Since the 2017 A.P. Møller-Maersk NotPetya attack, cyber incidents have become one of the highest-cost operational risks in shipping. Every major cyber attack has driven regulatory reform (IMO Res. MSC.428(98) 2017, IACS UR E26/E27 mandatory 2024) + industry practice change (segregated IT/OT networks, offline navigation backups, incident response drills). This reference catalogs the significant public cyber incidents in the maritime sector + their operational + regulatory lessons.
The defining modern maritime cyber incident. The NotPetya wiper (Russian GRU-attributed, disguised as Petya ransomware) propagated through the Ukrainian tax accounting software M.E.Doc into Maersk's global network on 27 June 2017. Within hours all Maersk global email, port terminal management, container tracking + booking systems went dark. ~4,000 servers + ~45,000 workstations required complete rebuild. Total commercial loss estimated at $250-300 million. Ships continued to sail (bridge systems isolated) but shore-side chaos disrupted container flows for 2+ weeks. Chairman Jim Snabe famously cited a coincidentally-offline Ghana office domain controller that survived to speed the recovery. Maersk NotPetya became the definitive modern case for IT/OT segregation, offline domain controller backup, and immutable-backup disaster recovery.
COSCO Americas offices suffered a ransomware attack affecting Long Beach + other US terminal operations. Response was rapid (~5 days to full recovery) — largely credited to network segmentation put in place after Maersk NotPetya. Case demonstrates the industry's post-Maersk learning curve.
MSC HQ Geneva suffered a network outage attributed to an internal malware infection. Booking systems + tracking down for 5 days at peak COVID cargo-flow crisis. MSC (privately-held) never confirmed ransomware attribution but industry consensus + insurance-market chatter placed it in the ransomware category. Notable for demonstrating that even major post-Maersk shipping companies still face substantial cyber-incident exposure.
CMA CGM confirmed a ragnar-locker ransomware attack affecting shore-based IT + booking + eBusiness portals. Vessel operations continued but shore-based systems down for ~2 weeks. CMA CGM disclosure was more transparent than MSC + INTL Maritime Bureau + industry associations subsequently issued heightened alert.
USCG issued Maritime Safety Alert 06-19 (July 2019) documenting a cyber incident affecting a deep-draft vessel bound for Port of New York/New Jersey. Malware disabled the ship's network + shore-communications; navigation continued via GPS + ECDIS but administrative + business systems down. USCG required vessel to implement measures before further US port calls — the first US enforcement action on maritime cyber.
India's largest container terminal suffered a ransomware attack disrupting container gate operations for 24-48 hours. Impact was contained by terminal automation redundancy but the incident demonstrated the sector-wide risk to critical port infrastructure. Indian CERT-In advisories subsequently strengthened maritime cyber-security-audit requirements.
One of the most disruptive port cyber attacks to date. DP World Australia (operator of ~40% of Australian container throughput) suffered a ransomware attack on 10 November 2023 that forced closure of Melbourne + Sydney + Brisbane + Fremantle container terminals for ~4 days. ~30,000 containers stranded on quay. Attributed to a Russian threat actor. Case became the definitive modern example of port cyber attack impact on national supply chain + drove Australian Government Critical Infrastructure Security Act 2018 amendments tightening port operator cyber requirements.
Japan's largest port terminal management system (UTMS) was affected by LockBit 3.0 ransomware. Container operations halted for 3 days. Case exposed the concentration risk of common port-terminal-management-system software across multiple ports.
Post-2020, the risk shifted from headline-grabbing megacarrier attacks to persistent lower-visibility attacks on smaller operators + specialised operators. IUMI + P&I clubs report a consistent 20-30% year-over-year increase in reported maritime cyber incidents 2020-2024, with the median incident affecting a small-to-mid operator + producing $1-5M loss + 5-14 days operational disruption.
Last verified