Maritime cybersecurity 2024 in numbers
596 maritime cyber incidents recorded in 2024, against 117 two years earlier. Almost all of that growth comes from a single mode of action, noisy and industrialised, which hardly ever touches operations. Behind that curtain, ransomware kept advancing among the sector’s suppliers, and two submarine cables were severed in the Baltic by merchant ships.
This article is also available in French.
These figures come from my research dataset on maritime cyber incidents, built during my doctorate and kept up since with my own means alone. It records only what came out publicly, and most often through the attacker’s voice. Read it as an indicator of pressure; nobody holds the full inventory.
The volume has changed order of magnitude
The rise is continuous: 92 records in 2021, 117 in 2022, 478 in 2023, 596 in 2024. The counter has been multiplied by five in two years. And 2025 is not slowing down: by the end of August I am at 741 for the current year, against 399 at the same date in 2024.

This change of scale measures the settling in of a heavily industrialised mode of action, one that produces volume at almost no cost.
One group alone accounts for half the year
Of the 596 records, 410 fall under distributed denial of service (DDoS), close to seven in ten, almost all hacktivist in origin. The pro-Russian ecosystem NoName057(16) carries 361 of them on its own: 61% of everything I recorded in the year, and close to nine DDoS out of ten.
Its target of choice remains the port, with 178 records, ahead of maritime administrations and defence players. Its geography follows political news rather than maritime activity: Spain comes far ahead with 81 records, then Sweden (29), then the United Kingdom, Germany and Italy (28 each). The July peak, 72 incidents in the month, looks like every wave of its kind: a few days of attacks concentrated on one country, after a statement or a summit.

The operational effect, though, stays small. A DDoS makes a website or a portal unreachable for a few hours and reaches neither the terminal nor the ship. Its real cost is the attention it takes up: watching these alerts go by, you end up no longer looking at the rest.
Ransomware settles in among suppliers
124 records in 2024, one incident in five, against 95 the previous year. Half of them are concentrated in the United States, with 51 records. And the split by trade says more than the total: 35 among manufacturers and equipment suppliers, 20 among shipowners, 14 among logisticians, 14 in ports, 12 offshore. These groups have no particular appetite for the maritime sector: they take what is vulnerable and reachable, and part of the sector happens to be in their path. What falls sits on the periphery of the ship, with those who build it, equip it and supply it.

No group dominates this category: Play and RansomHub at 16 records, LockBit at 11, then a long tail of affiliates. The ecosystem runs on subcontracting: the disappearance of a brand does not reduce the number of attacks.
The example of the year is the Port of Seattle, encrypted in late August 2024 by the Rhysida ransomware. The port authority, which also runs Seattle-Tacoma International Airport, disconnected its systems from the internet; check-in, baggage handling, kiosks, display boards and parking reservation went down, and staff went back to dry-erase boards. It refused to pay the ransom of roughly six million dollars, explaining publicly that it was handling public money [1]. The stolen data was eventually published, and the port notified nearly 90,000 people, mostly staff and contractors [2]. We find here what we had already seen at Norwegian cruise operator Hurtigruten: operations carry on after a fashion, the back office gives way.
The Baltic cables enter the picture
Four records from 2024 concern damage to subsea infrastructure. None of them is a computer attack. I keep them in the same dataset all the same, because these are the very links that carry the sector’s communications, and because the suspected authors are the same ones found behind the rest.
On 17 and 18 November 2024, the bulk carrier Yi Peng 3, Chinese-flagged and under a Russian master, left the Russian port of Ust-Luga and severed two links one after the other: the BCS East-West Interlink between Lithuania and Gotland, then C-Lion 1, the only direct submarine cable between Finland and Western Europe, some 700 kilometres (380 NM) from Helsinki [3]. The vessel had dragged its anchor. It then lay at anchor for several weeks in the Kattegat under international surveillance, received a delegation of investigators from five countries on board, and put back to sea without being seized or charged [4]. On 25 December, the tanker Eagle S damaged the Estlink 2 power link in the Gulf of Finland in its turn.
On attribution, caution remains in order. Several European officials spoke of sabotage, and the American press reported, from anonymous intelligence sources, that the master had acted on Russian instructions [5]; other assessments, American as well, did not conclude the cuts were deliberate. To this day, no state has formally attributed them. The demonstration, though, is established: an anchor and a bulk carrier are enough to cut a strategic link, at no cost and with next to no legal risk either. This is the kind of subject that critical infrastructure resilience legislation will have to take head-on.
And what about GNSS?
Four records only in 2024, which says nothing about the real scale of the phenomenon. Jamming has become so routine in the Persian Gulf, the eastern Mediterranean and the Black Sea that it is no longer reported case by case. Assume instead that, in those areas, the position and time given by satellite networks are not reliable. And beware of stories that are too neat: I have already explained why one should wait for the investigation reports before concluding spoofing in the face of a collision.
The noise, the supplier and the cable
Three movements stand out from the year, and none of them is settled with the same tools.
Hacktivist noise occupies the ground, seven incidents in ten, and a single group produces most of it. It is handled with anti-DDoS protection, a communication procedure, and the composure not to convene a crisis cell at every claim.
Ransomware, for its part, has moved towards suppliers. The scenario to prepare for is no longer only “my system is encrypted”, it is “my shipping agent has been unreachable for ten days and my port calls are piling up”. That is handled through contractual requirements, an inventory of dependencies, and tested backups. The vulnerabilities exploited are nothing exotic: exposed remote access, missing multi-factor authentication, late patching, end-of-life hardware. The United States Coast Guard and CISA say nothing else when they go fishing for vulnerabilities in ports.
The cable, finally, is a matter of link redundancy and of the ability to hold when links go down. For a shipowner or a port, the question fits in one sentence: what happens if the main link disappears for ten days, and who has tested it?
Sources
- [1] Cybersecurity Dive, Port of Seattle refuses to pay the Rhysida ransom (September 2024)
- [2] Port of Seattle, notice to individuals affected by the fall 2024 cyberattack
- [3] Cinia, a fault in the C-Lion1 submarine cable between Finland and Germany (November 2024)
- [4] CNN, accident or sabotage: American and European officials disagree over the cut undersea cables (November 2024)
- [5] gCaptain, Russia now primary suspect in the Yi Peng 3 Baltic Sea cable incident (December 2024)