Maritime cybersecurity 2022 in numbers
117 incidents recorded in 2022, against 92 the year before. The rise, 27%, is the smallest of the past three years. The nature of what I record does change: until 2021 my dataset held almost nothing but extortion crime, and 2022 brings politics into it.
This article is also available in French.
These figures come from my research dataset on maritime cyber incidents, built during my doctorate and kept up with my own means alone. Three biases to bear in mind: I only count what came out publicly, often through the attacker’s voice; the tally for a closed year keeps growing as I go back over it; and out of 117 records, a percentage computed on a small category means very little.
The war enters the picture
Ransomware stays well ahead, 73 records against 56 last year, with LockBit (12) and Conti (9) in the front line. But two categories that did not exist in my records appear at once: 12 incidents of political origin, 5 claimed by hacktivists, and above all 8 denial-of-service attacks, against none the year before.

February, with 15 records, is the busiest month of the first half. The June peak, 16, matches the first wave of denial-of-service attacks claimed by a pro-Russian collective against European ports.

Denial of service reaches the maritime sector
The pro-Russian collective Killnet opens the series. In June it targets web applications of Italian ports, then Lithuania’s national shipping company. In September it goes after Japanese sites, including that of the Nagoya port authority, unreachable for some forty minutes, and presents the operation as a declaration of war on the Japanese government [1]. In October, a Bulgarian port administration.
Technically, not much happens: a public-facing website down for an hour, no port operation affected. Politically the message lands, and the mode of action turns out to be nearly free for the attacker. Eight records in a year is few. What I mainly note is that they started from zero, and that the mechanism looks repeatable at will.
The same shift shows on the Israeli side, with data leaks claimed against the ports of Ashdod and Haifa in February, then a phishing campaign against Israeli shipping companies in August, this time attributed to an Iran-linked actor.
A supplier at a standstill, and charts that no longer update
On 2 December, the Singapore-based vendor Voyager Worldwide took all its systems offline after a compromise. Its fleet-management and charting products serve a large share of the world’s shipowners; online access became unavailable for several days, and service was only restored around 10 December [2]. The vendor called in an incident-response firm and detailed neither the nature of the attack nor its author [3].
No ship was put in danger. But a shipowner depending on a single service to keep its charts up to date found out, that month, what its plan B was worth. It is the year’s first case where a supplier outage reaches the conduct of the ship itself.
Another quiet and instructive case: in April, US investigators interrupted an intrusion into the servers of a company managing a submarine cable linking Hawaii to the wider Pacific, before any damage was done [4]. Subsea infrastructure is starting to draw attention.
Where the blows land
Ports come first with 22 records, followed by logisticians and manufacturers (18 each) and shipowners (16). Geographically the United States stays first with 20 records, ahead of Germany (9), the United Kingdom (8), France (7) and Israel (6). Europe moves back ahead of Asia, 50 against 39, after the 2021 reversal.
A blurring line
2022 will remain the year the maritime cyber threat stopped being solely about money. The volume stays criminal, by far. But part of the attacks now answer a diplomatic calendar, and aim at image rather than at the till.
For a port or a shipowner, that adds a line to the crisis plan without removing any: you now need to know what to say when a collective claims an attack that produced no effect, and to do it without giving the operation the publicity it seeks. That is an exercise in communication as much as in security, and exactly the kind of subject where a sector centre such as France Cyber Maritime proves useful.
Sources
- [1] Asia News Network, pro-Russia hackers claim to have temporarily brought down Japanese government websites (September 2022)
- [2] Splash 247, Voyager Worldwide hit by cyber attack (December 2022)
- [3] Riviera Maritime Media, Voyager Fleet Insight unavailable after cyber security incident (December 2022)
- [4] Hawaii News Now, HSI agents in Honolulu disrupted a cyberattack on an undersea cable (April 2022)