xin.bz

Future Insights · 2017–2027

Every Ship Is a Network: Maritime Cyber Risk From NotPetya to the 2027 Deadline

Xin.bz Future Insights ·

TL;DR

  • NotPetya took Maersk offline in June 2017 at $250–300 million and ten days of rebuilding. Nine governments attributed it to Russian military intelligence.
  • The U.S. Marine Transportation System carries $5.4 trillion a year through roughly 360 ports, on systems connected to the internet after they were designed.
  • Coast Guard protection teams find default credentials in place on more than two-thirds of their missions.
  • Ports are the pressure point ashore: Nagoya lost two days in 2023 and DP World Australia stranded 30,137 boxes across five terminals.
  • One software vendor reaches a thousand hulls. The January 2023 attack on DNV's ShipManager touched roughly 70 customers operating about 1,000 vessels.
  • GNSS spoofing went from a 2013 experiment to 35–117 vessels a day affected in the Mediterranean and Black Sea.
  • Three regimes come due together: IMO rules since 2021, IACS UR E26 and E27 from July 2024, and U.S. plans by July 16, 2027.

Future Insight — part of the Xin.bz Future Insights series.

At a glance

  • $5.4 trillion in goods and services move through the U.S. Marine Transportation System each year, across roughly 360 commercial ports, supporting more than 30 million jobs (GAO, 2025)
  • $250–300 million — the cost of NotPetya to Maersk in 2017, attributed by nine governments to Russian military intelligence
  • 30 hours — a U.S. maritime facility shutdown from Ryuk ransomware in 2019
  • 1,000 vessels touched by one software vendor’s ransomware incident in 2023
  • 30,137 containers stranded in Australia across five terminals in 2023
  • Two-thirds of Coast Guard cyber protection missions found default credentials in place
  • 35–117 vessels a day affected by GNSS interference in the Mediterranean and Black Sea; 1,700+ events around the Strait of Hormuz in early 2026
  • July 16, 2027 — the date U.S. cybersecurity plans come due

The industry already has its worked example

In June 2017 the NotPetya malware reached A.P. Møller-Maersk through a compromised accounting package and spread across the company’s network in hours. Screens went black in Copenhagen, in Rotterdam, at gates in New Jersey and Mumbai, and the booking system that tells terminals which box goes where stopped answering. Maersk put the cost at up to $300 million. Recovery took ten days and required rebuilding 4,000 servers and 45,000 computers. It ran from a single surviving copy of the company’s network directory, found on a server in Ghana that a local power cut had taken offline before the malware arrived. Congestion followed at terminals operated by APM Terminals, which runs 76 ports, with delays reported in Denmark, India, Spain, the Netherlands and the United States.

Maersk was collateral damage rather than a target. In February 2018 the United Kingdom’s National Cyber Security Centre concluded that the Russian military was “almost certainly responsible”, and the White House called it “the most destructive and costly cyber-attack in history”. Nine governments attributed it jointly to GRU unit 74455. The malware was aimed at Ukraine. A shipping line carrying a fifth of world container capacity became one of its most expensive casualties, because its network was flat, connected, and running the world’s freight bookings.

That is the shape of maritime cyber risk. The U.S. Marine Transportation System alone moves $5.4 trillion of goods and services a year through roughly 360 commercial ports, and supports more than 30 million jobs. It runs on systems designed for reliability at sea and connected to the internet afterward. A 2019 Ryuk ransomware infection shut one U.S. maritime facility for 30 hours, which is the scale at which most of this happens: short, expensive, and rarely named in public.

Nine years of the record

DateEventEffect
June 2017NotPetya reaches MaerskUp to $300M; 4,000 servers and 45,000 PCs rebuilt
2018COSCO, Port of Barcelona, Port of San DiegoRegional booking and terminal systems offline
2020MSC, CMA CGM, and the IMO itselfBooking platforms and the regulator’s own site down
Jan. 2023Ransomware at DNV’s ShipManager~70 customers, ~1,000 vessels
July 2023LockBit at the Port of NagoyaContainer operations halted two days at 10% of Japan’s cargo trade
Nov. 2023DP World AustraliaFive terminals, 40% of national box trade, 30,137 containers stranded
Mar. 2024Congressional report on crane supplierUndocumented cellular modems found on delivered equipment
Dec. 2025Adriatic Port Authority (Ancona)$10M bitcoin demand, Adriatic rerouting
Dec. 2025RAT on the ferry FantasticMalware carried to a bridge workstation on a USB drive
June 2026Shipping Association of New York & New JerseyData leaked by the Qilin group
Aug. 2026North Carolina PortsWilmington, Morehead City and Charlotte Inland Port on manual processing

The pattern in that column is worth reading twice. Every entry after 2020 involves cargo standing still, and the mechanism is the same each time: gate systems, terminal operating systems, and booking platforms are the software that decides whether a box moves.

Nobody has reliable numbers, and that is an official finding

Industry counts circulate widely. One 2026 vendor white paper puts maritime incidents at 828 in 2025 against 408 in 2024, with ransomware cases more than doubling to 372. Another records roughly a thousand navigation disruptions a day touching more than 40,000 vessels.

Set those beside the regulator’s own position. In its 2025 review of maritime cybersecurity, the U.S. Government Accountability Office found that Coast Guard cybersecurity incident data “are not sufficiently reliable” for describing how often incidents occur. It recommended the service fix its case management system so cyber deficiency data becomes accessible in full. The Coast Guard’s own Cyber Trends and Insights in the Marine Environment reports describe a 17% year-over-year rise in reported incidents, on a reporting base the GAO has flagged as incomplete.

Both things hold at once: the direction is consistent across every source, and the denominator is unknown. Reported figures describe reporting behaviour as much as attacker behaviour, and an industry with voluntary disclosure and commercial reputations at stake reports the incidents it has to. The useful readings are therefore the named events, where the effect is measurable, and the assessment findings, where an inspector looked directly at the systems.

The attack surface has three layers

Shore side. Terminal operating systems, gate automation, customs interfaces, booking platforms, and the inland rail and trucking systems that depend on them. This layer carries the most incidents because it looks like ordinary enterprise IT and behaves like critical infrastructure.

Vessel. Electronic chart display (ECDIS), automatic identification (AIS), engine and propulsion control, ballast water management, cargo and ballast monitoring, and integrated automation. The 2026 threat reporting records attacks penetrating these systems directly, with chart data manipulation and remote access to engineering systems among the observed outcomes.

Link. VSAT, Starlink, and cellular connections between the two. The integration of satellite communications with onboard operational technology is the change that widened the surface, because it connected equipment designed for an isolated environment to a permanent open channel.

Global navigation satellite signals arrive at a ship at roughly the power of a car headlight seen from 20,000 kilometres away, which makes them straightforward to overwhelm with a local transmitter. Jamming denies the signal. Spoofing replaces it with a false one, and the ship’s own instruments report the false position as fact.

The academic work came first and said exactly this. In June and July 2013 a University of Texas at Austin team led by Todd Humphreys took control of a 65-metre yacht on the Ionian Sea, the White Rose of Drachs. They used the first openly acknowledged GPS spoofing device, then measured how readily the bridge instruments accepted the false solution. The finding: a spoofed vessel steers off course while its own displays read nominal.

Four years later the same technique appeared in operation. In June 2017 the U.S. Maritime Administration issued advisory 2017-005A after more than twenty vessels in the Black Sea reported GPS positions placing them at an inland airport. A 2019 C4ADS investigation then documented the practice systematically. Using a GPS receiver aboard the International Space Station, it geolocated spoofing sources across Russia and Syria, and established the activity as routine state practice rather than isolated malfunction.

PeriodObserved activitySource
2013First open academic spoof of a vessel at seaUT Austin
June 201720+ vessels in the Black Sea placed at an inland airportMARAD 2017-005A
2019Spoofing sources geolocated across Russia and SyriaC4ADS
2021–2435–117 vessels a day affected, Mediterranean and Black SeaGAO
Early 20261,700+ interference events; 1,100+ vessels spoofed in 24 hoursIndustry reporting

The trend in that column is the story: a laboratory result in 2013, a regional incident in 2017, a documented state practice by 2019, a daily background rate by the mid-2020s, and a wartime concentration in 2026. The capability moved from proof to routine in roughly a decade.

The second-order effect is what matters for trade. A ship’s AIS transponder takes its position from the same GNSS receiver, so a spoofed vessel broadcasts a false position to every other ship and shore station in range. Interference against one hull degrades the traffic picture for everyone, and it lands in the busiest and most contested water: the Hormuz corridor carries roughly a fifth of world seaborne oil and gas.

Groundings and collisions in the Baltic through 2024 and 2025 were publicly linked to satellite navigation interference, which places the consequence in hull and cargo losses rather than in data.

One vendor reaches a thousand hulls

Maritime software concentrates. Fleet management, planned maintenance, chartering, and crew systems run on a small number of platforms sold to hundreds of operators, and a compromise at the vendor reaches every customer at once.

The January 2023 ransomware attack on DNV’s ShipManager suite demonstrated the arithmetic: roughly 70 customers, about 1,000 vessels, and a two-month restoration to full service. The ships sailed throughout, because the affected systems were shore-managed, and the operators lost the tooling that tracks maintenance, compliance and technical status across their fleets.

Equipment carries the same concentration. A March 2024 joint congressional investigation reported that one Chinese state-owned manufacturer supplies close to 80% of ship-to-shore cranes installed at U.S. ports, and that investigators found cellular modems attached to crane control systems that appeared outside the sales contracts and the delivery documentation. The manufacturer disputes the findings.

The GAO examined the same question and reached a broader conclusion. Coast Guard teams evaluated more than 90 Chinese-manufactured cranes and found vulnerabilities that reflect weaknesses across the marine transportation system rather than flaws specific to one manufacturer.

Both findings point the same way for an operator. One supplier holds four-fifths of the machines that lift every container off every ship at the receiving end of the world’s largest import market. The security baseline for port control equipment runs low wherever it was built.

The crew is the entry point

In December 2025 a remote access trojan reached the bridge workstation of the ferry Fantastic when a crew member, acting on outside instruction, inserted a USB drive. That single case describes the layer that sits beyond every firewall.

Crews rotate, work under time pressure, and now carry personal connectivity aboard through the same satellite links that serve the ship. Charts update by USB on many vessels. Contractors board with laptops for engine and automation work. Each is a routine operational practice that doubles as an entry path, which is why the training requirement in the new U.S. rules took effect before the technical ones.

Who is on the other side

The GAO names five threat sources against the marine transportation system: China, Iran, North Korea, Russia, and transnational criminal organisations, with hacktivists and insiders alongside them. It cites the Chinese state- sponsored Volt Typhoon group for pre-positioning in critical infrastructure, and Cl0p and Black Basta among the Russian-based ransomware operations. Grouped by what they want, that resolves into three.

Criminal ransomware crews supply the volume. LockBit at Nagoya, Anubis at Ancona with a $10 million bitcoin demand, Qilin against the New York and New Jersey shipping association: these are extortion businesses that treat a terminal’s downtime cost as their pricing model. A port that loses a day of gate moves pays more per hour than almost any other target, which is what puts maritime logistics high on their lists.

State and state-aligned operators want position rather than payment. GNSS jamming and spoofing at the scale recorded around the Strait of Hormuz requires transmitters, power and persistence, and it runs continuously rather than in bursts. Equipment supply chains belong in the same category: a modem on a crane control system is an access question, and access held quietly is worth more than access used.

Insiders and proximity access close the set. The Fantastic case ran through a crew member and a USB drive. Contractors, chandlers, surveyors and pilots all board with devices, and a vessel in port hosts more outside hands in a day than most facilities see in a month.

What defense looks like in practice

Coast Guard cyber protection teams publish what they find when they look. Their assessments report default credentials still in place on more than two- thirds of missions, and a 71% year-over-year rise in the use of stolen or compromised credentials in reported incidents. Between 2021 and 2024 those teams ran 60 security assessments, 21 threat-hunting operations and 9 incident responses across the system.

That is the baseline the defensive measures work against. The ones that have held up across these incidents are unglamorous and mostly architectural, and each has a case where it decided the outcome.

MeasureWhat it doesWhere it decided an outcome
SegregationKeeps navigation, engine automation and crew internet on separate networks, containing a compromise to the layer it lands inOperators who came through 2023 and 2025 with cargo moving had split terminal systems from corporate IT beforehand
Offline recoveryHolds directory and system state where an attacker cannot reach itMaersk restored in ten days on a domain controller that sat offline in Ghana through the attack
Manual fallbackRuns gates, stowage and position fixing on paper and radarNorth Carolina Ports kept cargo moving in August 2026 on manual gate processing
Vendor disciplinePuts security terms, software bills of materials and remote-access limits on the procurement deskThe DNV and crane cases both reached operators through suppliers
Crew trainingCloses the path that sits beyond every firewallThe Fantastic RAT arrived on a USB drive carried to the bridge

Crew training is the one the U.S. rule sequenced first, with the annual requirement effective January 2026, eighteen months ahead of the plan deadline. Manual fallback is the one the sector already knows: crews that drill paper procedures lose hours where others lose days.

What the numbers record

Measure20242025
Maritime cyber incidents408828
Year-over-year change—+103%
Ransomware cases—372, more than double 2024

Distributed denial of service, ransomware and malware account for most of that volume. The composition matters more than the total: the 2026 reporting describes attacks reaching vessel operational technology rather than stopping at shore-side offices, which moves the risk from lost bookings toward lost control of machinery.

The rules arrive in three waves

RegimeScopeIn force
IMO Resolution MSC.428(98)Cyber risk inside the safety management system, all vesselsJanuary 1, 2021
IACS UR E26 and E27Vessel-wide cyber resilience; hardened onboard systems from manufacturersShips contracted from July 1, 2024
U.S. Coast Guard, 33 CFR 101 Subpart FU.S.-flagged vessels, facilities, OCS facilitiesEffective July 16, 2025

The Coast Guard rule is the most specific of the three. It requires annual personnel training from January 12, 2026. By July 16, 2027 every regulated owner and operator must designate a Cybersecurity Officer, complete a cybersecurity assessment, and submit a cybersecurity plan for approval. It is the first mandatory cybersecurity framework under the Maritime Transportation Security Act.

UR E26 and E27 answer the vessel side by building resilience in from the design contract forward. E26 treats the ship as one integrated system across design, commissioning, operation and maintenance. E27 puts the obligation on equipment manufacturers to deliver hardened systems before installation.

Europe measures it the same way

The European Union Agency for Cybersecurity reaches comparable conclusions from its own data. Ransomware became the leading threat to the transport sector during 2022, rising from 13% of recorded attacks in 2021 to 25%. Across the January 2021 to October 2022 window it accounted for 38% of transport-sector attacks. ENISA also records that state-sponsored actors are attributed to maritime targets more often than to other transport subsectors, which separates the sea from the rest of the industry.

In the agency’s more recent reporting, transport ranks second among EU sectors at 7.5% of recorded incidents, with hacktivist denial-of-service campaigns supplying most of the volume and ransomware supplying most of the downtime and cost. The NIS2 directive brings European ports and operators into a mandatory reporting regime, which over time gives the sector the denominator the GAO says is missing in the United States.

Where the exposure concentrates

The three regimes leave a visible seam. UR E26 and E27 apply to ships contracted from July 2024, so they reach the newbuild order book and leave the existing fleet to the IMO’s safety-management language and to owners’ discretion. The average age of the world merchant fleet runs above a decade, which places the majority of hulls outside the technical standard for years.

Ports sit under national regimes that vary by jurisdiction, and the incident record concentrates there. Terminal operators run the systems that stop cargo, and an operator’s exposure extends to every carrier calling at its berths.

Three structural features set the size of the problem:

  1. Consolidation. A handful of carriers, terminal operators, software vendors and equipment manufacturers serve most of the industry, so a single compromise propagates to a large share of the trade.
  2. Operational technology lifecycles. Engine and automation systems run for the life of the vessel, measured in 25 to 30 years, on software that updates at the pace of dry-dock schedules.
  3. Jurisdictional patchwork. A vessel changes legal regime every few days and answers to the flag state, the port state, the class society and its charterer, each with a different cyber requirement.
  4. Regulator capacity. As of October 2024 the Coast Guard carried 15% vacancy rates in both its cybersecurity specialist positions and its cyber protection teams, which sets a ceiling on how many of the plans arriving by July 2027 can be reviewed and how many facilities can be assessed.

What can move the market?

  • Coast Guard plan submissions and the July 16, 2027 compliance rate
  • the first enforcement actions under 33 CFR 101 Subpart F
  • class society interpretations of UR E26 and E27 at newbuild delivery
  • GNSS interference levels in Hormuz, the Baltic and the Black Sea
  • cyber insurance pricing and war-risk exclusions for maritime hulls
  • any incident that reaches propulsion or steering on a laden vessel
  • terminal operating system vendor consolidation
  • port equipment procurement decisions on supplier origin
  • IMO action on cyber requirements for the existing fleet
  • ransomware group targeting shifts toward logistics and terminals
  • national rules following the U.S. model in other flag and port states
  • crew connectivity policy and onboard network segregation practice

Xin.bz bottom line

Maritime cyber risk stopped being theoretical in June 2017, when a piece of malware aimed at another country took $300 million and ten days out of the world’s largest container line.

The record since then is consistent: attacks land on the systems that decide whether cargo moves, and the cost appears as stationary boxes rather than as stolen data. Nagoya lost two days. DP World Australia lost five terminals and stranded 30,137 containers, more boxes than the largest ship afloat can carry. North Carolina Ports went back to paper in August 2026.

The surface has widened in a specific direction. Satellite connectivity reached vessel operational technology, which put engine control, chart display and ballast systems on the same network as the crew’s email. The 2025 incident count doubled, and its composition shifted toward those systems. Navigation faces a separate and continuous problem, with more than a thousand daily interference events worldwide and the densest concentration in the strait that carries a fifth of seaborne energy.

The rules answer the newbuild and the U.S. regulated entity. They leave the existing fleet, the foreign terminal, and the equipment already installed to commercial judgment, and that gap closes on shipowner timelines rather than regulatory ones.

The industry’s cyber exposure is a function of its efficiency: the same consolidation that moves 80% of world trade on a small number of platforms gives an attacker a small number of targets.

Sources

Government and regulatory

  • U.S. Government Accountability Office. Coast Guard: Additional Efforts Needed to Address Cybersecurity Risks to the Maritime Transportation System, GAO-25-107244. 2025.
  • U.S. Government Accountability Office. Offshore Oil and Gas: Strategy Urgently Needed to Address Cybersecurity Risks to Infrastructure, GAO-23-105789. 2023.
  • U.S. Coast Guard Cyber Command. Cyber Trends and Insights in the Marine Environment (CTIME), annual reports, 2023–2026.
  • U.S. Coast Guard. Cybersecurity in the Marine Transportation System, final rule, 90 FR 6298, January 17, 2025; 33 CFR Part 101 Subpart F.
  • U.S. Maritime Administration. Advisory 2017-005A, Black Sea — GPS Interference. June 2017.
  • U.S. House Committee on Homeland Security and Select Committee on the CCP. Joint investigative report on ship-to-shore cranes. March 2024.
  • The White House, Office of the Press Secretary. Statement attributing NotPetya to the Russian military. February 15, 2018.
  • United Kingdom National Cyber Security Centre. Assessment attributing NotPetya to the Russian military. February 2018.
  • European Union Agency for Cybersecurity. ENISA Transport Threat Landscape (January 2021 – October 2022) and ENISA Threat Landscape, 2024–2025 editions.
  • International Maritime Organization. Resolution MSC.428(98), Maritime Cyber Risk Management in Safety Management Systems, adopted June 16, 2017; MSC-FAL.1/Circ.3, Guidelines on Maritime Cyber Risk Management.
  • International Association of Classification Societies. UR E26 — Cyber Resilience of Ships and UR E27 — Cyber Resilience of On-board Systems and Equipment. In force July 1, 2024.

Academic and research

  • Bhatti, J. and Humphreys, T. E. Hostile Control of Ships via False GPS Signals: Demonstration and Detection. Radionavigation Laboratory, University of Texas at Austin; sea trials aboard the White Rose of Drachs, June–July 2013.
  • Center for Advanced Defense Studies (C4ADS). Above Us Only Stars: Exposing GPS Spoofing in Russia and Syria. 2019.

Company and incident disclosures

  • A.P. Møller-Maersk. NotPetya impact statements and interim results, 2017.
  • DNV. ShipManager cyber incident statements, January–March 2023.
  • Port of Nagoya Unified Terminal System. Incident statements, July 2023.
  • DP World Australia. Cybersecurity incident media statements, November 2023.

Industry and press reporting — cited above as industry figures, on a reporting base the GAO records as incomplete

  • CYTUR Inc. 2026 Maritime Cyber Threat White Paper. February 2026.
  • Cydome. Maritime Cyber Trends: What Shipping Executives Need to Know for 2026. March 2026.
  • Resecurity. Anubis ransomware analysis, Adriatic Port Authority. January 2026.
  • Greenberg, A. The Untold Story of NotPetya, the Most Devastating Cyberattack in History. WIRED. August 22, 2018.