Maritime cybersecurity 2023 in numbers
481 incidents recorded in 2023, against 117 the year before. The total is multiplied by four in twelve months, and a single group accounts for most of the gap. In October, meanwhile, a bulk carrier dragged its anchor for two hundred kilometres along the floor of the Gulf of Finland.
This article is also available in French.
These figures come from my research dataset on maritime cyber incidents, built during my doctorate and kept up with my own means alone. Three biases to keep in mind: I only count what came out publicly, and most often through the attacker’s voice; a year’s tally keeps growing for months after it closes; and a fourfold rise partly measures my ability to follow an actor who publishes its own targets, which is not the same thing as a fourfold rise in danger.
One group, two thirds of the year
Denial of service goes from 8 records to 353. Hacktivism, which accounted for 5 incidents in 2022, accounts for 356. And a single pro-Russian ecosystem, NoName057(16), claims 318 of them on its own, two thirds of my whole year.

This group works differently from the 2022 collectives: it publishes its targets, hands a tool to its volunteers and runs wave after wave, country by country. The result reads off the monthly curve. June alone concentrates 95 records, 77 of them for this one group, spread across Sweden, Italy, Lithuania, the Netherlands and Canada.

Its favourite target is the port: 196 port records in the year, ahead of shipowners (67), defence (39) and maritime administrations (36). The geography is that of a European political calendar, with Italy (46), Canada (37), Sweden (35), Finland (32), Germany and the Netherlands (31 each). Europe gathers 346 of the 481 records.
On the real effect, I stay cautious. A booking portal down for two hours does not disrupt a port call, and I recorded no case where these attacks reached operations. The cost is elsewhere: in the time teams spend handling alerts that lead nowhere, and in the difficulty of explaining to a board that no, nothing happened.
Meanwhile, ransomware keeps going
Under that blanket, ransomware rises from 73 to 95 records, up 30%, in line with previous years. LockBit (16), Cl0p (14) and ALPHV/BlackCat (11) lead the field.
The case of the year is Australian. On 10 November, DP World Australia, which handles about 40% of the country’s containerised freight across four terminals, detected an intrusion attributed to a LockBit affiliate. The entry point was a vulnerability then being massively exploited in a remote-access appliance [1]. The company disconnected its systems from the internet, which suspended operations at all four terminals for a whole weekend; Australian press reporting mentioned some 30,000 containers held up before work resumed on 13 November. The same vulnerability served dozens of other intrusions worldwide over the same period [2].
It is, as far as I know, the first time ransomware stopped four container terminals of one country at once. And the vector has nothing maritime about it: an unpatched remote-access appliance, of the kind found in every sector.
An anchor on the floor of the Gulf of Finland
In the early hours of 8 October, the Balticconnector subsea gas pipeline, which links Finland to Estonia over 77 kilometres, lost pressure abruptly. Operators isolated the section and cut gas transit between the two countries. Two telecommunications cables were damaged along the same route [3].
The Finnish investigation turned towards a Hong Kong-flagged container ship, the NewNew Polar Bear, which had dragged its anchor for about two hundred kilometres. Chinese authorities acknowledged that the vessel caused the damage, presenting it as accidental [4]. No state has formally attributed the incident, and I leave it there.
The ratio between means and effect deserves a pause. A merchant ship manoeuvre, with no computing involved, put an energy link between two states out of service. My dataset counts 4 attacks on subsea infrastructure this year; that is few, and it is the kind of series to watch closely if it continues.
Two novelties that will last
2023 will have established two things. An industrialised hacktivist mode of action, very noisy, with almost no operational effect, which now makes any volume statistic hard to read. And the demonstration that subsea infrastructure can be cut with a piece of deck equipment.
Between the two, ransomware carries on quietly, and it is still the one that stops terminals. For 2024 I will mainly watch two things: whether the hacktivist waves hold at this level once the novelty wears off, and whether cable and pipeline incidents repeat in the Baltic. The rest, meaning the securing of what is exposed on the internet, is work that the evolution of maritime information systems made predictable years ago.
Sources
- [1] The Maritime Executive, widely exploited vulnerability the likely cause of DP World Australia’s attack (November 2023)
- [2] BleepingComputer, LockBit ransomware exploits Citrix Bleed in attacks (November 2023)
- [3] Al Jazeera, Finland on the cause of the pipeline damage (October 2023)
- [4] The Maritime Executive, China acknowledges that boxship caused Balticconnector pipeline breach (2024)