Skip to content
avatar

Maritime and port cybersecurity.

Threats, vulnerabilities, incidents and regulation across the maritime and port sector, from an operational angle informed by the author’s background.

Foreign interference on a ferry in Sète: between Raspberry Pi, RAT and media overreaction

This article is also available in French.

The case of the ferry Fantastic (operated by the Italian company Grandi Navi Veloci, GNV) in Sète, in December 2025, is interesting for several reasons. Not so much for its technical sophistication - which remains limited - but for what it reveals about how cyber incidents are handled, particularly in the maritime domain.

Very quickly, the event was portrayed as a potentially serious case of foreign interference, or even as a scenario involving remote control of a vessel. The reality, as it gradually emerges from publicly available information, is more nuanced - and probably more instructive.

Lost at Sea: Confronting GPS Jamming and Spoofing in Maritime Operations

This article is also available in French.

TL,DR: The BIMCO webinar, held on the 3rd of septembre 2025, was moderated by Jakob Larsen and featured NATO MARCOM officers Eric (French Navy) and Kadir (Turkish Navy) on GPS jamming and spoofing threats to maritime operations. Eric highlighted recent incidents: Ursula von der Leyen’s aircraft disrupted by jamming in Bulgaria, the merchant vessel Green Admire spoofed near Russia, and widespread interference in the Eastern Mediterranean linked to military activity. He emphasized that GNSS disruption is now a deliberate tool of hybrid warfare, not accidental.

Maritime cybersecurity 2024 in numbers

716 maritime cyber incidents recorded in 2024, against 117 two years earlier. Almost all of that growth comes from a single mode of action, noisy and industrialised, which hardly ever touches operations. Behind that curtain, ransomware kept advancing among the sector’s suppliers, and two submarine cables were severed in the Baltic by merchant ships.

CISA and the U.S. Coast Guard go “fishing” for vulnerabilities

On July 31, 2025, the CISA (Cybersecurity and Infrastructure Security Agency) and the U.S. Coast Guard (US Coast Guard, USCG) published a joint advisory (available here:
https://www.cisa.gov/sites/default/files/2025-07/joint-advisory-cisa-identifies-areas-for-cyber-hygiene-improvement-after-conducting-proactive-threat-hunt.pdf).

The document follows a proactive threat-hunting operation conducted on the network of a U.S. critical infrastructure organization. Such initiatives are aligned with the Cybersecurity Performance Goals (CPGs) jointly driven by NIST and CISA, as well as with the longstanding - and more recent - work of the USCG on maritime cybersecurity.

Addressing State-Linked Cyber Threats to Critical Maritime Port Infrastructure

As part of your healthy summer reading, have you also gone through the CCDCOE paper, “Addressing State-Linked Cyber Threats to Critical Maritime Port Infrastructure”?

No?

Then let me offer a brief personal reflection on and around the topic of port cybersecurity.

In this fine month of July 2025, the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE) published a Policy Brief entitled “Addressing State-Linked Cyber Threats to Critical Maritime Port Infrastructure”.

Maritime collision and GNSS spoofing: waiting for the facts before drawing conclusions

This article is also available in French.

Only a few hours after the collision between two vessels off the coast of Oman, the first claims attributing the accident to GNSS spoofing (GPS spoofing) began to circulate.

It is likely that we will soon see many screenshots and analyses claiming that GPS spoofing is responsible… or that it is not.

As is often the case with this type of event, it is better to wait for the results of the investigation before drawing conclusions.