Maritime FUD seen from the bridge
On 16 December 2025, the first reports about the ferry Fantastic, operated by the Italian company Grandi Navi Veloci and alongside in Sète, announced the discovery on board of a “spy device”, or of a RAT [1] [2]. The acronym was not expanded.
It has two meanings. A RAT (Remote Access Trojan) is malware that arrives over the network, most often through a phishing attachment, and that antivirus or EDR (Endpoint Detection and Response) software handles well enough. A RAT (Remote Access Tool) can be a box you plug in, which then requires getting aboard. Over the following days the description became more precise: a Raspberry Pi type board paired with a cellular modem, physically installed on board, giving access to one of the vessel’s networks [3].
By then the public framing had settled. One headline announced that the operator “could have steered the vessel remotely” [1]. The French Interior Minister called the case extremely serious and noted that one country is often behind this type of interference. On 8 January 2026, a local weekly ran with a Russian spy aboard the ferry [4]. The same file nonetheless held measured elements: physical access on board, crew members questioned with one released, and an assessment putting the risk of genuine remote takeover close to zero [5].
Three unexpanded letters therefore carried the gap between a physical security incident and a scenario of conning a ship from outside. This is the ordinary mechanism of FUD (fear, uncertainty and doubt): a genuine technical uncertainty, filled with the most spectacular hypothesis before anyone could narrow it down. I devoted an article to the case in December, and I withdraw nothing from it today.
Commentary that runs ahead of the investigation
I am not writing any of this to hold that a ship is invulnerable, or that the maritime sector is doing fine. Maintaining an incident dataset with my own means would make no sense under that assumption, and neither would the years spent getting the subject understood.
The background noise weighs more. Every reasonably spectacular incident brings back the same lines, I told you so, it is an attack, ahead of any analysis and ahead of the least piece of investigation. The Dali struck the Francis Scott Key Bridge on 26 March 2024, and the cyberattack hypothesis was circulating the same day. Twenty months later the NTSB retained a signal wire that a label band had kept from seating fully in its terminal block, causing two blackouts and the loss of propulsion and steering on the approach to the bridge [6].
The Ever Given grounded in the Suez Canal on 23 March 2021, and the same hypothesis circulated within hours. In July 2023 the Panama Maritime Authority concluded that manoeuvrability was lost under wind, bank suction and a speed above the permitted limit, with hard helm orders and degraded communication on the bridge [7].
I have handled a case of that family myself. A Russian vessel managed by a company under United States sanctions, motionless for forty-one days in the middle of the Atlantic, transponder on, close to subsea infrastructure according to certain cable charts: the spy ship wrote itself. She was prospecting a polymetallic sulphide deposit inside blocks awarded to Russia by the International Seabed Authority, 165 nautical miles from the nearest cable.
These files share a trait of timing. Twenty months between the commentary and the conclusion for the Dali, twenty-eight for the Ever Given.
The distance between network access and conning a ship
On the Fantastic, I measure that distance with years spent at sea before I measure it with figures. A ship is not a network appliance. Propulsion and steering are operated from the bridge and from the engine control room, with local control positions available and a watch on duty. Taking a vessel anywhere means holding the loop long enough for it to matter, in front of an officer of the watch who sees the heading change and a helmsman who switches to hand steering. The satellite link adds its own latency and dropouts.
None of this makes the operation impossible, and I am not writing that a cyberattack against a ship cannot succeed. I am writing that it is hard to carry out, and that its difficulty rests on the architecture aboard and on the human presence well before it rests on the attacker’s skill. This is a statement about the cost of the operation.
The same connectivity that hinders the attacker grows year on year. Ships receive permanent broadband, remote maintenance links opened by equipment makers, shore-based performance monitoring, and fleet management run from an operations centre. Published vulnerabilities affect equipment on board, satellite terminals and electronic chart display systems among them. Underestimating them would be a mistake, and the trend runs in the attacker’s favour. Growing exposure nevertheless remains something other than an observed capability, and the December 2025 headline announced the latter.
An incident count measures collection first
Annual incident curves supply the other raw material of maritime FUD. They circulate with three-digit growth rates, and they are read as measurements of the phenomenon.
I maintain, with my own means, a longitudinal dataset of incidents affecting the maritime ecosystem. It holds 4,154 entries today. Because it is version-controlled, I can read it back at past dates and compare the same object with itself. On 31 May 2026 it carried 357 entries for the year 2023. On 21 September 2026 it carries 520 for that same year 2023, closed for two years and nine months. Nothing happened in 2023 between the two readings.

The year 2024 goes from 292 entries to 709, the year 2025 from 361 to 1,285. The whole dataset goes from 1,478 files to 4,155 in under four months. Those gains measure hours of reading and the opening of new collection channels. The curve also falls at times: the year 2023 went back from 357 entries to 342 in June, when a deduplication pass merged entries carrying the same fact.
The practical consequence is that a recent year is always the least read of the set. A catalogue being caught up with by the present therefore produces a curve that climbs, then sags over its last two or three years. That sag is the signature of the collection, and it is commonly read as a lull in the threat.
The share of vessels in a total
A ratio computed on such a denominator inherits the flaw. On 31 May 2026 my dataset carried 41 entries in which the ship itself is the victim, out of 1,478, or 2.8%. On 21 September it carries 60 out of 4,155, or 1.4%.

The number rose by 46% and the share was halved, in the same dataset, in four months. A vessel share expressed as a percentage therefore tells you how fast the rest was collected. The absolute number carries more: 60 entries in which the ship is the victim, from 1980 to today, 31 of them outside GNSS and AIS interference. Nine for 2026 as of 21 September, as many as for 2019, which was until now the best-filled year. Those 31 entries are a floor whose ceiling I do not know.
Impact, when someone goes and measures it
Attack claims lend themselves to the same slide as acronyms. A group publishes a target list, an aggregator picks it up, a count records it, and the impact sentence writes itself: logistics operations disrupted, supply chain threatened. What the source establishes is that a claim was published.
This point is settled by measurement, and the denial-of-service collector feeding my dataset runs an independent read-only probe against claimed targets, an HTTP HEAD request on the site root, through a relay, never against the endpoints under attack. Of the 88 targets measured so far, all in 2026, 61 were responding normally at probe time.

The probe has its limits. A single reading taken after the claim does not prove that there was never an outage, and a site root that answers says nothing about an application service behind it. It does establish that 23 targets out of 88 were genuinely unreachable, which rules out treating these campaigns as theatre. An instrument able to contradict whoever holds it keeps its value when it confirms.
Vessel incidents are poorly documented
Those 31 entries did not arrive on their own. Public disclosure of a cyber incident on board is mandatory under almost no flag. Insurers and protection and indemnity clubs handle the file under confidentiality, class societies are bound by contract, and the incident is settled at sea, often closed before anyone ashore thinks to ask. The ship then changes name and flag.
Three of the 2026 entries exist publicly because someone went and looked. A federal team boarded two tankers in the Gulf of Mexico on 21 and 24 August and established a network compromise. An LNG carrier has spent a month looking for a solution for her cargo, and the cyberattack accounts circulating about her come from no party with access to the ship.
The absence of documented cases is therefore a weak argument in both directions. The documentary gap leaves open the hypothesis that vessels are doing fine as much as the opposite one, and 31 entries trace no campaign directed at them. The question of risk level on board is settled with exposure measurements: how many ships run an unsegmented network, and how many would detect an unknown device plugged into it.
Asking before publishing
One may disagree with my analyses. Contesting a method, a set of figures or a conclusion is the substance of the trade, and I much prefer a public objection to polite agreement. Taking aim at a person falls outside that frame, and no scientific disagreement calls for it.
That frame is learned, and it is taught. In France, the arrêté of 25 May 2016 requires every doctoral student to receive training in research ethics and scientific integrity. Since 31 December 2022 the new doctor also speaks an oath aloud, individually, at the end of the defence. It opens on “in the presence of my peers” and closes on an undertaking to maintain “integrity of conduct in my relationship to knowledge, in my methods and in my results” [8]. What that commitment covers is written down elsewhere, in texts nobody has to guess at.
The European Code of Conduct for Research Integrity places respect for colleagues among its four founding principles, and asks reviewers and editors alike to respect the rights of authors [9]. Level with honesty, the Singapore Statement sets down professional courtesy and fairness in working with others, and expects fair, prompt and rigorous evaluations [10]. The French national charter for research ethics carries the same requirement over to working relationships [11].
On the matter of replying, the European code turns explicit where the stakes are heaviest: persons accused of research misconduct are given full details of the allegations, and are allowed a fair process for responding to them and presenting evidence [9]. Being cited as a counter-example in an article is plainly not an allegation of misconduct. The same reflex costs even less one notch down.
Journalism organises this under the name of the contradictoire. The French professional ethics charter for journalists ranks accusation without proof and failure to verify facts among the gravest lapses of the trade [12]. The French press council applies the rule to itself: on receiving a complaint, it informs the media outlet concerned and invites it to answer in writing within fifteen days [13]. Article 16 of the French code of civil procedure requires the judge to uphold, and to observe personally, the principle of contradiction [14]. Research imposes it nowhere in any systematic way.
I am writing this article because I have just experienced that. A search engine told me that I was cited, and called into question, in a journal article by another researcher. Neither the author nor the reviewers who approved the text contacted me, although my details are on this site. Without that chance discovery I would still be unaware of it.
The arrangement closes on itself. The text sits behind a paywall, out of reach of the person cited. Peer review gives it the journal’s warrant on top of that. A reader who opens it has little reason to doubt, since the author states it and the journal validated it. No channel allows an objection to be filed in the same place, and the attributed position is the one that reader carries away.
The effect on a researcher’s reputation does not depend on the intent behind it. A construction that produces that effect while opening no route to reply deserves to be asked what it is for.
The gesture asked for costs almost nothing. A position taken from a blog post and read quickly remains a first impression. Put to its author, it becomes a position, with its caveats, its dates, and what that author says of it today. The gap between the two is the one a research article works to remove everywhere else.
Making a dataset or a researcher the foil of an argument costs that argument more than it earns it: the thesis comes to depend on the caricature it has built, and falls with it.
When the same object is taken apart across several successive publications, the question stops being theoretical: at what point does methodical contradiction become something else? I see two possible explanations for that shift. Research ethics may never have featured in the training received. The professional cultures involved may also diverge to the point of no longer meeting on what one researcher owes another, and that kind of divergence is not settled by an exchange of publications.
Those divergences are judged in the end by what the work produces downstream. An incident dataset is worth only what it enables next: a crew that checks what is plugged into its network, an owner who segments theirs. Producing data in order to produce data leaves the maritime sector exactly where it was, and a publication mainly engaged in dismantling someone else’s does not move it either. Raising the sector’s awareness remains the only justification I find for this work.
For reviewers, one question fits on a line and breaks no anonymity: was the person cited contacted, or is this a reading of their public writing? Both approaches are legitimate, and the reader needs to know which one is in front of them.
That question extends what COPE (the Committee on Publication Ethics) already asks of reviewers: to be objective and constructive, and not to use the review process to disadvantage or discredit others [15]. In the current geopolitical and cyber context, where maritime work is picked up well beyond the circle able to read it, research gains from having the answer in the text.
Right of reply
Any person or organisation who considers themselves implicated by this text has a right of reply. A request sent through the contact page will be published in full and without comment following this article. Factual corrections are welcome and will be made with the change flagged.
Sources
- [1] CNEWS, “Il aurait pu diriger le navire à distance : la DGSI enquête après la découverte d’un dispositif espion sur un ferry”, 16 December 2025
- [2] Euronews, “France : enquête pour ingérence étrangère après un malware à distance détecté sur un ferry”, 18 December 2025
- [3] Le Monde Informatique, “Un ferry attaqué avec un Raspberry Pi”
- [4] La Gazette de Montpellier, “À Sète, un espion russe dans le ferry”, 8 January 2026
- [5] Le Parisien, “Ferry piraté par un logiciel espion : le risque d’une vraie prise de contrôle à distance est proche du zéro”, 16 December 2025
- [6] National Transportation Safety Board, “Loose Wire on Containership Dali Leads to Blackouts and Contact with Baltimore’s Francis Scott Key Bridge”, final report adopted on 18 November 2025
- [7] Splash247, account of the Panama Maritime Authority’s final investigation report into the grounding of the Ever Given, published on 12 July 2023
- [8] Arrêté du 25 mai 2016 setting the national framework for doctoral training, article 3 (training in research ethics and scientific integrity) and article 19 bis (oath of scientific integrity, introduced by the arrêté du 26 août 2022, in force on 31 December 2022; the oath is quoted here in my own translation from the French)
- [9] ALLEA, The European Code of Conduct for Research Integrity, revised edition 2023: principle of Respect (p. 5), section 2.8 “Reviewing and Assessment”, section 3.2 “Dealing with Violations and Allegations of Misconduct”
- [10] Singapore Statement on Research Integrity, 2nd World Conference on Research Integrity, Singapore, 21-24 July 2010: principle “Professional courtesy and fairness in working with others”, responsibility 8 on peer review
- [11] Charte nationale de déontologie des métiers de la recherche, January 2015, article 4 “Responsabilité dans le travail collectif” and article 5 “Impartialité et indépendance dans l’évaluation et l’expertise”
- [12] Charte d’éthique professionnelle des journalistes, Syndicat national des journalistes, 1918, 1938, 2011
- [13] Conseil de déontologie journalistique et de médiation, rules of procedure, articles 5.1 and 5.5
- [14] Article 16 of the French code de procédure civile
- [15] COPE, Ethical Guidelines for Peer Reviewers, DOI 10.24318/cope.2019.1.9