major hubs across Europe and North America. One fleet-monitoring study logged 23,400 malware detections and 178 ransomware attacks across 1,800 vessels in just the first half of 2024.

The newest pattern is electronic rather than encrypted. Through 2025, mass GPS spoofing and jamming across the Black Sea and Persian Gulf disrupted navigation for tens of thousands of vessels, turning signal interference into a daily hazard in contested waters.

Rules Reshaping Maritime Cyber Risk

The rules governing maritime cybersecurity have tightened quickly. The IMO's Resolution MSC.428(98) folded cyber risk into the ISM Code, making it a mandatory part of every shipping company's safety management system since January 2021, and updated 2025 guidance frames the work around identifying, protecting, detecting, responding to, and recovering from incidents.

National and regional rules now build on that base. The US Coast Guard's 2025 cybersecurity rule requires US-flagged vessels and regulated facilities to appoint a Cybersecurity Officer, run annual assessments, report incidents to the National Response Center, and train their crews. The crew-training deadline passed in early 2026, and plan-approval requirements come next, making compliance an immediate demand.

Classification and regional frameworks add further weight. IACS Unified Requirements E26 and E27 set cyber-resilience standards for ships contracted from July 2024, the EU's NIS2 Directive covers European operators, and industry codes such as TMSA and the BIMCO guidelines shape day-to-day practice.

Key Defenses Across Ship and Shore

Cybersecurity for maritime operators spans steel hulls, dockside terminals, and shoreside offices. The practices below apply across all three.

  • Segment IT and OT networks. Separate navigation and control systems from administrative and shore networks so an intrusion cannot cross between them.
  • Control removable media. Restrict and scan USB drives and external devices, a frequent path for malware onto ECDIS and bridge systems.
  • Patch bridge and connected systems. Update ECDIS, communications, and networked equipment on a schedule coordinated with manufacturers.
  • Train crew and shore staff. Run regular awareness sessions on phishing, passwords, and media handling for everyone with system access.
  • Enforce MFA and access control. Require multi-factor authentication and least-privilege access to both vessel and shore systems.
  • Reduce the external attack surface. Find and fix internet-facing weaknesses through ongoing external attack surface management of shoreside IT.
  • Manage vendor and software risk. Vet suppliers and ship-management platforms, since one compromised vendor can reach an entire fleet.
  • Monitor networks afloat and ashore. Watch vessel and port networks for the anomalies that signal an intrusion or a spoofed position.
  • Plan to operate offline. Keep tested backups and rehearsed procedures for reverting to manual navigation and paper charts.
  • Appoint a Cybersecurity Officer. Assign clear accountability for maritime cyber risk, as the USCG rule now requires.

How CloudSEK Charts the Attack Surface of Shipping and Ports

As shipping companies and ports have digitized, their internet-facing footprint has grown faster than their defenses: corporate systems, logistics and port-community platforms, remote-access gateways, and the management consoles behind new connectivity. CloudSEK BeVigil discovers and continuously monitors that external attack surface, mapping exposed assets, weak configurations, and known vulnerabilities across a maritime organization's shoreside IT.

This addresses the shore-side and corporate layer, not the vessel itself. Onboard OT, ECDIS, GNSS, and AIS security, along with IMO and USCG compliance, remain separate work that BeVigil does not replace. What it adds is visibility into the internet-exposed weak points attackers probe first, so security teams close them before they become the way in.

Frequently Asked Questions

Why is the maritime industry a target for cyberattacks?

The sea carries about 90 percent of global trade, so disrupting a ship or port creates leverage and ransom pressure. Aging onboard technology, new connectivity, and geopolitical tension add to the appeal for criminals and nation-states.

What is GPS spoofing in shipping?

GPS spoofing broadcasts counterfeit satellite signals that trick a vessel's navigation into showing a false position. It has surged in conflict zones like the Black Sea and Persian Gulf, where it can redirect ships or raise collision risk.

What was the NotPetya attack on Maersk?

In 2017, Russian military malware called NotPetya spread through compromised software and crippled the shipping company Maersk, wiping tens of thousands of devices and shutting 76 terminals. It cost around $300 million and remains the landmark maritime cyber incident.

What does the IMO require for maritime cybersecurity?

The IMO's Resolution MSC.428(98) requires shipping companies to include cyber risk management in their safety management systems under the ISM Code. It has been applied since January 2021 and is verified during ISM audits.

What is the USCG 2025 cybersecurity rule?

The US Coast Guard's 2025 rule sets minimum cybersecurity requirements for US-flagged vessels and regulated port facilities. It mandates a Cybersecurity Officer, annual assessments, incident reporting, and crew training.

How do ships defend against cyberattacks?

Ships defend by segmenting IT and OT networks, controlling USB media, patching bridge systems, training crew, and monitoring for intrusions. Keeping paper charts and manual procedures ready ensures safe navigation if digital systems fail.

Related Posts
Maritime Cybersecurity: Threats, Defenses, and Regulations
Why ships and ports are cyber targets: ransomware, GPS and AIS spoofing, the NotPetya attack on Maersk, IMO and USCG rules, and how the maritime sector defends.
What is DNS and SSL Scanner? How Each Scan Works
A DNS and SSL scanner checks domain records and certificates for misconfigurations, subdomain takeover, weak TLS, and expiry. How each scan works and what it finds.
What is CVE Scanner? How CVE Scanning Works
A CVE scanner matches software against the known-vulnerability catalog to find exploitable flaws. How CVE scanning works, CVSS and EPSS scoring, and how to prioritize.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.