CHINA-linked hackers showed a “consistent focus” on the maritime sector in 2025, a new report published by the EU has revealed.
The European Union Agency for Cybersecurity’s Threat Landscape 2026 report showed that shipping is increasingly finding itself in the crosshairs of online intruders.
That’s not always been the case. CyberOwl strategic adviser (and then chief executive) Daniel Ng told Lloyd’s List in November 2024 that the industry, by and large, was not a “targeted sector”. Fast forward to August last year, and he told Lloyd’s List that assessment was “a bit more tentative”.
Now the ENISA report suggests that the maritime industry is a clear target. Transport as a whole was the target of 11.7% of identified attacks in the EU last year, while “water transport” made up 16.4% of those attacks.
Shipping, along with the rail industry, is particularly vulnerable as both rely on “heterogenous systems”, ie, a diverse range of operating systems and equipment.
An earlier ENISA report explains this even further. As the maritime sector becomes more digitalised, it said, there is a tendency to link newer digital tools with legacy systems built to last, which might not be as secure as alternatives today.
As a result, cyber-attacks on shipping — unlike those on road or rail transport, which are often more localised in their impact — can spread quickly and “destabilise global supply chains”, the report said.
The majority of attacks, the report found, were so-called distributed denial of service attacks. These happen when a company’s servers are bombarded with requests, often from a network of compromised devices, which are then overloaded and unable to function.
Unauthorised intrusion, perhaps mostly commonly associated with “hacking”, made up just 16.3% of attacks.
What ENISA calls “state-nexus” activity, or largely state-aligned or state-linked, was largely linked to cyber espionage and strategic intelligence collection, the report said.
Maritime organisations were targeted by one China-nexus in particular: Mustang Panda.
The group conducted “continuous campaigns”, ENISA said, impacting at least seven EU member states.
Mustang Panda used two main routes of entry. The first was “spear phishing”, which uses personalised approaches, usually in the form of emails, to lure an individual into divulging information or installing malware.
The other entry route was compromised USB devices, which shipping showed particular vulnerability. Critical information that needs to be transferred from device to device on board a vessel, often varying greatly in age, is still done by USB devices.
There can be quite large disconnect between shoreside cyber analysts and the crew they are often training or advising. Techniques that work in an office, such as banning USB drives outright or scanning attachments, do not always work at sea.
Equally, as the University of Plymouth’s Professor Kevin Jones told the Lloyd’s List podcast, telling a crew to step away and do nothing while a shoreside team runs an analysis is likely to be met with resistance, especially if the vessel is due in port soon.
Looking ahead, the ENISA report suggests the threat level is unlikely to decrease. Geopolitical developments are likely to remain a major driver of cyber activity, it said.
“Throughout the reporting period, disruptive and cyber-espionage campaigns frequently coincided with political developments, public statements or high-visibility events.”
This is likely to continue, ENISA suggested, as cyber operations offer a relatively low-cost way of signalling intent and applying pressure “without crossing the threshold of conventional conflict”.
Perhaps more worryingly, ENISA said AI will only accelerate the trend.
AI is already helping attackers amplify existing capabilities, but the technology could eventually automate the entire cyber kill chain, from identifying targets to executing attacks, it said.
Shipping emerges as prime cyber target for China-linked hackers
Transport sector was targeted by nearly 10% of cyber-attacks in the EU last year

Source: Lloyd's List
Related articles

Company newsKuehne+Nagel and CATL partner to advance battery logistics and fleet electrification
Sea newsLandside bottlenecks, not ships, are the real constraint says Maersk, as Red Sea return gathers pace
Sea newsShipping’s battery blindspot: boxships put at risk of fire by regulation gap
Sea newsMaritime AI gains momentum, but digital foundations remain unstable
Sea newsShipping stands on cusp of ‘something extraordinary’, says Frangou
Sea newsCosco turns to LNG for 18,000 teu newbuilds in $2.7bn boxship spree
