Shipping is being targeted with an unprecedented level of cyber attacks, as hackers use AI-enhanced tools to launch phishing schemes, GPS jamming and spoofing and malware attacks
Shipping is in the crosshairs of hackers, cyber criminals and bad actors. Over the last six months of 2024, an unprecedented level of cyber attacks — 9Bn security events and 39Bn firewall events, 718,000 alerts and 10,700 malware incidents detected, and 50 managed major incidents — were aimed at shipping companies. These incidents covered everything from phishing schemes to disruptive GPS jamming and spoofing, to dangerous malware attachments. These incidents were tracked in a recent report compiled by Marlink, based on almost 2,000 vessels it monitors. And this troubling trend shows no signs of abating, with increasingly more sophisticated, complex and structured types of nefarious approaches, thanks to the use of AI-enhanced tools.
“In the cyber world, you have to keep up with the malicious players,” said Marlink, president, maritime, Tor Morten Olsen. During an interview at Nor-Shipping following the recent of the report, Mr Olsen said maritime cyber security preparedness varies greatly, with large shipowners like Mitsui OSK Lines (MOL), CGM CMA and others at the forefront, with smaller family-owned companies that “don’t see this as a problem”.
“You have to keep up with the malicious players”
But cyber attacks can have a crippling impact on a shipping operation, and even some shipping giants can fall prey. This June marked the eighth anniversary of one of the most severe malware attacks on shipping in recent memory. The NotPetya cyber attack knocked out the global operations of AP Moller-Maersk, one of the world’s largest ship operators, which controls about 15% of the global container shipping fleet. The malicious attack impacted Maersk’s IT operations, forcing the Danish shipping giant to shut down operations at 76 ports.
The commercial, operational and reputational implications for Maersk were staggering. Discussing its Q3 2017 results, Maersk reported a negative impact of US$250M-US$300M from the cyber attack, with a vast majority related to Maersk Line.
The rise of AI
And a lot has happened in eight years. Cybercriminals are enhancing their attacks using new AI tools, according to Marlink’s Security Operations Centre 2025 Global Maritime Cyber Threat report.
Hackers have used off-the-shelf large language models to accelerate malware development, automate phishing campaigns, and refine social engineering tasks.
Spoofing and jamming
Ships sailing through the Red Sea not only face the dangers of drone and missile attacks, but also increasing levels of GPS jamming and spoofing, according to Marlink. Jamming and spoofing GPS signals effectively remove position, navigation and timing information from the control of the ship’s navigators.
In July 2024, the Marlink help desk on average received one call every two weeks from clients concerned that their GPS was unavailable. By mid-July 2025, it received separate reports from more than 150 vessels in a single day.
One apparent victim of GPS jamming in the region was MSC Antonia. On 10 May, the 7,000-TEU container ship ran aground some 100 nm south of Jeddah. The United Kingdom’s Maritime Trade Operations unit posted a warning on 9 May of electronic interference in the Red Sea. It received several “corroborating reports from vessels experiencing GPS interference in the Red Sea... with disruptions lasting several hours, affecting navigation systems and requiring vessels to rely on backup methods.”
Threat activity
Marlink’s Service Operations Center monitors and actively protects onboard systems across a client’s fleet and corporate infrastructure connected to maritime operations. Among the findings in the report is that endpoint security on a vessel can be particularly vulnerable. Widespread use of unauthorised or pirated software, proliferation of hacking tools, unauthorised VPN software, and ransomware or espionage tools were all uncovered. There was even evidence of crypto-jacking — with some systems running crypto-mining malware to mine cryptocurrency. Crews and technical teams need to be educated and trained on safe software practices.
Maritime cyber regulations
Maritime cyber security falls within the ISM Code. Under an IMO resolution, an approved safety management system should consider cyber risk management in accordance with the objectives and functional requirements of the ISM Code.
At the 110th session of the Maritime Safety Committee held in June, delegates agreed to revise guidelines on maritime cyber risk management and identify the next steps to enhancing maritime cyber security.
Recommendations on cyber resiliency from the International Association for Classification Societies (IACS) apply to the use of computer-based systems, which provide control, alarm, monitoring, safety or internal communication functions that are subject to the requirements of a classification society. These recommendations apply to newbuilds but can also serve as guidance for existing ships.
“Regulations so far have focused mainly on newbuilds,” said Mr Olsen. “But there is a huge retrofit market that is not really covered within the current regulations. What we are doing is helping our clients to assess where they are compared to the standards, while providing them with solutions to bring them to a more secure level,” he said.
Reinforcing cyber security
To support shipping against evolving cyber threats, Marlink has bolstered its cyber security resources in the maritime sector through recent acquisitions. It acquired Diverto, an IT and OT security solutions provider, and Port-IT, a cybersecurity specialist with deep knowledge of the maritime sector, to form Marlink Cyber, which employs around 150 cyber security experts.
Mr Olsen explained the drive behind the acquisitions and the formation of Marlink Cyber was simple. While there are a host of generic cyber experts that serve shore-based companies, most “lack the understanding of the vessel operating environment”, he said. Marlink Cyber allows the company to have a “solid base of cyber experts, with maritime and enterprise knowledge to tailor solutions for that environment.”
Marlink’s solutions include endpoint detection, with over 2,500 activations, and managed services for small vessel owners. The company uses data analytics and ‘honeypots’ to monitor cyber threats.
Mr Olsen emphasised companies need “increased training and awareness starting in the boardroom, dripping down to seafarers. You need to have a holistic view, including both technology and the human element.”
Events
© 2026 Riviera Maritime Media Ltd.