Skip to content
avatar

Maritime and port cybersecurity.

Threats, vulnerabilities, incidents and regulation across the maritime and port sector, from an operational angle informed by the author’s background.

The Russian ship, the cable and... the mineral deposit

This article is also available in French.

Today, for a change from cyber (although we will be talking about AI, data and bias), I suggest you grab a bag of popcorn and settle in comfortably. We are going to talk about a film. More precisely, about two scenarios. Tempted? Off we go.

Two scenarios for a good film, then, with espionage and high-seas operations in the background but, in the end, a single story (and it ends well).

First scenario. A Russian ship, managed by a company under US sanctions, moving slowly in the middle of the Atlantic Ocean, about 1,600 kilometres (860 NM) east of Barbados, and staying there for 41 days. No port call, apparently no other ship encountered, its AIS transponder on the whole time, and, according to some submarine cable maps, a piece of “critical” underwater infrastructure nearby. Calling it a spy ship is only one step further, a step easily taken if you do not stand back.

Second scenario. The same ship, on the same dates and in the same position, running a prospecting campaign across a metallic sulphide deposit, with the fairly irregular kinematics typical of that kind of operation, inside mining blocks allocated to Russia by the International Seabed Authority, 305 kilometres (165 NM) from the nearest cable.

Maritime cybersecurity 2025 in numbers

Some still picture the maritime cyber threat as exclusively a matter of hijacked ships and tampered AIS transponders. By consolidating the incidents of 2025 in my own research dataset on maritime cyber incidents - one I built during my doctoral work and keep maintaining with my own means - I get a rather different, and sometimes more instructive, picture, because it rests on facts. I call this cyber incidentology, not to sound pompous, but because it is rich in lessons for prevention, protection and response.

The necessary inventory

This article is also available in French.

Cellular modems were fitted to ship-to-shore cranes bound for US ports while those cranes were being built in China. Port technicians saw them, assumed they were there for remote maintenance, and moved on. Yet the modems appeared in no contract: the remote diagnostics option they corresponded to had been declined at purchase. A joint report by two committees of the US House of Representatives documented the case in September 2024 [1]. Connected to Linux computers inside the cranes, the modems “created an obscure method to collect information, and bypass firewalls in a manner that could potentially disrupt port operations”, the committees wrote. At another port, a modem turned up in the server room hosting the cranes’ firewall and networking equipment, and port officials could not say why it was there [2].

Constanța: when NoName goes after a whole port ecosystem

Cet article est aussi disponible en français.

Normally, when the pro-Russian hacktivist outfit NoName057(16) goes after the maritime and port sector, it picks a handful of sites: a ferry company here, a port authority there. This time, over the past ten days or so, the whole ecosystem and hinterland of the port of Constanța have been worked through.

FortiBleed and the maritime sector: a real exposure?

A recap of the facts first. FortiBleed was disclosed in mid-June 2026 by independent researcher Volodymyr “Bob” Diachenko, who specialises in hunting down databases and servers left open on the Internet. Tellingly, the leak comes from the attackers themselves: Diachenko spotted one of their poorly secured servers, exposing their tooling, their logs and the credential set itself. The operation, which he attributes to a Russian-speaking multi-operator group, is said to have harvested and then cracked the authentication hashes of tens of thousands of FortiGate appliances, enriching each entry with the target’s industry, revenue and headcount - enough to plan future attacks. Several researchers validated part of the batch, among them the British Kevin Beaumont, who confirmed the authenticity of a sample of administration credentials.