{
  "slug": "maritime-cyber-defense-attack-surface",
  "url": "https://xin.bz/future-insights/maritime-cyber-defense-attack-surface/",
  "title": "Every Ship Is a Network: Maritime Cyber Risk From NotPetya to the 2027 Deadline",
  "description": "Future Insights — the maritime cyber record from GAO, Coast Guard Cyber Command, MARAD and ENISA: NotPetya at $250–300M and attributed to the GRU, GPS spoofing from a 2013 UT Austin experiment to 1,700 events at Hormuz, default credentials on two-thirds of Coast Guard missions, and the plans due July 2027.",
  "published": "2026-09-21",
  "updated": "2026-09-21",
  "section": "Future Insights",
  "series": null,
  "category": null,
  "author": "Xin.bz Future Insights",
  "period": "2017–2027",
  "tags": [
    "maritime cyber",
    "cybersecurity",
    "GAO",
    "CTIME",
    "ENISA",
    "ransomware",
    "GPS spoofing",
    "AIS",
    "ECDIS",
    "operational technology",
    "ports",
    "container shipping",
    "NotPetya",
    "LockBit",
    "IACS UR E26",
    "US Coast Guard",
    "IMO",
    "ZPMC",
    "ship-to-shore cranes",
    "Strait of Hormuz",
    "supply chain security"
  ],
  "keyPoints": [
    "NotPetya took Maersk offline in June 2017 at $250–300 million and ten days of rebuilding. Nine governments attributed it to Russian military intelligence.",
    "The U.S. Marine Transportation System carries $5.4 trillion a year through roughly 360 ports, on systems connected to the internet after they were designed.",
    "Coast Guard protection teams find default credentials in place on more than two-thirds of their missions.",
    "Ports are the pressure point ashore: Nagoya lost two days in 2023 and DP World Australia stranded 30,137 boxes across five terminals.",
    "One software vendor reaches a thousand hulls. The January 2023 attack on DNV's ShipManager touched roughly 70 customers operating about 1,000 vessels.",
    "GNSS spoofing went from a 2013 experiment to 35–117 vessels a day affected in the Mediterranean and Black Sea.",
    "Three regimes come due together: IMO rules since 2021, IACS UR E26 and E27 from July 2024, and U.S. plans by July 16, 2027."
  ],
  "bodyFormat": "markdown",
  "body": "*Future Insight — part of the Xin.bz Future Insights series.*\n\n## At a glance\n\n- **$5.4 trillion** in goods and services move through the U.S. Marine\n  Transportation System each year, across roughly 360 commercial ports,\n  supporting more than 30 million jobs (GAO, 2025)\n- **$250–300 million** — the cost of NotPetya to Maersk in 2017, attributed by\n  nine governments to Russian military intelligence\n- **30 hours** — a U.S. maritime facility shutdown from Ryuk ransomware in 2019\n- **1,000 vessels** touched by one software vendor's ransomware incident in 2023\n- **30,137 containers** stranded in Australia across five terminals in 2023\n- **Two-thirds** of Coast Guard cyber protection missions found default\n  credentials in place\n- **35–117 vessels a day** affected by GNSS interference in the Mediterranean\n  and Black Sea; **1,700+** events around the Strait of Hormuz in early 2026\n- **July 16, 2027** — the date U.S. cybersecurity plans come due\n\n## The industry already has its worked example\n\nIn June 2017 the NotPetya malware reached A.P. Møller-Maersk through a\ncompromised accounting package and spread across the company's network in\nhours. Screens went black in Copenhagen, in Rotterdam, at gates in New Jersey\nand Mumbai, and the booking system that tells terminals which box goes where\nstopped answering. Maersk put the cost at up to $300 million. Recovery took ten\ndays and required rebuilding 4,000 servers and 45,000 computers. It ran from a\nsingle surviving copy of the company's network directory, found on a server in\nGhana that a local power cut had taken offline before the malware arrived.\nCongestion followed at terminals operated by APM Terminals, which runs 76\nports, with delays reported in Denmark, India, Spain, the Netherlands and the\nUnited States.\n\nMaersk was collateral damage rather than a target. In February 2018 the United\nKingdom's National Cyber Security Centre concluded that the Russian military\nwas \"almost certainly responsible\", and the White House called it \"the most\ndestructive and costly cyber-attack in history\". Nine governments attributed\nit jointly to GRU unit 74455. The malware was aimed at Ukraine. A shipping line\ncarrying a fifth of world container capacity became one of its most expensive\ncasualties, because its network was flat, connected, and running the world's\nfreight bookings.\n\nThat is the shape of maritime cyber risk. The U.S. Marine Transportation\nSystem alone moves $5.4 trillion of goods and services a year through roughly\n360 commercial ports, and supports more than 30 million jobs. It runs on\nsystems designed for reliability at sea and connected to the internet\nafterward. A 2019 Ryuk ransomware infection shut one U.S. maritime facility for\n30 hours, which is the scale at which most of this happens: short, expensive,\nand rarely named in public.\n\n## Nine years of the record\n\n| Date | Event | Effect |\n|---|---|---|\n| June 2017 | NotPetya reaches Maersk | Up to $300M; 4,000 servers and 45,000 PCs rebuilt |\n| 2018 | COSCO, Port of Barcelona, Port of San Diego | Regional booking and terminal systems offline |\n| 2020 | MSC, CMA CGM, and the IMO itself | Booking platforms and the regulator's own site down |\n| Jan. 2023 | Ransomware at DNV's ShipManager | ~70 customers, ~1,000 vessels |\n| July 2023 | LockBit at the Port of Nagoya | Container operations halted two days at 10% of Japan's cargo trade |\n| Nov. 2023 | DP World Australia | Five terminals, 40% of national box trade, 30,137 containers stranded |\n| Mar. 2024 | Congressional report on crane supplier | Undocumented cellular modems found on delivered equipment |\n| Dec. 2025 | Adriatic Port Authority (Ancona) | $10M bitcoin demand, Adriatic rerouting |\n| Dec. 2025 | RAT on the ferry *Fantastic* | Malware carried to a bridge workstation on a USB drive |\n| June 2026 | Shipping Association of New York & New Jersey | Data leaked by the Qilin group |\n| Aug. 2026 | North Carolina Ports | Wilmington, Morehead City and Charlotte Inland Port on manual processing |\n\nThe pattern in that column is worth reading twice. Every entry after 2020\ninvolves cargo standing still, and the mechanism is the same each time:\ngate systems, terminal operating systems, and booking platforms are the\nsoftware that decides whether a box moves.\n\n## Nobody has reliable numbers, and that is an official finding\n\nIndustry counts circulate widely. One 2026 vendor white paper puts maritime\nincidents at 828 in 2025 against 408 in 2024, with ransomware cases more than\ndoubling to 372. Another records roughly a thousand navigation disruptions a\nday touching more than 40,000 vessels.\n\nSet those beside the regulator's own position. In its 2025 review of maritime cybersecurity, the U.S. Government\nAccountability Office found that Coast Guard cybersecurity incident data \"are\nnot sufficiently reliable\" for describing how often incidents occur. It\nrecommended the service fix its case management system so cyber deficiency\ndata becomes accessible in full. The\nCoast Guard's own Cyber Trends and Insights in the Marine Environment reports\ndescribe a 17% year-over-year rise in reported incidents, on a reporting base\nthe GAO has flagged as incomplete.\n\nBoth things hold at once: the direction is consistent across every source, and\nthe denominator is unknown. Reported figures describe reporting behaviour as\nmuch as attacker behaviour, and an industry with voluntary disclosure and\ncommercial reputations at stake reports the incidents it has to. The useful\nreadings are therefore the named events, where the effect is measurable, and\nthe assessment findings, where an inspector looked directly at the systems.\n\n## The attack surface has three layers\n\n**Shore side.** Terminal operating systems, gate automation, customs\ninterfaces, booking platforms, and the inland rail and trucking systems that\ndepend on them. This layer carries the most incidents because it looks like\nordinary enterprise IT and behaves like critical infrastructure.\n\n**Vessel.** Electronic chart display (ECDIS), automatic identification (AIS),\nengine and propulsion control, ballast water management, cargo and ballast\nmonitoring, and integrated automation. The 2026 threat reporting records\nattacks penetrating these systems directly, with chart data manipulation and\nremote access to engineering systems among the observed outcomes.\n\n**Link.** VSAT, Starlink, and cellular connections between the two. The\nintegration of satellite communications with onboard operational technology is\nthe change that widened the surface, because it connected equipment designed\nfor an isolated environment to a permanent open channel.\n\n## Navigation: from a 2013 experiment to an industrial-scale problem\n\nGlobal navigation satellite signals arrive at a ship at roughly the power of a\ncar headlight seen from 20,000 kilometres away, which makes them\nstraightforward to overwhelm with a local transmitter. Jamming denies the\nsignal. Spoofing replaces it with a false one, and the ship's own instruments\nreport the false position as fact.\n\nThe academic work came first and said exactly this. In June and July 2013 a\nUniversity of Texas at Austin team led by Todd Humphreys took control of a\n65-metre yacht on the Ionian Sea, the *White Rose of Drachs*. They used the\nfirst openly acknowledged GPS spoofing device, then measured how readily the\nbridge instruments accepted the false solution. The finding: a spoofed vessel\nsteers off course while its own displays read nominal.\n\nFour years later the same technique appeared in operation. In June 2017 the\nU.S. Maritime Administration issued advisory 2017-005A after more than twenty\nvessels in the Black Sea reported GPS positions placing them at an inland\nairport. A 2019 C4ADS investigation then documented the practice systematically. Using\na GPS receiver aboard the International Space Station, it geolocated spoofing\nsources across Russia and Syria, and established the activity as routine state\npractice rather than isolated malfunction.\n\n| Period | Observed activity | Source |\n|---|---|---|\n| 2013 | First open academic spoof of a vessel at sea | UT Austin |\n| June 2017 | 20+ vessels in the Black Sea placed at an inland airport | MARAD 2017-005A |\n| 2019 | Spoofing sources geolocated across Russia and Syria | C4ADS |\n| 2021–24 | 35–117 vessels a day affected, Mediterranean and Black Sea | GAO |\n| Early 2026 | 1,700+ interference events; 1,100+ vessels spoofed in 24 hours | Industry reporting |\n\nThe trend in that column is the story: a laboratory result in 2013, a regional\nincident in 2017, a documented state practice by 2019, a daily background rate\nby the mid-2020s, and a wartime concentration in 2026. The capability moved\nfrom proof to routine in roughly a decade.\n\nThe second-order effect is what matters for trade. A ship's AIS transponder\ntakes its position from the same GNSS receiver, so a spoofed vessel broadcasts\na false position to every other ship and shore station in range. Interference\nagainst one hull degrades the traffic picture for everyone, and it lands in\nthe busiest and most contested water: the Hormuz corridor carries roughly a\nfifth of world seaborne oil and gas.\n\nGroundings and collisions in the Baltic through 2024 and 2025 were publicly\nlinked to satellite navigation interference, which places the consequence in\nhull and cargo losses rather than in data.\n\n## One vendor reaches a thousand hulls\n\nMaritime software concentrates. Fleet management, planned maintenance,\nchartering, and crew systems run on a small number of platforms sold to\nhundreds of operators, and a compromise at the vendor reaches every customer\nat once.\n\nThe January 2023 ransomware attack on DNV's ShipManager suite demonstrated the\narithmetic: roughly 70 customers, about 1,000 vessels, and a two-month\nrestoration to full service. The ships sailed throughout, because the affected\nsystems were shore-managed, and the operators lost the tooling that tracks\nmaintenance, compliance and technical status across their fleets.\n\nEquipment carries the same concentration. A March 2024 joint congressional\ninvestigation reported that one Chinese state-owned manufacturer supplies\nclose to 80% of ship-to-shore cranes installed at U.S. ports, and that\ninvestigators found cellular modems attached to crane control systems that\nappeared outside the sales contracts and the delivery documentation. The\nmanufacturer disputes the findings.\n\nThe GAO examined the same question and reached a broader conclusion. Coast\nGuard teams evaluated more than 90 Chinese-manufactured cranes and found\nvulnerabilities that reflect weaknesses across the marine transportation\nsystem rather than flaws specific to one manufacturer.\n\nBoth findings point the same way for an operator. One supplier holds\nfour-fifths of the machines that lift every container off every ship at the\nreceiving end of the world's largest import market. The security baseline for\nport control equipment runs low wherever it was built.\n\n## The crew is the entry point\n\nIn December 2025 a remote access trojan reached the bridge workstation of the\nferry *Fantastic* when a crew member, acting on outside instruction, inserted\na USB drive. That single case describes the layer that sits beyond every\nfirewall.\n\nCrews rotate, work under time pressure, and now carry personal connectivity\naboard through the same satellite links that serve the ship. Charts update by\nUSB on many vessels. Contractors board with laptops for engine and automation\nwork. Each is a routine operational practice that doubles as an entry path,\nwhich is why the training requirement in the new U.S. rules took effect\nbefore the technical ones.\n\n## Who is on the other side\n\nThe GAO names five threat sources against the marine transportation system:\nChina, Iran, North Korea, Russia, and transnational criminal organisations,\nwith hacktivists and insiders alongside them. It cites the Chinese state-\nsponsored Volt Typhoon group for pre-positioning in critical infrastructure,\nand Cl0p and Black Basta among the Russian-based ransomware operations.\nGrouped by what they want, that resolves into three.\n\n**Criminal ransomware crews** supply the volume. LockBit at Nagoya, Anubis at\nAncona with a $10 million bitcoin demand, Qilin against the New York and New\nJersey shipping association: these are extortion businesses that treat a\nterminal's downtime cost as their pricing model. A port that loses a day of\ngate moves pays more per hour than almost any other target, which is what\nputs maritime logistics high on their lists.\n\n**State and state-aligned operators** want position rather than payment. GNSS\njamming and spoofing at the scale recorded around the Strait of Hormuz\nrequires transmitters, power and persistence, and it runs continuously rather\nthan in bursts. Equipment supply chains belong in the same category: a modem\non a crane control system is an access question, and access held quietly is\nworth more than access used.\n\n**Insiders and proximity access** close the set. The *Fantastic* case ran\nthrough a crew member and a USB drive. Contractors, chandlers, surveyors and\npilots all board with devices, and a vessel in port hosts more outside hands\nin a day than most facilities see in a month.\n\n## What defense looks like in practice\n\nCoast Guard cyber protection teams publish what they find when they look.\nTheir assessments report default credentials still in place on more than two-\nthirds of missions, and a 71% year-over-year rise in the use of stolen or\ncompromised credentials in reported incidents. Between 2021 and 2024 those\nteams ran 60 security assessments, 21 threat-hunting operations and 9 incident\nresponses across the system.\n\nThat is the baseline the defensive measures work against. The ones that have\nheld up across these incidents are unglamorous and mostly architectural, and\neach has a case where it decided the outcome.\n\n| Measure | What it does | Where it decided an outcome |\n|---|---|---|\n| **Segregation** | Keeps navigation, engine automation and crew internet on separate networks, containing a compromise to the layer it lands in | Operators who came through 2023 and 2025 with cargo moving had split terminal systems from corporate IT beforehand |\n| **Offline recovery** | Holds directory and system state where an attacker cannot reach it | Maersk restored in ten days on a domain controller that sat offline in Ghana through the attack |\n| **Manual fallback** | Runs gates, stowage and position fixing on paper and radar | North Carolina Ports kept cargo moving in August 2026 on manual gate processing |\n| **Vendor discipline** | Puts security terms, software bills of materials and remote-access limits on the procurement desk | The DNV and crane cases both reached operators through suppliers |\n| **Crew training** | Closes the path that sits beyond every firewall | The *Fantastic* RAT arrived on a USB drive carried to the bridge |\n\nCrew training is the one the U.S. rule sequenced first, with the annual\nrequirement effective January 2026, eighteen months ahead of the plan\ndeadline. Manual fallback is the one the sector already knows: crews that\ndrill paper procedures lose hours where others lose days.\n\n## What the numbers record\n\n| Measure | 2024 | 2025 |\n|---|---:|---:|\n| Maritime cyber incidents | 408 | 828 |\n| Year-over-year change | — | +103% |\n| Ransomware cases | — | 372, more than double 2024 |\n\nDistributed denial of service, ransomware and malware account for most of that\nvolume. The composition matters more than the total: the 2026 reporting\ndescribes attacks reaching vessel operational technology rather than stopping\nat shore-side offices, which moves the risk from lost bookings toward lost\ncontrol of machinery.\n\n## The rules arrive in three waves\n\n| Regime | Scope | In force |\n|---|---|---|\n| IMO Resolution MSC.428(98) | Cyber risk inside the safety management system, all vessels | January 1, 2021 |\n| IACS UR E26 and E27 | Vessel-wide cyber resilience; hardened onboard systems from manufacturers | Ships contracted from July 1, 2024 |\n| U.S. Coast Guard, 33 CFR 101 Subpart F | U.S.-flagged vessels, facilities, OCS facilities | Effective July 16, 2025 |\n\nThe Coast Guard rule is the most specific of the three. It requires annual personnel training from January 12, 2026. By **July 16,\n2027** every regulated owner and operator must designate a Cybersecurity\nOfficer, complete a cybersecurity assessment, and submit a cybersecurity plan\nfor approval. It is the first mandatory cybersecurity framework under the Maritime\nTransportation Security Act.\n\nUR E26 and E27 answer the vessel side by building resilience in from the\ndesign contract forward. E26 treats the ship as one integrated system across\ndesign, commissioning, operation and maintenance. E27 puts the obligation on\nequipment manufacturers to deliver hardened systems before installation.\n\n## Europe measures it the same way\n\nThe European Union Agency for Cybersecurity reaches comparable conclusions\nfrom its own data. Ransomware became the leading threat to the transport sector during 2022,\nrising from 13% of recorded attacks in 2021 to 25%. Across the January 2021 to\nOctober 2022 window it accounted for 38% of transport-sector attacks. ENISA also records that state-sponsored actors\nare attributed to maritime targets more often than to other transport\nsubsectors, which separates the sea from the rest of the industry.\n\nIn the agency's more recent reporting, transport ranks second among EU\nsectors at 7.5% of recorded incidents, with hacktivist denial-of-service\ncampaigns supplying most of the volume and ransomware supplying most of the\ndowntime and cost. The NIS2 directive brings European ports and operators into\na mandatory reporting regime, which over time gives the sector the denominator\nthe GAO says is missing in the United States.\n\n## Where the exposure concentrates\n\nThe three regimes leave a visible seam. UR E26 and E27 apply to ships\ncontracted from July 2024, so they reach the newbuild order book and leave the\nexisting fleet to the IMO's safety-management language and to owners'\ndiscretion. The average age of the world merchant fleet runs above a decade,\nwhich places the majority of hulls outside the technical standard for years.\n\nPorts sit under national regimes that vary by jurisdiction, and the incident\nrecord concentrates there. Terminal operators run the systems that stop cargo,\nand an operator's exposure extends to every carrier calling at its berths.\n\nThree structural features set the size of the problem:\n\n1. **Consolidation.** A handful of carriers, terminal operators, software\n   vendors and equipment manufacturers serve most of the industry, so a single\n   compromise propagates to a large share of the trade.\n2. **Operational technology lifecycles.** Engine and automation systems run\n   for the life of the vessel, measured in 25 to 30 years, on software that\n   updates at the pace of dry-dock schedules.\n3. **Jurisdictional patchwork.** A vessel changes legal regime every few days\n   and answers to the flag state, the port state, the class society and its\n   charterer, each with a different cyber requirement.\n4. **Regulator capacity.** As of October 2024 the Coast Guard carried 15%\n   vacancy rates in both its cybersecurity specialist positions and its cyber\n   protection teams, which sets a ceiling on how many of the plans arriving\n   by July 2027 can be reviewed and how many facilities can be assessed.\n\n## What can move the market?\n\n- Coast Guard plan submissions and the July 16, 2027 compliance rate\n- the first enforcement actions under 33 CFR 101 Subpart F\n- class society interpretations of UR E26 and E27 at newbuild delivery\n- GNSS interference levels in Hormuz, the Baltic and the Black Sea\n- cyber insurance pricing and war-risk exclusions for maritime hulls\n- any incident that reaches propulsion or steering on a laden vessel\n- terminal operating system vendor consolidation\n- port equipment procurement decisions on supplier origin\n- IMO action on cyber requirements for the existing fleet\n- ransomware group targeting shifts toward logistics and terminals\n- national rules following the U.S. model in other flag and port states\n- crew connectivity policy and onboard network segregation practice\n\n## Xin.bz bottom line\n\nMaritime cyber risk stopped being theoretical in June 2017, when a piece of\nmalware aimed at another country took $300 million and ten days out of the\nworld's largest container line.\n\nThe record since then is consistent: attacks land on the systems that decide\nwhether cargo moves, and the cost appears as stationary boxes rather than as\nstolen data. Nagoya lost two days. DP World Australia lost five terminals and stranded\n30,137 containers, more boxes than the largest ship afloat can carry. North\nCarolina Ports went back to paper in August 2026.\n\nThe surface has widened in a specific direction. Satellite connectivity reached\nvessel operational technology, which put engine control, chart display and\nballast systems on the same network as the crew's email. The 2025 incident\ncount doubled, and its composition shifted toward those systems. Navigation\nfaces a separate and continuous problem, with more than a thousand daily\ninterference events worldwide and the densest concentration in the strait that\ncarries a fifth of seaborne energy.\n\nThe rules answer the newbuild and the U.S. regulated entity. They leave the\nexisting fleet, the foreign terminal, and the equipment already installed to\ncommercial judgment, and that gap closes on shipowner timelines rather than\nregulatory ones.\n\n**The industry's cyber exposure is a function of its efficiency: the same\nconsolidation that moves 80% of world trade on a small number of platforms\ngives an attacker a small number of targets.**\n\n## Sources\n\n**Government and regulatory**\n\n- U.S. Government Accountability Office. *Coast Guard: Additional Efforts Needed to Address Cybersecurity Risks to the Maritime Transportation System*, GAO-25-107244. 2025.\n- U.S. Government Accountability Office. *Offshore Oil and Gas: Strategy Urgently Needed to Address Cybersecurity Risks to Infrastructure*, GAO-23-105789. 2023.\n- U.S. Coast Guard Cyber Command. *Cyber Trends and Insights in the Marine Environment (CTIME)*, annual reports, 2023–2026.\n- U.S. Coast Guard. *Cybersecurity in the Marine Transportation System*, final rule, 90 FR 6298, January 17, 2025; 33 CFR Part 101 Subpart F.\n- U.S. Maritime Administration. Advisory 2017-005A, *Black Sea — GPS Interference*. June 2017.\n- U.S. House Committee on Homeland Security and Select Committee on the CCP. Joint investigative report on ship-to-shore cranes. March 2024.\n- The White House, Office of the Press Secretary. Statement attributing NotPetya to the Russian military. February 15, 2018.\n- United Kingdom National Cyber Security Centre. Assessment attributing NotPetya to the Russian military. February 2018.\n- European Union Agency for Cybersecurity. *ENISA Transport Threat Landscape* (January 2021 – October 2022) and *ENISA Threat Landscape*, 2024–2025 editions.\n- International Maritime Organization. Resolution MSC.428(98), *Maritime Cyber Risk Management in Safety Management Systems*, adopted June 16, 2017; MSC-FAL.1/Circ.3, *Guidelines on Maritime Cyber Risk Management*.\n- International Association of Classification Societies. *UR E26 — Cyber Resilience of Ships* and *UR E27 — Cyber Resilience of On-board Systems and Equipment*. In force July 1, 2024.\n\n**Academic and research**\n\n- Bhatti, J. and Humphreys, T. E. *Hostile Control of Ships via False GPS Signals: Demonstration and Detection*. Radionavigation Laboratory, University of Texas at Austin; sea trials aboard the *White Rose of Drachs*, June–July 2013.\n- Center for Advanced Defense Studies (C4ADS). *Above Us Only Stars: Exposing GPS Spoofing in Russia and Syria*. 2019.\n\n**Company and incident disclosures**\n\n- A.P. Møller-Maersk. NotPetya impact statements and interim results, 2017.\n- DNV. ShipManager cyber incident statements, January–March 2023.\n- Port of Nagoya Unified Terminal System. Incident statements, July 2023.\n- DP World Australia. Cybersecurity incident media statements, November 2023.\n\n**Industry and press reporting** — cited above as industry figures, on a reporting base the GAO records as incomplete\n\n- CYTUR Inc. *2026 Maritime Cyber Threat White Paper*. February 2026.\n- Cydome. *Maritime Cyber Trends: What Shipping Executives Need to Know for 2026*. March 2026.\n- Resecurity. Anubis ransomware analysis, Adriatic Port Authority. January 2026.\n- Greenberg, A. *The Untold Story of NotPetya, the Most Devastating Cyberattack in History*. WIRED. August 22, 2018."
}