Skip to content

Contents

Marlink's 2026 cyber report: what does the field data say (or rather, the data from space!)?

On 15 April 2026, Marlink published three cyber threat intelligence reports [1], built on the 2025 activity of its security operations centres (SOC) and on more than 200 security assessments. The satellite connectivity provider has a rare vantage point: direct telemetry from ships in operation. These documents therefore contain original field data, worth analysing for those of us who usually sit on the other side (well, often), waiting for the attacker to communicate and, broadly, watching the same sources.

This article is also available in French.

The full report and its two sector editions

The “Cyber intelligence report for remote operations” (38 pages) is the reference document. The reports dedicated to maritime (26 pages) and to energy, enterprise and critical infrastructure (20 pages) are extracts of it, reproduced almost word for word. All three are downloaded against a form and an email address on the publisher’s website [2]. The maritime edition is also freely available, since Hellenic Shipping News published it in open access [3], and Marlink put a six-page executive summary online on 16 September 2026 [4].

The maritime edition adds a section on low Earth orbit (LEO) connectivity and a more detailed presentation of one case study. It leaves out most of the cross-cutting figures, however: IT/OT exposure, exposed credentials, phishing statistics, tactics observed by the SOC, ransomware volumes. IT and OT stand here for business information technology and for the operational technology that runs industrial or onboard systems. So if you stick to the maritime report alone, you risk missing the most interesting data. Unless stated otherwise, the figures quoted here therefore refer to the full report.

Marlink’s methodology describes its sources: SOC monitoring, more than 200 assessments including 160 technical tests and red team exercises, incident investigations, simulated phishing campaigns and threat analysis. The report is honest enough to state that its results are indicative trends, “indicative patterns derived from observed environments rather than exhaustive measurements of global cyber activity” (maritime report, p. 25). It gives no volume at all, neither ships monitored, nor alerts, nor confirmed incidents, and every result is therefore expressed as a percentage. The same page promises citations for external figures, “Where external research findings or third-party statistics are referenced, they are clearly cited in the report to ensure transparency and proper attribution”. None of the three documents contains a single reference, and several of the figures examined below suffer from it.

The expected findings…

These percentages serve a central thesis that will surprise no one: incidents are increasingly centred on identity and persistence. Initial access comes through compromised credentials, phishing or the hijacking of legitimate access, including that of third parties. What follows is quiet activity, relying on the administration tools already in place (LOTL, living off the land). The report concludes that the priority is shifting from prevention to early detection and containment (you too may be thinking of Zero Trust).

The finding is familiar, but it is consistent, and the recommendations are concrete. Among those the report puts forward:

  • eliminate shared credentials across the fleet (many of which, incidentally, live on the satellite segment),

  • enforce multi-factor authentication on remote access,

  • centralise the approval and monitoring of vendor access,

  • segment the crew network, business systems and operational domains,

  • include the loss of navigation and communications in exercises.

The section on misconceptions is rather well built: physical isolation (air gap) that is rarely real in practice, insurance that is no substitute for resilience, and the famous “too small to be targeted” argument.

On the regulatory side, the report relies on the US Coast Guard Final Rule on cybersecurity in the Maritime Transportation System (MTS) [5]. Published on 17 January 2025 and in force since 16 July 2025 for US-flagged vessels and facilities subject to the Maritime Transportation Security Act (MTSA), it phases its obligations up to the cybersecurity plan due on 16 July 2027. The consultation opened on a two-to-five-year delay for vessels alone has had no published outcome at the time of writing, and the June 2026 instructions on the assessment, discussed here, fit within the original timeline.

The report also mentions the obligations stemming from NIS 2 for the maritime and port entities concerned. As a reminder, the famous directive [6] excludes the ships operated by the companies it covers: those fall under the IMO framework, the flag State and… the classification societies. In France, the transposition bill adopted by the Senate in March 2025 had still not been scheduled for debate in the National Assembly by mid-September 2026 [7]. The reference texts are gathered on this site’s links page.

As for the IACS UR E26 and E27 requirements [8], the Unified Requirements of the International Association of Classification Societies, they apply to vessels contracted on or after 1 July 2024. Because of shipyard backlogs, however, a good share of the vessels delivered in 2025 and 2026 were ordered before that date. Fleets will therefore remain heterogeneous for many years to come. The report also points to the tendency of shipowners to assume that cybersecurity is taken care of by equipment manufacturers and integrators, whereas the latter commit to the functioning of their systems (maritime report, p. 13). The overall risk stays with the shipowner (who will be delighted). Cyber clauses in newbuild contracts remain vague, and cyber expertise applied to onboard OT is often lacking among owners, managers and charterers (and equipment manufacturers, we would add). In short, we are not quite ready for the CRA (Cyber Resilience Act) yet :-)

Finally, the report lists the insurance sector among the parallel regulators, with premium increases of approximately 34% year on year (maritime report, p. 9). It does not say where this figure comes from, and the available market indicators point the other way for rates. Fitch Ratings [9] records for 2025 a rise of nearly 11% in US cyber direct written premiums, driven by growth of about 34% in the number of policies in force, with rates flat to down. Marsh’s market index [10] measures for its part a 7% decline in cyber rates in the fourth quarter of 2025, in every region of the world. The widening of exclusions for State-attributed attacks and for unpatched systems, which the report mentions in the same sentence, is on the other hand consistent with the evolution of insurance market clauses since 2023.

The assessments, the solid part

These governance findings come out of Marlink’s assessments, which are also where the report’s most useful figures come from (p. 9 of the full report). Around 60% of the sites assessed in 2025 relied on infrastructure shared between IT and OT, more than 70% had undocumented or poorly secured connections to IT or to the outside, and 30 to 40% of OT assets were initially unknown or undocumented. Fewer than 25% of organisations had assigned OT security ownership, and more than half used third-party remote access solutions without centralised monitoring. With one important caveat: the sites assessed are those of organisations that commissioned an assessment, which does not make them a representative sample. The orders of magnitude remain telling nonetheless.

Otherwise, external attack surface monitoring shows 69% of risks tied to exposed or compromised credentials, against 12% tied to vulnerabilities (p. 12). Across the 160 technical tests, 33% of infrastructure findings are of critical or high severity, and 45% of web application findings are of high severity (p. 14). Red team exercises repeatedly end in full domain compromise, achieved by chaining moderate weaknesses. OK, why not. It probably depends on who is “on the other side” ;-)

The SOC sees… what it monitors

The report classifies what its SOC sees using the MITRE ATT&CK framework (Adversarial Tactics, Techniques and Common Knowledge), which has become the “common language” of many detection teams. A tactic there designates the objective of a step in the intrusion: discover the environment, stay in it, obtain credentials, execute code. A technique designates the method used to get there. A SOC that labels every alert this way can say at which point in the attack chain it most often catches the adversary, and where it sees nothing. The same grid serves to compare year on year, provided detection coverage has not moved in between.

At Marlink, the most frequent tactics in 2025 are Discovery (20%), Persistence (17%) and Credential Access (15%): once inside, the attacker maps, settles in and looks for credentials. At technique level, System Owner/User Discovery (18%), OS Credential Dumping (7%) and Command and Scripting Interpreter (7%) dominate. In plain terms: identifying the user and machine one has landed on, extracting the authentication secrets held by the system, and using the command interpreter already present. The Execution tactic, once in first place, drops to fifth. Process-related events account for 60% of the activity observed in enterprise and energy environments (energy report, p. 11). The SOC therefore mostly catches the adversary already inside and getting its bearings, and rarely at the moment it enters.

The report reads this as a change in attacker behaviour, “a structural change in attacker behaviour” (energy report, p. 11). Yet the same page describes, at Marlink, “the transition from perimeter-centric detection toward internal behavioural monitoring”, presented as an improvement in defensive maturity. A distribution of tactics measures first what the SOC is able to detect. The System Owner/User Discovery technique, in first place with 18%, is legitimately very present in day-to-day administration and usually generates many false positives. Likewise, the report reads into the concentration of alerts during working hours a will on the attackers’ part to blend into normal activity (p. 14), whereas such a peak can just as well follow the users’ own activity. Nothing in the report allows the two readings to be told apart.

The maritime report (p. 14) then narrows the focus to what the SOC sees of ships. Alerts there are concentrated at 82% on the crew network and 17% on network support; the office, LAN, administration and OT/ICS (industrial control systems) zones each weigh less than 1% (ouch!). Marlink’s maritime monitoring therefore bears essentially on the ship’s internet access. The report acknowledges it in so many words: “Low detection rates in these environments should not be interpreted as low risk, but rather as an indication of monitoring constraints and architectural complexity” (maritime report, p. 5). A low detection rate there reflects monitoring constraints (this reminds me of my PhD work). The report’s conclusions on onboard OT therefore come mostly from the assessments rather than from the SOC.

The same page splits the SOC’s investigations and confirmed incidents three ways: 41% for maritime transport, 41% for yachting and 18% for cruise. Yachting would thus weigh as much, in Marlink’s response activity, as the whole of maritime transport. This weight most likely reflects a specific feature of the operator’s customer portfolio: the logo of OmniAccess, the group’s brand dedicated to yachts since its acquisition in 2018 [11], appears in the footer of the full report. Nothing in it allows the sector’s loss experience to be read, nor the number of incidents behind these percentages, since the report gives no volume. Offshore, which nonetheless gets a qualitative section, thus seems absent from this split (and is no less exposed for it).

Within these alerts, the report records no large-scale malware outbreak over the period: intrusions rely on valid credentials, misconfigured access and quiet lateral movement. Initial access detections are less frequent than mid- or late-chain alerts, which suggests intrusions spotted after the attacker has settled in. The report finally states that 92% of the groups tracked by its intelligence team fall outside the advanced persistent threat (APT) category (p. 12), in other words, for the most part, cybercrime. For a shipowner, the likely threat therefore looks like what hits any connected company.

Two maritime case studies complete the picture (maritime report, p. 18):

  • the first is a compliance assessment against the US Coast Guard rule for an operator of US-flagged vessels: 17 findings across 8 categories, 16 applicable requirements, a maturity rated 2.1 out of 5;

  • the second concerns a yacht: a crew member returns from rotation with a compromised personal device, which connects to the onboard WiFi and spreads malware to other systems. The incident was only detected after propagation.

The yacht case illustrates what the section on low Earth orbit, specific to the maritime report (p. 16), develops with relevance. With LEO constellations, the bandwidth available on board goes up, latency drops from half a second to a few tens of milliseconds, and the link becomes permanent: the ship is no longer isolated in practice. The crew gains an internet experience comparable to home, personal devices included, and every additional use opens one more path to the onboard systems. The same link also allows continuous monitoring, provided governance, segmentation and surveillance keep pace1.

Phishing: an aggregate and two cases that do not add up

On simulated phishing, around 20% of recipients clicked (that is not much, usually, the first time, on a realistic exercise; I tend to see 80% instead), 11% of those who clicked entered their credentials (about 2% of recipients), and only 11% of recipients reported the message (p. 11). Most disclosures occur within the hour following receipt, which leaves very little room to react. Attackers rely on legitimate services such as SharePoint, DocuSign, PayPal or Zoom to host their content.

This aggregate does not match the detailed cases. The energy report (p. 12) presents two of them, a manufacturer of more than 600 staff put through three campaigns, and a critical infrastructure operator in the energy sector with fewer than 100 people put through four, where reporting declines with each wave. Their charts give, in aggregate, 9% clicks, 3% disclosure and 28% reporting for the first, and 19%, 10% and 30% for the second. If disclosure is measured against recipients, a third of clickers entered their credentials in the first case, and more than half in the second. That is a long way from the 11% announced overall. The reporting rates (28 to 30%) are also well above the aggregate’s 11%. Either the calculation bases differ, or the aggregate is dominated by other campaigns. The report does not say.

Ransomware: a plausible count with no stated source

The report states (p. 12) a rise from 5,740 attacks in 2024 to 7,793 in 2025, “based on leak-site reporting”, without naming the source. Its chart of the most active groups puts Qilin first with 1,024 victims, ahead of Akira (723), Clop (510), Play (390) and SafePay (373). These values are consistent with those of the main observatories, which in fact differ noticeably from one another.

Source20242025Change
Marlink (source not stated)5,7407,793+36%
Comparitech [12]5,6317,419+32%
Searchlight Cyber [13]not stated7,458+30%
Check Point [14]not stated7,960+53%

Comparitech’s ranking, published in January 2026, gives the same five groups in the same order, with close values (Qilin 1,034, Akira 765, Clop 454, Play 393, SafePay 374), which suggests a reading of the same leak sites a few weeks apart.

The report does not agree, on the other hand, with its own press release. The one dated 15 April 2026 [1] announces ransomware “detected across Marlink-monitored environments rising from 5,740 in 2024 to 7,793 in 2025”, that is, incidents detected among monitored customers. The report, for its part, ties these same figures to the ransomware groups’ leak sites, that is, to the worldwide count of published victims. No SOC sees 7,793 ransomware cases a year among its own customers alone. The report’s version is the right one, and the September summary indeed speaks of “reported” attacks.

The report, though it comes in a maritime edition, offers no maritime breakdown of ransomware. My own research dataset on maritime cyber incidents, built during my PhD work and maintained since with my own means, provides one. Its filter keeps the organisations whose activity belongs to the maritime ecosystem, from shipowners to equipment manufacturers, through ports, port logistics and offshore. For 2025, it counts 299 ransomware incidents against these organisations, a little under 4% of the victims published worldwide, including 86 at equipment manufacturers and industrial firms, 58 at logistics providers, 38 at shipowners and 32 at ports. The top five groups are Qilin (51), Play (40), Cl0p (37), Akira (27) and SafePay (15). These are exactly Marlink’s five, in a different order: Play and Cl0p move ahead of Akira, and Cl0p owes its rank to two waves, at the start and end of the year, typical of its mass exploitation campaigns of a single vulnerability. Maritime therefore follows the 2025 global hierarchy, and the groups that hit it most are the ones that hit most everywhere. I have detailed elsewhere what this dataset says about the past year.

GNSS spoofing: unsourced figures and a missing Red Sea

The maritime report (p. 11) puts forward two figures on GNSS spoofing (Global Navigation Satellite System, of which GPS is the best-known representative): an increase of approximately 340% in incidents in 2025, and 88% of vessels said to rely primarily on GPS. The full report repeats them (p. 19), and the trade press has already attributed them to Marlink. I found no source for the first, neither at Marlink nor among the usual observatories. Public indicators exist, but they measure something else. Windward, for instance, counts more than 13,000 vessels affected by jamming in the second quarter of 2025, then 11,600 in the third, a 510% increase over the first quarter [15]. These metrics count vessels per quarter, whereas Marlink counts “incidents” over a year, without defining them (reported incidents? vessels affected?), dating them or sourcing them. Marlink did publish, on 25 March 2026, a press release on a rise of more than 50% in GNSS interference observed among its customers over the single month of March [16]. That figure is dated and tied to a customer base. It does not match the 340%.

Same silence on the origin of the second. A neighbouring figure has been circulating for years: the European GNSS Service Centre writes that around 87% of the merchant fleet uses satellite navigation systems, referring to the European agency’s market study [17], and an ICRC blog post was already quoting it in 2017 [18]. Beyond the source, the wording confuses GPS and GNSS. Nor does it add much: nearly every ship uses GNSS as its primary position reference.

As for the spoofing areas cited, they are the Baltic, the Persian Gulf and the South China Sea. Neither the Red Sea, nor the eastern Mediterranean, nor the Black Sea appears. Yet Marlink had communicated in summer 2025 on a spectacular rise in requests for assistance. Its president for maritime explained to Splash247 [19] that in July 2024 the help desk received one call every two weeks for an unavailable GPS, and that by mid-July 2025 more than 150 vessels had reported the problem in a single day. This proprietary, dated and telling piece of data is not in the report. I have already described what GNSS interference does to a ship beyond position. A provider that receives the crews’ calls holds material on this subject that no one else has.

Assessment

One can take up the assessment data on IT/OT convergence, the 69/12 ratio between exposed credentials and vulnerabilities, the severity of technical test findings and the speed of credential disclosure during phishing. Also worth the detour are the phasing of the E26 and E27 requirements, the finding on dependence on equipment manufacturers, the analysis of low Earth orbit and the recommendations. The SOC breakdowns are to be read with the customer portfolio in mind and near-zero visibility on OT, the phishing aggregates with the discrepancies noted above, and the 340%, 88% and 34% will wait for a source to be produced.

Marlink holds a privileged vantage point, and the report only partly uses it. Absolute volumes, a maritime breakdown of ransomware, the use of its own GNSS assistance data and references for external figures would make it a reference document. There remains the nature of the document: the recommendations for independent validation, red team exercises and compliance assessments overlap with the group’s service offering. Fair enough for a service provider, and as attentive readers you will of course keep it in mind. Happy reading ;-)

Right of reply

Marlink, like any organisation named in this article, has a right of reply. Any request received through the contact page will be published in full and without comment below this article, within a few days.

Header image: top of the “Cyber intelligence report for maritime 2026”. Source: Marlink, reproduced under the right of quotation.

Sources

  • [1] Marlink, Marlink report reveals evolving cyber risk driven by user credentials and human error, press release of 15 April 2026
  • [2] Marlink, download page for the Cyber intelligence report for remote operations 2026, the Cyber intelligence report for maritime 2026 and the Cyber intelligence report for energy, enterprise & critical infrastructure 2026
  • [3] Hellenic Shipping News, open-access copy of the maritime report (April 2026)
  • [4] Marlink, Cyber intelligence report, executive summary 2026 (16 September 2026)
  • [5] US Coast Guard, Final Rule: Cybersecurity in the Marine Transportation System, Implementation Timeline
  • [6] Directive (EU) 2022/2555, known as NIS 2
  • [7] French National Assembly, legislative file of the bill on the resilience of critical infrastructure and the strengthening of cybersecurity
  • [8] IACS, Unified Requirement E26, Cyber resilience of ships
  • [9] Fitch Ratings, US Cyber Insurance Growth Raises Underwriting Risk (15 April 2026)
  • [10] Marsh, Global commercial insurance rates fall 4% in Q4 2025 (4 February 2026)
  • [11] The Maritime Executive, OmniAccess Becomes Part of Marlink Group (2018)
  • [12] Comparitech, Worldwide ransomware roundup: 2025 end-of-year report (13 January 2026)
  • [13] Searchlight Cyber, Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase (17 February 2026)
  • [14] Check Point, Ransomware Attack, What is it and How Does it Work?
  • [15] Windward, GPS Jamming Is Now a Mainstream Maritime Threat (23 October 2025)
  • [16] Marlink, Marlink reports 50% surge in satellite jamming and spoofing as geopolitical tensions impact global shipping (25 March 2026)
  • [17] European GNSS Service Centre, Expanding Opportunities for Maritime use of GNSS
  • [18] ICRC, Law & Policy blog, Combating ‘cyber fatigue’ in the maritime domain (7 December 2017)
  • [19] Splash247, Ship crews reach out for support as Red Sea GPS spoofing climbs to danger levels (22 July 2025)

  1. Let us remember that this analysis comes from a connectivity provider, which sells both :-) ↩︎

Olivier JACQ

Olivier JACQ