Maritime Cyber Incidents, Reviewed
In one line:From Maersk crippled by NotPetya to a DNV ransomware hit affecting a thousand ships — a few public cases that show what maritime cyber risk actually looks like.
Key takeaways
- In 2017 NotPetya led Maersk to self-report USD 250–300M in losses, rebuilding ~4,000 servers and ~45,000 PCs.
- CMA CGM (2020) and DNV ShipManager (2023, ~1,000 vessels / 70 customers) were hit in turn.
- Many impacts land on IT / office networks, yet the outage still paralyses terminals and bookings.
- Every figure is from a public source; trend statistics are always named to their origin.
The incidents below are public and verifiable — named, sourced, checkable. The point of listing them is not alarm but calibration: when industry media cite figures like "up 900% in three years" or "the top maritime cyber threat is attacking the rudder," real case records give us a measuring stick.
A single thread runs through every incident that caused serious financial loss: attackers hit corporate IT networks or shore-based business systems — ERP, booking platforms, fleet-management SaaS, terminal scheduling — not shipboard control equipment. The movie scenario of "hackers remotely seizing the helm" has no confirmed documented case; "hackers encrypting an enterprise network and halting global bookings for ten days" has left a real bill of USD 250–300 million. That distinction is not a reason to downplay the threat — it is a guide to where defensive resources belong.
Common assumption
- Hackers "seize the rudder" remotely
- Attacks aim straight at ship controls
- Rare, cinematic
Usually in reality
- Office / business systems ransomed
- Bookings, terminals, scheduling halt
- IT outages still stop ships & ports
The benchmark: Maersk × NotPetya (2017)
On 27 June 2017, the NotPetya wiper swept the globe. The propagation chain has since been well established by security researchers and US intelligence: Russia's GRU military intelligence directorate, operating through the Sandworm group, implanted a backdoor in the update server of M.E.Doc — Ukrainian accounting software required by local tax authorities — and pushed a poisoned update to users worldwide that day. Because M.E.Doc was mandatory for companies doing business in Ukraine, the initial infection pool centred on multinationals with Ukrainian operations.
Maersk was collateral damage: a finance computer in its Odessa (Ukraine) office had M.E.Doc installed. Once NotPetya entered that machine, it exploited the EternalBlue vulnerability to move laterally across Maersk's global corporate network — at the time, 600 offices in 130 countries were connected in a flat, fully trusted network with minimal internal segmentation. According to Maersk Group Chairman Jim Hagemann Snabe at the 2018 Davos World Economic Forum, the full rebuild "would normally take six months" but was compressed to ten days through what he called a heroic effort by more than 40,000 employees.
During the incident, terminal operations across Maersk's 76 ports went dark, and container bookings and cargo tracking were halted for approximately ten days. CEO Soren Skou stated on Maersk's August 2017 earnings call that the estimated loss was **USD 250–300 million** — still the highest publicly disclosed financial loss from a single maritime cyber incident on record. Critically, Maersk's official communications stated that "all Maersk Line vessels were under control" and that crews were safe and vessels remained maneuverable throughout. NotPetya attacked corporate IT infrastructure — Windows endpoints, Active Directory domain controllers, ERP systems — with no confirmed impact on shipboard control systems.
The lesson here is twofold. First, the point of vulnerability is not necessarily where it is most expected — the entry point was a routine finance computer in an overseas office. Second, a flat enterprise network architecture lacking internal segmentation is the true amplifier that turns a localised infection into a global catastrophe.
- Maersk's own estimate (CEO Skou Aug 2017; Chairman Snabe Davos Jan 2018)
- $250–300MMaersk's own estimate (CEO Skou Aug 2017; Chairman Snabe Davos Jan 2018)
- servers rebuilt
- ~4,000servers rebuilt
- PCs rebuilt
- ~45,000PCs rebuilt
- of disruption
- ~10 daysof disruption
Note: that was IT, not shipboard OT
NotPetya hit Maersk's IT / business network, not shipboard control systems. Yet it remains the most famous "cost of a cyber incident" case in shipping — proof that an IT failure still stops ships and terminals. Maersk's official statement: "All Maersk Line vessels were under control." Shipboard OT was spared in part because onboard systems ran proprietary or legacy operating systems incompatible with the EternalBlue propagation path — some analysts characterised this as partly a matter of luck rather than deliberate design-level isolation.
Not a one-off
In the years following NotPetya, large shipping and port organisations suffered a series of cyber incidents sharing a consistent pattern: attacks landed on enterprise IT or shore-based software, with vessel operations largely unaffected.
**COSCO (July 2018).** On Tuesday 24 July 2018, COSCO's Americas network was struck by ransomware. Email servers and telephone networks went offline across the US, Canada, Panama, Argentina, Brazil, Peru, Chile, and Uruguay; customer service resorted to personal Yahoo email accounts. The specific ransomware variant was never officially identified. The Americas network recovered approximately five days later on 30 July. COSCO explicitly stated that "vessels were not impacted and main business operation systems were performing stably."
**CMA CGM (September 2020).** On 27 September 2020, CMA CGM was hit by Ragnar Locker ransomware, making it the fourth major container carrier to suffer a significant cyber incident following Maersk, COSCO, and MSC. The company proactively cut external IT access to contain the spread, and stated: "We suspect a data breach and are doing everything possible to assess its potential volume and nature." "Suspected data breach" is the company's own wording; the actual volume and scope were never officially confirmed. Maritime and port activities were described as "fully operational" throughout.
**IMO (October 2020).** The International Maritime Organization was not spared. Disruption began 30 September; on 2 October 2020 IMO confirmed a cyberattack, characterising it as "a sophisticated cyberattack against the Organization's IT systems that overcame robust security measures in place." The word "sophisticated" is IMO's self-description; the attack type — whether ransomware, DDoS, or other — was never publicly disclosed. As a regulatory and standards body with no operated fleet, the incident had no direct effect on vessel operations.
**DNV ShipManager (January 2023).** On 7 January 2023, DNV's ShipManager fleet management software was struck by ransomware. A detail that is easily misread: ShipManager is a **shore-based SaaS platform** used for fleet compliance management, maintenance scheduling, and technical documentation — it is not a navigational or control system aboard ships. DNV stated clearly that "the cyber-attack does not affect the vessels' ability to operate," with affected vessels retaining offline onboard functionality. Approximately 1,000 vessels across 70 customers were disrupted, out of a total ShipManager user base of over 7,000 vessels and 300 customers — roughly 14% of users affected. The ransomware group responsible has never been publicly identified.
**These four cases point to a structural pattern.** Shipping companies invest heavily in building and maintaining vessel OT systems, but the attacks that caused actual business interruption and financial loss have without exception landed on shore-based enterprise IT. The mismatch between defensive priority and actual threat location is the industry's genuine blind spot.
| When | Target | Type | Impact |
|---|---|---|---|
| 2018-07 | COSCO (Americas) | Ransomware | Americas office/comms down; vessels unaffected |
| 2020-09 | CMA CGM | Ransomware (Ragnar Locker) | Cut external apps; suspected data breach |
| 2020-10 | The IMO itself | "Sophisticated attack" | Public site & systems offline |
| 2023-01 | DNV ShipManager | Ransomware | ~1,000 vessels / 70 customers affected |
Widening the lens: ports, supply chains, and further incidents
Extending the view from container carriers to ports and software supply chains reveals the same attack pattern repeating.
**Port of San Diego (September 2018).** On 25 September 2018, the Port of San Diego suffered a SamSam ransomware attack that disrupted public records systems and port administrative services, prompting FBI and DHS involvement. Because the port's IT team maintained functioning backups, no ransom was paid and port shipping operations were unaffected throughout. Two Iranian nationals were subsequently indicted by the US Department of Justice for the SamSam campaign. The episode underlines the operational value of verified backup and recovery capability against ransomware.
**Port of Houston (August 2021).** On 19 August 2021, the Port of Houston's network was breached via the high-severity vulnerability CVE-2021-40539 in ManageEngine ADSelfService Plus. CISA Director Jen Easterly publicly stated: "I do think it is a nation-state actor." The intrusion was detected and contained rapidly; no operational data or systems were confirmed compromised — a successful near-miss. Its significance is that nation-state threat actors targeting port infrastructure are real, not hypothetical.
**K-Line (2021).** Japanese carrier Kawasaki Kisen Kaisha (K-Line) suffered two separate cyberattacks within a single year — one in March and one in July 2021 — both via its overseas affiliate networks. The July incident resulted in stolen data being published online. The company issued a public apology but disclosed minimal technical detail — a representative example of the maritime industry's disclosure culture. Both incidents were IT and data-side events, with no reported impact on fleet operations.
**ZPMC cranes (2024 congressional investigation).** This entry requires a strict distinction between established fact and open concern. ZPMC, a Chinese state-owned manufacturer, supplies cranes representing approximately 80% of cargo crane capacity at US ports — over 200 units. In March 2024, joint findings from the US House Homeland Security Committee and the Select Committee on the CCP stated that undocumented cellular modems not specified in contracts had been found on some cranes, and that ZPMC had repeatedly requested remote access to the equipment. ZPMC denied the allegations, stating the modems serve normal equipment-diagnostics purposes. **No publicly documented evidence of malicious use has been established.** This is an unresolved congressional supply-chain concern and should be treated as categorically distinct from confirmed attack incidents.
Not just IT: navigation has been touched too
The incidents above all involve IT or business-layer attacks. Disruption of navigation integrity represents a different threat model entirely — no ransom demand, no data breach, but false position signals carrying risks of collision, grounding, or inadvertent entry into restricted waters.
**Black Sea GNSS spoofing (June 2017).** At 07:10 GMT on 22 June 2017, a merchant vessel in the Black Sea reported that its GPS showed the ship's position as an inland airport, approximately 25 nautical miles from its actual location. A vessel master contacted the US Coast Guard Navigation Center by VHF radio, stating that more than 20 nearby vessels were reporting the same false fix. MARAD issued Maritime Advisory 2017-005a and a follow-up advisory 2017-006. Signal analysis pointed toward the Russian Black Sea coast, but no official attribution was ever formally published.
**C4ADS "Above Us Only Stars" (March 2019).** The think tank C4ADS published its report on 26 March 2019, covering data from February 2016 through November 2018. Across 10 locations including the Russian Black Sea coast, Crimea, and Syria near Russian military installations, the researchers documented **9,883 suspected spoofing instances** affecting **1,311 civilian vessel navigation systems**. The researchers noted that several spoofing episodes correlated in time and location with Vladimir Putin's travel schedule, proposing VIP protection as one possible motive.
GNSS spoofing and IT ransomware are categorically different threat types, and their countermeasures differ accordingly. Anti-spoofing defence relies on multi-source position redundancy (cross-checking radar, AIS, and inertial navigation), anomaly alerting, and crew awareness of the risks of single-source GPS trust. IMO's Navigation Safety Circular MSC-Circ.1609 has included this category of risk in bridge team training recommendations.
- 2017-06NotPetya / Maersk
- 2018-07COSCO
- 2020-09CMA CGM
- 2020-10IMO
- 2023-01DNV ShipManager
Ransomware economics: who pays, and how much
The March 2022 report "The Great Disconnect," jointly published by CyberOwl, Thetius, and HFW (Herbert Smith Freehills), is among the broader maritime cybersecurity surveys to date, based on responses from more than 200 industry professionals. It found that only **3%** of attacked organisations ultimately paid a ransom; among those that did pay, the average payment was **USD 3.1 million**.
Two layers of context are essential when reading these numbers. First, a 3% payment rate means the large majority of attacks either did not generate a ransom demand or were met with refusal. This low payment rate partly reflects growing industry resilience, and partly the compliance risk dimension: in certain jurisdictions, paying a ransom to a sanctioned entity may itself constitute a legal violation, and maritime legal counsel is increasingly involved in early-stage incident response decisions regarding the OFAC sanctions compliance implications. Second, USD 3.1 million is a **self-reported survey figure**, not an insurance-claims database or regulatory filing; the sample is self-selected and covers only those willing to disclose. CyberOwl, Thetius, and HFW's 2023 follow-on report "Shifting Tides, Rising Ransoms" revised the figure upward to USD 3.2 million — "up from USD 3.1 million last year" — indicating an escalating trend.
The correct way to cite this data is: "According to CyberOwl, Thetius, and HFW's 2022 'Great Disconnect' report (200+ industry respondents), among those who paid ransom, the average payment was USD 3.1 million; only 3% of attacked organisations reported paying." It should not be presented as an industry-wide average ransom figure.
The numbers trap: why "up 900%" statistics mislead
Figures on "how many times attacks have grown" are quoted in extremely loose ways in the industry press. The most common example is the "up 900% in three years" claim — this originates from Israeli maritime OT security vendor Naval Dome, stated by its Head of North American Operations Robert Rizika at the 2020 AAPA Port Security Seminar and Expo. The underlying data: 50 maritime OT attacks in 2017, 120 in 2018, 310 in 2019 — a cumulative three-year increase of roughly 900%. The figure was widely reprinted by maritime trade media without scrutiny.
It carries at least four methodological problems. **First, small-number percentage arithmetic:** the absolute increase from 50 to 310 is 260 incidents across an industry of 50,000-plus commercial vessels — a very low absolute rate, but percentage expression creates the visual impression of explosive growth. **Second, undefined terms:** Naval Dome did not publish its counting methodology. The definition of "attack" could span anything from failed scanning probes to confirmed breaches, and the width of that definition directly determines the number. **Third, commercial interest:** Naval Dome sells maritime OT security products and has a commercial incentive for the market to perceive the threat as severe. This does not mean the figures are fabricated, but it does mean citing them without attribution is a lapse of editorial responsibility. **Fourth, neutral alternatives exist for comparison:** the EU Agency for Cybersecurity (ENISA) publishes a regularly updated Maritime Cyber Threat Landscape report, which — while itself subject to scope limitations — is produced without direct commercial interest in the outcome.
A deeper structural problem underlies all incident-count statistics: most shipping companies do not publicly disclose cyber incidents. The COSCO ransomware variant remains unknown; K-Line's two 2021 attacks yielded almost no technical disclosure; CMA CGM's data breach scope was never confirmed. "The Great Disconnect" itself noted that many companies do not report incidents internally, let alone to regulators. This means that every "growth in incidents" statistic is built on a denominator of unknown size — a fact that should inform all quantitative claims about maritime cybersecurity trends.
A solid source, Thetius/CyberOwl/HFW's "The Great Disconnect" (2022), reports that where a ransom was paid, owners paid about USD 3.1 million on average; whereas oft-quoted figures like "up 900% over three years" come from a single vendor (Naval Dome) and should be named rather than treated as neutral fact.
The takeaway
Most of these could have been blunted by fundamentals: change default passwords, segment networks, keep audit logs, back up and test recovery. E26/E27 turned these fundamentals from voluntary into hard requirements for new-builds. Supply-chain risk (the DNV case) and navigation integrity risk (the Black Sea spoofing case) signal that the defensive perimeter extends beyond the ship itself — to software vendor selection, contractual security clauses, and the system design of multi-source position redundancy.
Sources
- Maersk NotPetya cost ~$250–300M (CEO Skou earnings call) — Supply Chain Dive · 2017-11
- Maersk at Davos: rebuilt ~4,000 servers, 45,000 PCs, 2,500 applications — BleepingComputer · 2018-01-26
- Maersk at Davos — primary account (The Register) — The Register · 2018-01-25
- NotPetya technical origin: M.E.Doc update chain, Sandworm / GRU attribution — Control Engineering (Throwback Attack series) · 2021
- COSCO cyberattack response timeline (began 2018-07-24, ~5-day recovery) — Supply Chain Dive · 2018-07-25
- CMA CGM official IT update (2020-09-29) — CMA CGM Group · 2020-09-29
- CMA CGM hit by Ragnar Locker — BleepingComputer · 2020-09
- IMO hit by "sophisticated cyberattack" (confirmed 2020-10-02) — SecurityWeek · 2020-10-02
- DNV ShipManager ransomware impacts ~1,000 vessels / 70 customers — SecurityWeek · 2023-01-17
- Port of San Diego SamSam ransomware attack (2018-09-25) — Seatrade Maritime · 2018-09
- Port of Houston nation-state intrusion attempt (CVE-2021-40539, thwarted) — SecureWorld · 2021-09
- K-Line apologises for second cyberattack in 2021 (July) — Maritime Executive · 2021-07
- US Congressional investigation: ZPMC cranes, undocumented cellular modems — The Record (citing House committee report) · 2024-09
- Black Sea GPS spoofing: what really happened (MARAD 2017-005a / 2017-006) — GPS World · 2017-08
- "Above Us Only Stars" GNSS spoofing report (9,883 instances / 1,311 vessels) — C4ADS (Center for Advanced Defense Studies) · 2019-03-26
- "The Great Disconnect" (avg ransom $3.1M; only 3% paid) — IIMS summary of CyberOwl / Thetius / HFW (March 2022) · 2022-03
- Naval Dome "maritime OT attacks up 900% in 3 years" (single-vendor data, methodology undisclosed) — WorkBoat (citing Naval Dome / AAPA 2020) · 2020
Share this asset
Share this asset
https://www.haishide.com/en/resources/maritime-cyber-incidents-reviewed
This asset's reading of IACS UR E26/E27 is for reference only; formal compliance requirements and classification are decided by the class society.

