Skip to content

Contents

Maritime cybersecurity 2025 in numbers

Some still picture the maritime cyber threat as exclusively a matter of hijacked ships and tampered AIS transponders. By consolidating the incidents of 2025 in my own research dataset on maritime cyber incidents - one I built during my doctoral work and keep maintaining with my own means - I get a rather different, and sometimes more instructive, picture, because it rests on facts. I call this cyber incidentology, not to sound pompous, but because it is rich in lessons for prevention, protection and response.

This article is also available in French.

Figures and charts as of 7 September 2026.

Two brief reminders before we start:

  • these figures describe what was observed and publicly documented, not everything that happened. As you might guess, a good share of incidents never come to light. And the term “incident”, as you know, is a debated one. This overview is therefore an indicator of pressure, not an exhaustive census. That said, over one year and close to 1,300 recorded events, some broad trends emerge.
  • we should also keep in mind the difficulty of doing open-source Cyber Threat Intelligence: that is, very often, relying on attacks claimed by the attacker rather than those confirmed by the targeted entities.

A persistent threat that keeps growing

After a decade of continuous growth, the volume of recorded maritime incidents still shows no levelling off: 529 in 2023, 716 in 2024, then 1,295 in 2025. And the movement carries on: as of 7 September 2026 I already have 1,028 incidents on the books for the current year, against 862 at the same date in 2025.

Year on year the rise reaches 81%, and it is very uneven depending on the threat: denial of service gains 70%, from 531 to 902 records, ransomware 120%, from 123 to 270, and data theft 258%, from 19 to 68. Part of that growth measures my own work of going back over past years, and I cannot cleanly separate it out. Proportions hold up better against that bias, and they are what I lean on below.

/maritime-cybersecurity-2025-in-numbers/incidents-par-an.png

In 2025, this pressure was spread fairly evenly from one month to the next, with no marked respite. And it has a heavily dominant face: close to seven incidents in ten, 902 out of 1,295, are distributed denial-of-service (DDoS) attacks, almost always hacktivist in origin. A single pro-Russian ecosystem, NoName057(16), accounts on its own for 705 of my annual records, more than one incident in two and close to eight DDoS in ten. Its favourite target is ports, with 229 records, well ahead of public administrations and defence players. The geography mirrors that of the war: Italy comes clearly first among the countries hit, then Finland, France and Poland, ahead of Germany and Belgium, depending on stances taken on Ukraine or on NATO and G7 meetings. Over one year the group grows by 46%, from 482 to 705 records, and its map inverts: Italy goes from 31 to 85 records, Finland from 15 to 62, Lithuania from 10 to 39, while Spain, its main target in 2024, falls back from 82 to 46.

/maritime-cybersecurity-2025-in-numbers/incidents-2025-par-mois.png

Should we be alarmed? Yes and no. A DDoS saturates a website or a portal, causes disruption, gets people talking, but stays reversible and almost never reaches the operating systems of the ship or the terminal. It’s mostly about making noise and being seen. The risk, here, is mainly to end up treating these alerts as scenery, and to lower our guard on the rest.

Beneath the noise, ransomware advances

Beneath the hacktivist carpet-bombing, the ransomware threat keeps wreaking havoc among maritime SMEs. It accounts for a little over a fifth of the incidents I recorded in 2025, 270 records against 123 in 2024, having hovered around a sixth of the total the previous year. The balance is therefore shifting slowly: the DDoS share falls year on year, from 76% of the total in 2023 to 70% in 2025, while ransomware climbs. Its progression is more worrying than the DDoS peak, which is mostly a matter of volume.

/maritime-cybersecurity-2025-in-numbers/menaces-par-annee.png

The groups that come up most often in my records (Qilin, Cl0p, Akira, Play) are not looking for the maritime sector: they take what is vulnerable and reachable, and maritime companies fall in with the rest. What does fall sits mostly on the periphery of ships, first of all with manufacturers and equipment suppliers, which on their own account for 78 of my 2025 ransomware records, ahead of logisticians, shipowners, ports and offshore operators. The year-on-year rise is very uneven from one trade to the next: among logisticians, ransomware goes from 14 to 58 records, among manufacturers from 34 to 78, among shipowners from 20 to 38, while ports only move from 14 to 23. The United States still concentrates most of it, from 50 to 108 victims. At basin level and across all incidents, the count doubles in the Baltic, from 161 to 355, and rises 185% in the Americas, from 80 to 228. To my mind, that is the year’s most important signal. When you go after a supplier, you strike its entire customer base by ricochet.

The most telling example of 2025 is the compromise, by the Rhysida ransomware, of a major Japanese supplier of navigation electronics (RADAR, ECDIS, Voyage Data Recorders, GNSS receivers, autopilots) [1]. Beyond the data theft, the attack disrupted service, software updates and the shipping of parts. Yet this manufacturer’s equipment is installed on thousands of vessels worldwide: this is the “one-to-N” risk in its purest form, where the failure of a single supplier propagates to an entire fleet.

One compromised supplier: 116 ships cut off

If proof were needed that the maritime sector can be hit far harder than with a mere DDoS, 2025 supplied it, on the political side this time. In March, an anti-Iranian hacktivist collective claimed the cutting of the SATCOM (VSAT) communications of 116 ships belonging to two sanctioned Iranian state shipowners, namely 50 tankers and 66 cargo ships [2].

The technical detail says a great deal about the sector’s real fragility. The attackers did not target the ships one by one: they first compromised the two companies’ Iranian satellite-connectivity provider, then pivoted from that operator’s internal network to the onboard VSAT terminals. Analysis of the published screenshots shows exposed iDirect modems, with an accessible administration service and default credentials never changed, running versions of OpenSSH and OpenSSL that had been end-of-life for years. Once inside, the attackers wiped the modems’ storage partitions, a wiper technique directly comparable to the attack against Viasat / KA-Sat attributed to Russian military intelligence in 2022 [3]. Restoration was estimated at several weeks.

This is a far cry from the symbolic DDoS: prior reconnaissance of the fleet, exploitation of a supply chain, a destructive payload synchronised across 116 ships. This kind of high-leverage operation calls for close watching, and a mere incident count misses it.

And what about GPS jamming and spoofing?

The usual areas are still hit, daily, by disruptions. The US/Iran conflict and the situation in the Near East have only sharply reinforced the GNSS jamming and spoofing zones, in the Persian Gulf and the eastern Mediterranean. These incidents are so frequent that trying to count them now offers only limited interest, or a wish to frighten with figures. Assume that, in these areas, trust in position, navigation and timing networks can only be limited, with all the consequences that may have on board (and ashore). The rest is just literature.

Let us also recall that GPS-related incident reports are also often laden with approximations. I have shown, regarding the famous collision off Oman regularly presented as a case of GPS spoofing, how a convenient hypothesis ends up circulating as an established fact. Caution, then, with stories that are wrapped up too neatly.

A lot of noise, and a risk that is moving

If I had to sum up the year in two developments:

  • Hacktivist DDoS has become the dominant volume (close to seven incidents in ten), noisy but reversible: it must not monopolise attention. Its background noise diverts us from the priorities. And our inability to make it stop can legitimately concern us.
  • Ransomware is progressing, a little over a fifth of the year’s incidents, and constitutes the real structuring risk, shifting towards the supply chain (equipment suppliers, logisticians, shipowners, service providers).

The tactics, techniques and procedures (TTPs) most often found are stable and unsurprising: phishing and targeted phishing (spearphishing) for initial access; credentials stolen by infostealers and then resold by Initial Access Brokers; exploitation of exposed remote-access services (VPN, RDP, SSH) and of unpatched end-of-life systems; double extortion combining data theft and encryption; and compromise of service providers to reach their customers in cascade.

The recurring vulnerabilities are, likewise, classics: default or weak credentials, multi-factor authentication that is absent or bypassable, a poorly managed Internet-exposed surface, late patching, end-of-life equipment and software, insufficient segmentation between business IT and industrial systems, and dependence on a single supplier.

The good news is that the most effective protections are known and accessible. In order of impact: deploy phishing-resistant multi-factor authentication, everywhere; reduce and harden the exposed surface (inventory, closing unnecessary remote accesses, rigorous patch management); take care of identity hygiene and monitor credential leaks; segment networks and test offline backups; equip yourself with anti-DDoS protection and a continuity plan so as not to panic in the face of noise; and finally carry contractual cyber requirements through to equipment suppliers and service providers, since a growing share of the risk now passes through them.

In practice, the scenario to prepare for as a priority is the prolonged unavailability of a link in the chain: a freight forwarder, a shipping agent or an electronics supplier at a standstill for two weeks, along with all the activity that depends on it. That risk is concrete, and already common. Budget for it and test it in 2026, well before the headline-grabbing ship hijacking.

Sources

  • [1] ISSSource, Rhysida ransomware attack on a marine navigation electronics manufacturer (2025)
  • [2] Security Affairs, Lab-Dookhtegan disrupts Iranian ships’ communications via their VSAT provider (March 2025)
  • [3] Council of the EU, attribution of the Viasat / KA-Sat attack to Russian military intelligence (10 May 2022)
Olivier JACQ

Olivier JACQ