U.S. government agencies are tracking cyber threats to nearly 20 ships around the world

📅 2026-09-17

Abstract:

According to U.S. officials familiar with the situation, U.S. government agencies are tracking cyber threats to nearly 20 ships around the world. Three people who spoke on condition of anonymity because they were not authorized to discuss the matter publicly said the U.S. Coast Guard has required advance notice if any of the ships planned to enter a U.S. port. The specific destinations and cargo lists of these ships are currently unclear.

An official from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) said that several commercial ships were targeted by potential cyberattacks at the end of August, and pointed out that hackers did not appear to have actually gained control of the ships. A Department of Homeland Security official said the Coast Guard is currently working with the FBI and relevant departments of the Department of Homeland Security to track the ships.

In recent years, warnings of cyberattacks against the maritime industry have escalated as ships have become increasingly reliant on digital systems for navigation, communications and other operations. Governments and security researchers have repeatedly warned that hackers are trying to exploit these systems to disrupt global supply chains. Cyber ​​risks are emerging as a new challenge for the global shipping industry, already under pressure from war and geopolitical competition.

The U.S. Coast Guard said in a statement that it boarded two foreign merchant ships bound for the United States in the Gulf of Mexico to "ensure the integrity of the ship's operating systems and information technology systems" after there were signs that the networks of both ships had been compromised. The first ship was inspected on August 21 and the second on August 24.

The Coast Guard said: "There are currently no operational disruptions, ship instability, threats to crew safety, or environmental impacts." The agency added that it is maintaining close communication with port operators, shipowners and other stakeholders.

Antonio Cassidy, director of services at London-based maritime cybersecurity firm CyberOwl, said he has seen no signs of a large-scale hacking campaign targeting oil and gas carriers. However, CyberOwl has monitored a significant increase in the number of ship cybersecurity incidents in the first half of this year.

According to the company's report, more than half of the network intrusion attempts discovered by its tracking ships involved the insertion of malware into the ship's computer system through storage devices. Most of the rest come from Internet downloads or phishing attacks.

In December, European investigators suspected that Russian military hackers may have been involved in a cyber attack on Mediterranean Shipping Company (MSC) ships. According to media reports at the time, the ferry, operated by Grandi Navi Veloci, a subsidiary of MSC, was originally scheduled to sail to Algeria, but was forced to be stranded in the port of Sète in southern France.

Cybersecurity company Cydome stated that in March 2025, a hacker group called Lab Dookhtegan claimed responsibility for a cyber attack that disrupted the communication systems of more than 100 Iranian oil tankers.

Maria Bartnes, director of cybersecurity research projects at Norwegian cybersecurity company DNV, said that ship operation control systems are particularly vulnerable to cyber attacks because they contain a large number of old equipment that are difficult to update. Most of these systems were born in an era when the threat of cyberattacks was not yet prominent.

She said the purpose of such intrusions may be to create uncertainty and instability rather than causing actual damage.

“This is part of war in itself,” she said, “by making it impossible for the adversary to determine what is going on. Whether it is the country, the politicians, or the people working on the ship, it can be affected.”

Related tags

Related articles

Comments

0/500
Captcha (click to refresh)
No comments yet