Skip to content

Contents

Constanța: when NoName goes after a whole port ecosystem

Cet article est aussi disponible en français.

Normally, when the pro-Russian hacktivist outfit NoName057(16) goes after the maritime and port sector, it picks a handful of sites: a ferry company here, a port authority there. This time, over the past ten days or so, the whole ecosystem and hinterland of the port of Constanța have been worked through.

/images/constanta/constanta-map.png

A methodical saturation

Forty maritime entities claimed between 29 July and 7 August, all around the same basin. Not only the port authority: the bulk and container terminals, the shipping agencies that handle the vessels, the Danube river ports upstream, the Black Sea offshore oil companies, the Romanian naval authority, right down to the port’s employers’ association.

/images/constanta/constanta-maillons.svg

Put end to end, these targets trace a full logistics chain, from the quay to the shipper. It is the largest hacktivist wave by NoName057(16) against the maritime and port sector.

A word of caution, on several counts, so as not to oversell the affair. First, the group strikes far wider elsewhere, in finance, government or telecoms, and Romania regularly takes thousands of targets in a single week. Second, NoName057(16) is as much an influence operation as a technical attack: the claim, the tally and the staging are above all after an echo chamber, and writing about it already hands them a little of that resonance. Third, this kind of wave has a modest operational record: in the past it has rarely left lasting marks on seriously prepared organisations. What makes this wave notable is the ambition of the targeting: treating an entire regional ecosystem as a single attack surface.

Ten days, from the port to the hinterland

The wave advanced in tiers, with even a short pause over the weekend of 1-2 August.

/images/constanta/constanta-frise.svg

/images/constanta/constanta-par-jour.svg

First the core of Constanța, its terminals and agencies, from 29 to 31 July. Then the hinterland: the Danube ports towards Galați and Brăila, the oil companies’ headquarters, from 3 to 5 August. Finally a tail end, three stragglers on 6 and 7 August. So you move up the logistics chain, from the quay towards the hinterland. Is this a deliberate progression, or simply the order in which the targets were added to the tool’s configuration? Hard to tell from the outside.

Cyber and geopolitics, again…

That leaves the question of motive. Constanța is not a port like any other. Since the Black Sea came under strain, it has become one of the main outlets for Ukrainian grain to the rest of the world. The Romanian press, for its part, sums up the mood in two words: hybrid war [1].

Denial of service is only one instrument among others there. Over the same weeks, the port faced hoax bomb threats [2], delivered as audio messages in Romanian that the authorities believe were generated by artificial intelligence and sent from numbers with Polish and Ukrainian prefixes, targeting in particular the Romanian naval authority, itself on the group’s target list. Back in June, a marine drone had already been spotted in one of the port’s basins [3]. Should we read this as a coordinated manoeuvre? Nothing allows us to assert it: these incidents come from distinct actors and distinct modes of operation. What they mainly outline is a climate, that of a diffuse pressure on grain logistics, of which digital harassment is only one component.

What about the impact?

It is tempting, reading “thirty ports attacked”, to picture shoreside sites and cranes at a standstill. But a port appearing among NoName057(16)’s targets does not mean its site actually went down: a listed target signals an attempted attack; whether it cut anything off is another matter.

Romania’s cyber authority, the DNSC, is consistent on this point. During an earlier wave, on 4 May 2025, it publicly noted [4] that “all the listed Romanian sites” remained operational. It also points out that these claims are often inflated: a service announced as “down” had in reality suffered only a few minutes’ disruption. Romania is no stranger to such salvoes, its government sites having weathered pro-Russian waves since 2022.

The damage plays out somewhere other than in the outage: in the harassment, in the resources burned responding, and in the sense of insecurity all this keeps alive.

What the configuration reveals

One last detail, for those who like to look under the bonnet. The attackers do not merely hammer the home pages. Their configuration aims at specific spots, chosen because they are expensive for the server: contact forms, login pages, internal search engines. So many requests that force work on the server side, a database query, sending an email, opening a session, to maximise the effect at minimal cost. Most of the victims are small WordPress sites, poorly equipped to absorb it, and often clustered with the same shared hosting providers. Those providers therefore share part of the responsibility: it is at their level, through filtering and upstream mitigation, that a wave like this is best contained, where an isolated small site can do almost nothing. Technically, nothing sophisticated: DDoSia is a turnkey tool that any “sympathiser” runs from their own computer. The attackers’ real effort went into selecting the targets: which victims to hit, and which precise points to strike on each.

Defending at the scale of the basin

We are used to thinking about cybersecurity site by site, company by company. When an adversary treats a whole port basin as a single target, the question changes in nature: your quayside neighbour’s exposure becomes a little bit yours. Defending then means reasoning at the scale of the basin, together, and no longer each behind their own firewall.

Sources

  • [1] Aktual24, “Din nou alertă cu bombă în Portul Constanța. Se intensifică războiul hibrid dus de Rusia” (in Romanian)
  • [2] Romania Insider, “Bomb alert at Romania’s Black Sea Port of Constanța” (July 2026)
  • [3] Maritime Security Forum, review of the drone incident at the port of Constanța on 5 June 2026
  • [4] DNSC (Romania’s cyber authority), the listed Romanian sites remained operational (4 May 2025, via financialintelligence.ro)
Olivier JACQ

Olivier JACQ, President and founder of CYBERMOOV Consulting.