Maritime cybersecurity 2021 in numbers
92 incidents recorded in 2021, against 50 the year before. Ransomware still supplies most of the volume, but two things change: Asia becomes the most affected region in my records, and part of the attacks no longer seek to be noticed at all.
This article is also available in French.
These figures come from my research dataset on maritime cyber incidents, built during my doctorate and kept up with my own means alone. Three biases before reading them: I only count what came out publicly, often through the attacker’s voice; a year’s tally keeps growing for months after it closes; and at this order of magnitude percentages are fragile. I give them where the base allows, with the counts alongside.
Ransomware settles in, and so does the silent intrusion
Ransomware goes from 33 to 56 records, up 70%, and accounts on its own for six incidents in ten. But the most interesting rise is elsewhere: intrusions go from 7 to 16, and the espionage and state-sponsored categories, absent in 2020, total 15 records.

By trade, logisticians move ahead of everyone with 20 records, before shipowners (16), ports (13) and offshore (8). The Cl0p campaign against the Accellion file-transfer appliance illustrates the period well: it hit victims with nothing in common, including the classification society American Bureau of Shipping in February, simply because they ran the same end-of-life product.

Asia moves ahead of Europe
That is the year’s oddity, and I did not expect it: 33 records concern Asian victims, against 31 European and 17 American. Japan (7), South Korea (5) and Singapore (5) carry most of it, with shipyards, shipowners and ports.
Two factors combine. First a real maritime density, that of the large East Asian ports and yards. Then espionage campaigns documented that year against South-East Asian navies, notably Philippine and Indonesian, which a Europe-centred record would not have counted. I take it that my coverage widened at the same time as the threat: both effects are mixed here.
Two cases, two threat models
On 22 July, Transnet, South Africa’s state-owned ports and rail freight operator, was hit by ransomware. The company declared force majeure at its container terminals. Durban, which handles more than half of South African seaborne trade, went manual for several days [1]. Everyone saw it, including the ships waiting at anchor.
In August, Port Houston, the largest US port by foreign tonnage, suffered an intrusion of an entirely different nature. The attackers exploited a then-unknown flaw in a password-management product, dropped a web shell on an authentication server and exfiltrated an account database [2]. The US cybersecurity agency issued an advisory on the vulnerability [3] and the port authority stated that no operation had been disrupted. Nobody saw anything go by, which was the point.
These two cases call for opposite answers. Against the first, backups and a continuity plan. Against the second, detection, logs kept long enough, and someone to read them.
Warships that were not there
On the night of 18 to 19 June, public traffic-tracking sites showed the British destroyer HMS Defender and the Dutch frigate HNLMS Evertsen leaving Odesa and entering the harbour of Sevastopol, in Crimea. Both ships were alongside in Odesa [4]. In late July, a systematic analysis of AIS data identified falsified tracks for at least eleven NATO vessels, across several areas of tension [5].
AIS was never designed to be authenticated, and that weakness has been known for a long time. The use, though, is new: manufacturing a diplomatic incident by injecting a position, without touching the ship. I record only 4 jamming or spoofing incidents this year, which reflects the difficulty of documenting such cases rather than their rarity.
Two risks, and one data point you can no longer trust
The 2021 landscape fits in three lines. Ransomware remains the leading risk by volume and now hits logistics above all. Espionage settles quietly among those who matter, ports and navies, without seeking effect. And position data can be manipulated, which should give pause before basing a decision on a single source.
For the year ahead the priority stays dull and effective: reduce what is exposed on the internet, patch remote-access and authentication software fast, keep usable logs, and test your backups for real. Default passwords in maritime systems remain, for their part, a matter still not settled.
Sources
- [1] Moneyweb, Death Kitty ransomware linked to attack on South African ports (July 2021)
- [2] The Record, state-sponsored hacking group targets Port of Houston using Zoho zero-day (September 2021)
- [3] CISA, advisory AA21-259A on exploitation of the Zoho ManageEngine vulnerability (September 2021)
- [4] USNI News, positions of two NATO ships were falsified near Russian Black Sea naval base (June 2021)
- [5] SkyTruth, systematic data analysis reveals false vessel tracks (July 2021)