- Joined
- Jan 22, 2026
- Messages
- 101
- Reaction score
- 916
Why hackers are now attacking not company offices, but ship management systems.

Cyber attacks on ships have ceased to be a rarity and are increasingly leading to real disruptions in the fleet. Over the past two years, the attackers have noticeably increased their activity, and their tools have become more complex. This is stated in a new report by CYTUR.
The authors analyzed the incidents of 2024 and 2025, based on data from their own CYTUR-TI maritime threat intelligence system, and tried to predict what the threat landscape will look like in 2026. According to their estimates, the number of vulnerable points is growing almost exponentially. The reason is simple: ships are increasingly connecting satellite communications and digital services, which expands the attack surface.
The most disturbing change is related to ransomware, which now targets not only office networks, but also shipboard control systems. Previously, attacks were mostly limited to information systems. Now, attackers are infiltrating operational technologies that control, for example, the ballast water system or engine monitoring. As a result, ships are stopped, and companies have to urgently restore control over the equipment.
Attacks on supply chains in the maritime industry pose a particular danger. Dozens of software solutions and devices from different manufacturers are installed on board the modern vessel. If the attackers find a gap in one of these components, the consequences can affect dozens of vessels at once. In fact, one vulnerability can paralyze an entire fleet.
The report also describes cases of attacks on the marine satellite communications infrastructure. We are talking about the forgery of data and commands transmitted via satellite channels. Attackers are trying to exploit gaps in the protection of satellite lines to send fake commands or distort information about the vessel and its equipment.
CYTUR calls 2026 the "first year of practical verification." After the requirements of the International Association of Classification Societies, known as UR E26 and UR E27, come into force, the formal approach to cybersecurity will no longer work. These regulations became effective in July 2024, and ships ordered after that date are already under construction, taking into account the new rules. If non-compliance with the requirements is revealed during sea trials and certification, the vessel will simply not be handed over to the customer.
The authors of the report expect that attackers will actively use artificial intelligence technologies to find weaknesses and circumvent regulatory requirements. In these circumstances, not only protection as such comes to the fore, but also the ability to quickly restore work after an incident. The company calls this cyber resilience and considers it a key condition for maintaining the ship's right to go to sea.

Cyber attacks on ships have ceased to be a rarity and are increasingly leading to real disruptions in the fleet. Over the past two years, the attackers have noticeably increased their activity, and their tools have become more complex. This is stated in a new report by CYTUR.
The authors analyzed the incidents of 2024 and 2025, based on data from their own CYTUR-TI maritime threat intelligence system, and tried to predict what the threat landscape will look like in 2026. According to their estimates, the number of vulnerable points is growing almost exponentially. The reason is simple: ships are increasingly connecting satellite communications and digital services, which expands the attack surface.
The most disturbing change is related to ransomware, which now targets not only office networks, but also shipboard control systems. Previously, attacks were mostly limited to information systems. Now, attackers are infiltrating operational technologies that control, for example, the ballast water system or engine monitoring. As a result, ships are stopped, and companies have to urgently restore control over the equipment.
Attacks on supply chains in the maritime industry pose a particular danger. Dozens of software solutions and devices from different manufacturers are installed on board the modern vessel. If the attackers find a gap in one of these components, the consequences can affect dozens of vessels at once. In fact, one vulnerability can paralyze an entire fleet.
The report also describes cases of attacks on the marine satellite communications infrastructure. We are talking about the forgery of data and commands transmitted via satellite channels. Attackers are trying to exploit gaps in the protection of satellite lines to send fake commands or distort information about the vessel and its equipment.
CYTUR calls 2026 the "first year of practical verification." After the requirements of the International Association of Classification Societies, known as UR E26 and UR E27, come into force, the formal approach to cybersecurity will no longer work. These regulations became effective in July 2024, and ships ordered after that date are already under construction, taking into account the new rules. If non-compliance with the requirements is revealed during sea trials and certification, the vessel will simply not be handed over to the customer.
The authors of the report expect that attackers will actively use artificial intelligence technologies to find weaknesses and circumvent regulatory requirements. In these circumstances, not only protection as such comes to the fore, but also the ability to quickly restore work after an incident. The company calls this cyber resilience and considers it a key condition for maintaining the ship's right to go to sea.