Maritime cybersecurity 2020 in numbers
Of the 50 maritime cyber incidents I recorded in 2020, 33 are ransomware. None is a ship taken over remotely. And within a single week of September, a top-tier container carrier and then the United Nations agency that regulates shipping were hit two days apart.
This article is also available in French.
These figures come from my research dataset on maritime cyber incidents, built during my doctorate and kept up with my own means alone. Three biases to keep in mind before reading them. I only count what came out publicly, most often through the attacker’s voice. A year’s tally keeps growing for months after it closes, as I go back over it. And with numbers this small, one more incident moves a percentage point: so I will mostly give counts.
Ransomware takes two thirds of the year
50 records in 2020, against 23 in 2019. The doubling is real, but it partly reflects my own ramping up: I document 2020 better than 2019. What is clear-cut is the composition. Ransomware goes from 7 to 33 records, and criminal origin covers 37 of the 50 incidents. Nothing hacktivist, nothing claimed politically.

The names that recur belong to the double-extortion generation, which encrypts and publishes: Maze, Egregor, DoppelPaymer, REvil, Nefilim, NetWalker. None of them has any particular interest in the maritime sector. They take what is vulnerable and reachable, and the sector happens to be in their path like any other.

The February and March trough, one record each, deserves a comment. The sector had other things to deal with then, and incident reporting stopped dead. The curve also measures the attention paid to incidents.
What falls is the chain, not the ship
The split by trade is the year’s main lesson: 10 records among shipowners, 10 among logisticians, 8 in ports, 6 on board, 5 among manufacturers, 3 in shipyards. Geographically the United States comes first with 11 records, ahead of Norway (6) and France (5).
Australia’s Toll Group sums up the mechanism: two different ransomware attacks in four months, in January and then in May, at a carrier that weighs on the whole Pacific logistics chain. The same pattern shows up at cruise operator Hurtigruten, at Carnival and as far as an inland port in the western United States: ships keep sailing, but booking, invoicing, customs paperwork and payroll stop.
One week in September
On 28 September, CMA CGM announced an attack by the Ragnar Locker ransomware. The group’s external applications and websites went down, booking fell back on stand-by channels, and the carrier then acknowledged a possible leak of customer data [1]. Two days later, on 30 September, the International Maritime Organization lost its public website and its intranet. The agency spoke of a sophisticated attack that had overcome its protections, even though it holds ISO/IEC 27001 certification, and shut systems down to limit the spread [2].
The closeness of the two dates circulated widely, and nothing allows them to be linked. The overall demonstration matters more: in the same week, the carrier and the regulator ended up in the same situation, with the same makeshift workarounds.
Beware the figures going around
2020 was also the year of the spectacular percentage. I relayed here myself a 900% increase in attacks on operational systems and a 400% rise in attempts during the health crisis. Those figures come from security vendors, cover attempts rather than incidents, and rest on no verifiable count. Fifty documented incidents sells less well than a tenfold increase, and it is far more useful when deciding where to put your money.
A sector discovering it can be reached
The risk materialised at shipowners and logisticians rather than on board. The attackers are opportunists living off extortion, with no maritime agenda. And the sector’s regulator turned out to be as exposed as those it regulates.
The scenario to work on for 2021 is therefore not the hijacked ship. It is far more mundane: commercial administration at a standstill for ten days, backups nobody has ever restored for real, and a service provider holding your data without your knowing how it protects them.