Skip to content
avatar

Maritime and port cybersecurity.

Maritimeinfosec.org is an analysis site dedicated to maritime and port cybersecurity. Its articles offer insights into cyber threats, system vulnerabilities, and the digital challenges of the maritime sector, drawn from an operational reading of risks informed by the author’s experience and background.

FortiBleed and the maritime sector: a real exposure?

A recap of the facts first. FortiBleed was disclosed in mid-June 2026 by independent researcher Volodymyr “Bob” Diachenko, who specialises in hunting down databases and servers left open on the Internet. The leak did not surface at a victim’s site. He found it on the attackers’ side: a poorly secured server exposing their tooling, their logs and the credential set itself. The operation, which he attributes to a Russian-speaking multi-operator group, is said to have harvested and then cracked the authentication hashes of tens of thousands of FortiGate appliances, enriching each entry with the target’s industry, revenue and headcount - enough to plan future attacks. Several researchers validated part of the batch, among them the British Kevin Beaumont, who confirmed the authenticity of a sample of administration credentials.

Maritime cybersecurity 2025 in numbers

Some still picture the maritime cyber threat as exclusively a matter of hijacked ships and tampered AIS transponders. By consolidating the incidents of 2025 in my own research dataset on maritime cyber incidents - one I built during my doctoral work and keep maintaining with my own means - I get a rather different, and sometimes more instructive, picture, because it rests on facts. I call this cyber incidentology, not to sound pompous, but because it is rich in lessons for prevention, protection and response.

NORMA Cyber 2026 Report: a maritime threat that is primarily geopolitical, more hybrid than spectacular

This article is also available in French.

The latest NORMA Cyber annual report has the merit of placing maritime cybersecurity back where it now truly operates: in a space saturated with geopolitical tensions, logistical interdependencies, and blurred boundaries between cyber, physical, and informational domains. Its main outlook for 2026 (for those who still believe in cyber crystal balls) is that the structuring risk is not so much the “big” destructive attack as the accumulation of intelligence operations, opportunistic disruptions, and hybrid effects on already strained logistical and operational chains. In that sense, it is a less alarmist report than it may appear at first glance, and that is probably its main strength.