Home / Industries / Cruise Lines and Maritime

Transportation Systems · Maritime · Cruise lines and fleets

Shipboard OT security, from the satcom link down to the propulsion drives.

A cruise ship runs a power plant, a bridge, life safety systems, and a hotel on one hull, and on many ships they share one satcom link to shore. Red Tiger Security assesses shipboard OT and IT without putting the ship at risk. The walk starts where the ship touches the outside world: satcom, shore connections, OEM remote access, and the hotel and guest networks. Then it works down to the field devices: propulsion drives, power management, ballast, fire detection, and watertight doors. After the assessment the team fixes what is hurting operations now. If you want Red Tiger to stay, the close is 24x7 MSP + Metrics and Reports.

White cruise ship at sea on a bright, calm day
As many as one a dayShips being hacked, as an industry webinar heard in 2021. Reported by Lloyd's List under the headline "One ship is hacked every day on average" (D. Osler, July 6, 2021). An estimate, not a count. [7]
1,295Maritime cyber incidents recorded in 2025, up from 716 in 2024. About 7 in 10 were hacktivist DDoS. Counts organizations, not only ships. [8]
~1,000 a dayGPS disruption incidents in 2025, with over 40,000 vessels affected (Cydome). MARAD warns of GNSS spoofing around the Strait of Hormuz. [9,23]
~60%Of the sites and vessels Marlink assessed relied on shared IT/OT infrastructure that was poorly documented and poorly secured. [10]

2017 to 2026: shipping, ports, navigation, and now ships at sea

Every event below comes from public filings, regulator decisions, company statements, or named press reports. Over these years the targets moved from shoreside IT and guest data toward terminals, satcom, and navigation. The cruise-line events were IT and guest-data incidents, not shipboard OT.

2017201820192020202120222023202420252026SHIPPING AND CRUISEPORTS AND REGULATION123456789101112131415161718
Numbered markers match the cards below. Upper track: shipping and cruise. Lower track: ports and regulation.
1June 2017Shipping

Maersk: NotPetya

Malware hit Maersk Line, APM Terminals, and Damco. Maersk put the impact at USD 200 to 300 million. [11]

2Nov. 2017Shipping

Clarksons

The shipbroker was breached through a single user account; data was copied and a ransom demanded. [12]

3July 2018Shipping

COSCO

Ransomware took COSCO's IT systems down for weeks. [13]

4April 2019Cruise

Royal Caribbean Cruises (Asia)

An attack on a vendor-hosted receipt system deleted the database and left a ransom note. 6,004 customers affected; Singapore's PDPC fined the company S$16,000. [14]

5March 2020Cruise

Norwegian Cruise Line

A travel agent portal was breached, exposing about 27,000 agent emails and passwords. NCL said no guest, employee, or payment data was involved. [15]

6April 2020Shipping

MSC

Malware brought down MSC's data center for days. [13]

7Aug. 2020Cruise

Carnival Corporation

Ransomware encrypted part of one brand's IT systems and data files were downloaded, disclosed in an SEC Form 8-K. [16]

8Sept. 2020Shipping

CMA CGM

Ransomware cut external access; e-commerce was fully back Oct. 11. All four of the largest container lines had now been hit. [18,13]

9Dec. 2020Cruise

Costa Crociere (Carnival)

Ransomware encrypted Costa systems; files with passport numbers and dates of birth were downloaded. [17]

10June 2022Cruise

NYDFS penalty: Carnival

USD 5 million for four cybersecurity events in 2019 to 2021, including two ransomware attacks. NYDFS cited gaps in MFA, reporting, and training. [17]

11July 2023Ports

Port of Nagoya

LockBit ransomware hit the system that runs all five container terminals. About three days to recover. [19]

12Nov. 2023Ports

DP World Australia

Landside operations at four Australian ports were suspended after unauthorized access. [20]

13Aug. 2024Ports

Port of Seattle

Rhysida ransomware. The Port refused to pay. [21]

14March 2025Shipping

116 Iranian-owned ships lose satcom (claimed)

Hacktivists claimed they cut VSAT links to 50 tankers and 66 cargo ships through their satcom provider. [8]

15May 2025Shipping

MSC Antonia grounding

The container ship ran aground in the Red Sea; GPS interference was blamed. [22]

16July 2025Regulation

USCG cyber rule in force

33 CFR 101 Subpart F takes effect. Reportable cyber incidents go to the National Response Center. [24]

172025Shipping

Navigation electronics supplier

Rhysida hit a major Japanese maker of radar, ECDIS, and voyage data recorders. [8]

18Aug. 2026Shipping

Two U.S.-bound tankers boarded

Coast Guard and FBI teams board two foreign-flagged tankers in the Gulf of Mexico. See below. [1,2]

The Gulf of Mexico tanker boardings

What U.S. officials confirmed, and what is still unconfirmed.

Sequence of events

  • Aug. 1: The first tanker departs Egypt's Sidi Kerir terminal for Galveston, per public vessel data. [2]
  • UnconfirmedAug. 7: Iran's Mehr News says the ship was attacked near Gibraltar and lost communications for 30 hours. U.S. officials say it slowed near Gibraltar around that time. [2,3]
  • Aug. 21: Coast Guard law enforcement, a vessel inspector, the Coast Guard Cyber Protection Team, and FBI Cyber Action Team operators board in the Gulf of Mexico and stay aboard four days. [1,2]
  • Aug. 24: A similar team boards a second foreign-flagged vessel. [1,6]
  • Sept. 15 to 16: The Coast Guard confirms the Aug. 21 boarding; a joint Coast Guard and FBI statement follows. [3,1,4]
Officer at the bridge console of a ship, sea beyond the windows

Confirmed by U.S. officials

  • Indications that both vessels' networks were compromised; the boardings checked OT and IT systems. [1]
  • Investigators found malicious cyber activity. [2]
  • No reports of operational disruption, vessel instability, danger to crews, or environmental impact. [1,4]
  • Reported, not officially named: CBS News identifies the first vessel as the VL Prosperity, a Liberian-flagged crude carrier bound for Galveston. [2,3]

Not confirmed as of mid-September 2026

  • Who did it. Investigators are looking at whether Iran or another actor was involved. [2,6]
  • UnconfirmedIranian media claims of access to engine room, propulsion, navigation, and cargo systems. [2,3]
  • Whether the two incidents are connected. [2]
  • The second vessel's name. Reuters noted the Coast Guard and FBI accounts differed in detail. [5]
"The real thing we're concerned about is those IT systems being connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel."Rear Adm. Amy Grable, Commander, U.S. Coast Guard Cyber Command, to CBS News [2]

Why it matters for cruise: Grable told CBS the barrier to tampering with shipboard machinery is "not necessarily that sophisticated," and pointed to network segmentation, phishing, and basic cyber hygiene. A cruise ship carries the same propulsion and navigation systems, plus thousands of guests and a large hotel network. [2] The first step is an independent, ship-level assessment of the IT to OT boundary, done plant-safe, so you know where each ship stands.

What runs a cruise ship

Four groups of systems share one hull, and on many ships they share one satcom link to shore.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 bowazipods
Simplified drawing; the layout varies by ship class and builder.
1Integrated automation (IAS), engine control room
2Power management, main switchboard
3Diesel generators
4Propulsion motors, azipods
5Ballast and stability
6Fuel tanks and transfer
7HVAC plant
8Water, wastewater, AWP
9Bridge: ECDIS, radar, autopilot
10Mast: radar scanners, GNSS, AIS
11Bow thrusters, DP
12Emergency generator
13Lifeboats, muster stations
14Fire detection, watertight doors, PA/GA, CCTV (ship-wide)
15Satcom: VSAT and LEO
16Hotel IT: PMS, POS, Wi-Fi, cashless and guest ID
17Data center, crew networks
18Medical center

OT and control

Integrated automation system (IAS), power management and diesel-electric propulsion, azipods, engine control, ballast and stability, HVAC, fuel, water, wastewater, and AWP.

Navigation and bridge

ECDIS, radar, GNSS, AIS, autopilot, voyage data recorder (VDR), dynamic positioning (DP), and thruster control.

Life and safety

Fire detection and suppression, watertight doors, emergency power, PA/GA, muster systems, lifeboat systems, and CCTV.

Critical IT

Hotel property management (PMS), point of sale, guest Wi-Fi, crew networks, satcom, medical systems, cashless and guest ID, reservations, and shore connectivity.

Every critical system, and why it matters

What a compromise could mean, system by system. Open a group to see each system and where assessment, remediation, and monitoring apply. What fits depends on how each ship is built and connected.

ARM  Core serviceARM  Dashed: where it fits the ship and the riskA Assess · R Remediate · M Monitor
Propulsion4 systems
Diesel-electric gensets. Tripped or desynced generator controls can black out the ship.
ARM
Propulsion motors and azipods. Loss of thrust or steering force, often in tight harbor waters.
ARM
Propulsion control. Bridge and ECR commands to the drives could be blocked or changed.
ARM
Bow and stern thrusters. Needed for docking; a failure risks hitting the pier.
ARM
Steering4 systems
Steering gear. Lost rudder or pod commands means no control of heading.
ARM
Autopilot and track control. A changed track or setting can walk the ship off course quietly.
ARM
DP and joystick control. Bad position or thruster data can push the ship off station.
ARM
Stabilizers. Faulty fins affect stability and guest safety in heavy seas.
ARM
Power and utilities12 systems
Power management system. Runs load sharing and breakers; misuse can cause a blackout.
ARM
Main and emergency switchboards. Remote breaker operation can cut power to whole zones.
ARM
Emergency generator. If it will not start, safety systems lose power in a blackout.
ARM
HVAC. Also handles smoke control; failures hit guests, galleys and data rooms.
ARM
Potable water. Treatment and dosing faults are a public health problem at sea.
ARM
AWP and wastewater. Discharge faults can mean environmental violations and fines.
ARM
Fuel systems. Tampered transfer or purifier control risks spills or engine damage.
ARM
Ballast and stability. Wrong tank transfers can put a list on the ship.
ARM
Bilge. Bilge alarms and pumps are the first line against flooding.
ARM
Refrigeration and cold rooms. Lost temperature control can spoil provisions for a voyage.
ARM
Shore power. A fault in the connection controls drops power alongside.
ARM
Emissions scrubbers. Their data backs environmental compliance reports.
ARM
Life and safety6 systems
Watertight doors. Doors that will not close, or close without warning, risk flooding and injury.
ARM
Emergency lighting. Guides thousands of people to muster stations in a blackout.
ARM
PA/GA. The main way to alert people; a silenced or false alarm causes confusion.
ARM
Muster and passenger counting. Wrong counts slow an evacuation and the search that follows.
ARM
Lifeboat davits. Launch controls must work on demand and never by accident.
ARM
Safety management system. Drills, records and procedures lost or altered.
ARM
Fire and gas5 systems
Fire detection. Suppressed alarms delay response; false ones trigger needless evacuations.
ARM
Sprinklers and hi-fog. Pump and valve controls must work the moment they are needed.
ARM
Gas detection. A missed alarm in machinery or galley spaces risks explosion or injury.
ARM
CO2 and fixed suppression. Release controls are life-critical for anyone in the space.
ARM
Fire doors and dampers. Hold back fire and smoke; a remote release or block defeats them.
ARM
Navigation7 systems
ECDIS. An altered chart or position can lead to a grounding.
ARM
Radar and ARPA. The targets and collision warnings the watch officer relies on.
ARM
GNSS. Jamming or spoofing feeds a false position to every system that uses it.
ARM
AIS. False or missing targets; spoofing is common in some regions.
ARM
Gyro compass. Heading feeds the autopilot, radar and ECDIS.
ARM
VDR. The ship's black box; evidence after an incident.
ARM
BNWAS. Checks that the watch officer is alert; disabled means no backup.
ARM
Communications6 systems
GMDSS. Distress and safety communications must work when everything else fails.
ARM
VSAT and LEO satcom (e.g. Starlink). The main path in for remote attackers and for OEM access.
ARM
VHF radio. Bridge-to-bridge and port communications.
ARM
Internal phones. Crew coordination during an emergency.
ARM
Crew and guest Wi-Fi. Thousands of untrusted devices to keep apart from ship systems.
ARM
Shore connection. In-port network links to terminal and corporate systems.
ARM
Monitoring and control2 systems
IAS and alarm monitoring (AMS). Thousands of alarms and controls; the ship's nervous system.
ARM
OEM remote maintenance access. Trusted remote links are what attackers look for first.
ARM
Security and access3 systems
CCTV. Cameras are often network-exposed and used as a foothold.
ARM
Key card and door access. Controls who can reach the bridge, ECR and crew areas.
ARM
Gangway screening. ID checks and screening at embarkation.
ARM
Hotel and guest7 systems
Property management (PMS). Guest records, folios and passport data.
ARM
Point of sale. Payment card data in PCI DSS scope.
ARM
Cashless and guest ID. Cards or wearables tie identity, payments and door access together.
ARM
Casino. Regulated gaming systems and cash handling attract attackers.
ARM
Entertainment and stage rigging. Automated rigging moves heavy loads over performers and guests.
ARM
Galley equipment. Connected cooking equipment is a fire risk if controls fail.
ARM
Elevators and escalators. Passenger safety and evacuation routes.
ARM
Deck machinery1 system
Mooring and anchor winches. Unexpected movement under load can injure crew.
ARM
Medical2 systems
Medical center systems. Patient records and connected medical devices.
ARM
Telemedicine. Links to shoreside doctors ride on satcom and must stay private.
ARM
Crew devices and IoT2 systems
Crew phones and laptops. Marlink found 82% of detected alerts in crew network zones. [10]
ARM
IoT sensors. Many small, rarely patched sensors across the ship.
ARM

IT and OT on a ship, and why OT risk is different

Information technology (IT) is the email, reservations, payments, and Wi-Fi side of the ship. Operational technology (OT) is the automation that runs engines, power, steering, ballast, and safety systems. They were built by different people for different reasons, and on many ships they now share the satcom link to shore.

When IT fails, the operator loses data. When OT fails, the ship can lose power or steering with thousands of people on board. That is why OT cannot run on the same patch cycle and scanning tools as the office, and why the assessment stays passive on live shipboard systems.

Ship ITShip OT
What matters mostProtect the data: confidentiality firstKeep the ship safe and running: safety and availability first
Life span3 to 5 years, then replaceOften the life of the ship; refits come years apart
PatchingMonthly, often automaticNeeds OEM approval and a safe window, often in a yard or dry-dock period
Who owns itIT department, shoresideChief engineer, captain, and the OEM or integrator
When it failsData loss, outage, finesBlackout, loss of propulsion or steering, fire or flooding risk
Remote accessCorporate VPNOEM and integrator support links over satcom

How a typical ship network hangs together

Shoreinternet, OEMs SatcomVSAT / LEO firewall Guest Wi-Fi, hotel Crew, business IT Bridge, navigation OT DMZ OT and controlIAS, power managementpropulsion, ballast, fuelfire and safety systems
Simplified. Real ships often have more links, and some have none of the separation shown.
Behind that one firewall can be "navigation, propulsion, ballast, steering, ship command, everything on one shared network."Robert M. Lee, CEO, Dragos, to CBS News [2]

What applies, and what each one asks for

The short version for a fleet governance program.

2021Jul 1, 2024Jul 16, 2025Jan 12, 2026May 28, 2026Jul 16, 2027 Cyber in theISM SMSIACS E26/E27for new shipsUSCG rule effective;incident reportingUSCG trainingdeadlineIMO guidelinesRev.4CySO, Assessment,and Plan due
2017

IMO Resolution MSC.428(98)

Ties cyber risk to the ISM Code for SOLAS ships

IMO encourages administrations to ensure cyber risks are addressed in the Safety Management System no later than the first annual Document of Compliance verification after Jan. 1, 2021. [28]

May 28, 2026

IMO MSC-FAL.1/Circ.3/Rev.4

Guidance, not mandatory

IMO's high-level guidelines on maritime cyber risk management, latest revision approved by FAL 50 and MSC 111. Functional elements: identify, protect, detect, respond, and recover. [29,28]

July 1, 2024

IACS UR E26 and E27

Class rules for new ships contracted on or after that date

E26 covers cyber resilience of the ship as a whole: security zones, network protection, access control, monitoring, incident response, manual operation, and recovery. E27 covers the systems and equipment suppliers deliver. [30,31]

Effective July 16, 2025

USCG 33 CFR 101, Subpart F

U.S.-flagged vessels, OCS facilities, and MTSA facilities; not foreign-flagged vessels

Cyber incident reporting to the National Response Center, annual training, a Cybersecurity Officer (CySO), a Cybersecurity Assessment, and a Coast Guard approved Cybersecurity Plan. [24,25,27]

Series

ISA/IEC 62443

Industrial automation and control systems

The core OT security standard: zones and conduits, security levels, and requirements for asset owners, integrators, and product suppliers. Useful language for OEM and shipyard contracts. [32]

2024

NIST CSF 2.0

Voluntary framework, any sector

Six functions. The Govern function covers strategy, roles, policy, oversight, and supply chain risk. A good spine for a governance program and board reporting. [33]

Status check on the USCG rule (as of Oct. 4, 2026): the training deadline passed on Jan. 12, 2026; the CySO, Assessment, and Plan are due July 16, 2027. With the final rule the Coast Guard asked for comments on a possible 2 to 5 year delay for U.S.-flagged vessels. The Federal Register docket shows no document adopting that delay, and the eCFR still carries the July 16, 2027 dates. [26,25,27] The rule does not apply to foreign-flagged vessels, so for a cruise fleet the practical questions are which vessels and U.S. terminals are covered, and what flag state and class require for the rest. USCG Regulated Sector page →

Assess the ship, fix the immediate need, then stay

The same steps work for one ship or a whole fleet. Findings on the first ship of a class usually apply to her sister ships, so later assessments go faster. Start with one ship.

The door
1

Assess

  • Cyber risk assessment by ship and by system
  • Vulnerability assessment, plant-safe on live systems
  • Network architecture review, satcom down to the field devices
  • Penetration testing only where it is plant-safe (spares, staging, yard periods)
  • Standards gap review: IMO MSC-FAL.1/Circ.3, IACS UR E26/E27, USCG 33 CFR 101 Subpart F, IEC 62443, NIST CSF
The plant-safe assessment →
The fix
2

Remediate

  • Remediation plan, ranked by safety and risk
  • Network segmentation between hotel IT, the bridge, and OT
  • Secure remote access for OEMs and integrators
  • System hardening
  • Policy and corporate guidance
  • Security roadmap tied to dry-dock and refit windows
  • Crew and shoreside training through CambiOS Academy
Fix the immediate need →
The close
3

Monitor and maintain

  • OT network monitoring
  • 24x7 MSP + Metrics and Reports
  • Incident response planning and support
  • Tabletop exercises with the bridge, engine, and IT teams
  • Periodic reassessment after refits and new builds
24x7 MSP + Metrics and Reports →

Where each service fits on a ship

AssessRemediateMonitor
System groupRisk assessmentVulnerability and architecture reviewPen testing (plant-safe)Standards gapSegmentation, hardeningSecure remote accessPolicy, guidance, roadmapOT monitoringIncident response, tabletops
Propulsion and steeringGensets, pods, thrusters
Power and utilitiesPMS, HVAC, water, fuel
Life safety, fire and gasDoors, alarms, suppression
NavigationECDIS, radar, GNSS, AIS
CommunicationsGMDSS, satcom, Wi-Fi
Monitoring and OEM accessIAS/AMS, OEM links
Security and accessCCTV, doors, screening
Hotel, guest and medicalPMS, POS, casino, medical
Deck, crew and IoTWinches, crew devices
  Core service for this group  Where it fits the ship and the riskBlank: rarely appropriate

Why pen testing is limited on OT

Active testing on live propulsion or fire systems can trip them. Test on spares or in yard periods; stay passive at sea.

Why OEM access gets a row

OEMs and integrators hold remote access into many shipboard systems. Their access is part of the ship's risk.

Why communications get a row

The satcom link is the path in for remote attacks on a ship at sea, as the March 2025 VSAT claim against 116 Iranian-owned ships showed. [8]

A fleet-wide approach for a major cruise line

For a major cruise line, Red Tiger Security performed security assessments of their cruise ships, a remediation plan, strategy and security roadmap, including corporate guidance that positively shaped the security posture of the entire fleet.

1

Security assessments of the ships

2

Remediation plan

3

Strategy and security roadmap

4

Corporate guidance for the fleet

Sister ships share designs, OEMs, and remote access paths, so a finding on one ship is usually a finding for the class. Corporate guidance sets what new builds, refits, and vendors have to deliver before a ship sails. One method across the fleet lets the board compare ships and see progress over time.

First 90 days for a new maritime security leader

Days 1 to 30

Listen and map

  • Governance framework alignment: map current policy to NIST CSF 2.0 Govern, IMO guidance, and the ISM Code SMS.
  • Regulatory readiness: list which vessels and terminals fall under USCG, flag state, and class rules.
Days 31 to 60

Baseline

  • Fleet risk baseline: one method across ships and brands, starting with one ship per class.
  • Vendor, OEM, and integrator risk: who has remote access, and what the contracts require.
Days 61 to 90

Report and plan

  • Board and executive reporting: a one-page fleet view with OT and IT side by side.
  • A roadmap that ties fixes to dry-dock and refit schedules.

Fifteen questions to ask the teams and vendors

They tell a governance leader quickly where a fleet stands. Ask the same questions on two ships of the same class. If the answers differ, that gap is usually the first governance finding.

Inventory and ownership

  • Is there an OT asset inventory for each ship, and who keeps it current?
  • Who owns OT security on board: IT, the chief engineer, or the OEM?
  • Which systems are safety critical, and are they on separate networks?

Connectivity and remote access

  • How many satcom and LEO links does each ship have, and what can reach OT through them?
  • Which vendors have remote access, how is it approved, and is it logged and time-limited?
  • Is guest and crew traffic kept off the bridge and machinery networks?

Vendors, OEMs and shipyards

  • Do contracts require IACS E27 or IEC 62443 security from suppliers?
  • How do OEMs deliver and test patches, and who signs off on board?
  • Do new builds and refits go through a cyber review before delivery?

Detection and response

  • Can the team see OT network traffic at sea, or only IT?
  • Does the incident response plan cover a ship at sea with limited bandwidth?
  • When did the bridge, engine room, and shore teams last run a cyber tabletop together?

Compliance and reporting

  • Which vessels and U.S. terminals fall under the USCG rule, and are they on track for July 16, 2027?
  • Is cyber risk in each ship's Safety Management System, as IMO expects?
  • What does the board see each quarter, and does it show OT as well as IT?
Download

Fleet cyber governance checklist

The fifteen questions as a one-page PDF with space for answers by ship. Red Tiger can turn it into a fleet baseline survey and score every ship the same way.

Download the checklist (PDF)

Glossary of maritime OT terms

Terms used on this page.

AIS
Automatic Identification System. Broadcasts the ship's identity and position; can be spoofed.
AWP
Advanced wastewater purification plant.
Azipod
Electric propulsion pod under the stern that turns 360 degrees for steering.
Ballast
Water pumped between tanks to keep the ship stable and trimmed.
Class society
Organization that sets technical rules and surveys ships (members of IACS).
CySO
Cybersecurity Officer required by the USCG rule.
DOC / SMS
Document of Compliance and Safety Management System under the ISM Code.
DP
Dynamic positioning. Holds the ship in place using thrusters and position data.
ECDIS
Electronic Chart Display and Information System, the electronic chart on the bridge.
ECR
Engine control room.
GA / PA
General alarm and public address systems.
GNSS
Satellite positioning such as GPS. Can be jammed or spoofed.
IAS
Integrated automation system that monitors and controls machinery.
LEO
Low earth orbit satellite internet.
MTSA
Maritime Transportation Security Act of 2002; defines the facilities covered by the USCG rule.
OEM
Original equipment manufacturer, the maker of a system.
OT DMZ
Buffer network between IT and OT where shared services sit.
PMS
Two meanings on a ship: power management system (engine side) and property management system (hotel side).
SOLAS
IMO Safety of Life at Sea convention.
VDR
Voyage data recorder, the ship's black box.
VSAT
Very small aperture terminal, the dish-based satellite link.
Zones and conduits
IEC 62443 idea: group systems by risk and control every path between groups.

References

Numbers match the bracketed citations on this page. Sources accessed October 2026.

  1. CyberScoop, "Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks," Sept. 16, 2026. https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks/
  2. CBS News, "Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?" Sept. 16, 2026. https://www.cbsnews.com/news/coast-guard-fbi-boarded-energy-tankers-cyberattacks-amy-grable-iran/
  3. CBS News, "Coast Guard, FBI boarded Texas-bound commercial oil tanker to investigate cyberattack". https://www.cbsnews.com/news/coast-guard-fbi-board-oil-tanker-texas/
  4. Associated Press via WFLA, "FBI and Coast Guard boarded US-bound oil tankers after signs the ships were hit with cyberattacks," Sept. 16, 2026. https://www.wfla.com/news/politics/ap-politics/ap-fbi-and-coast-guard-boarded-us-bound-oil-tankers-after-signs-the-ships-were-hit-with-cyberattacks/
  5. Reuters, "Two US-bound vessels apparently compromised by hackers, US officials say," Sept. 17, 2026. https://www.reuters.com/world/two-us-bound-vessels-apparently-compromised-by-hackers-us-officials-say-2026-09-17/
  6. ABC News, "Coast Guard, FBI investigating after 2 oil tankers bound for US hit with cyberattacks". https://abcnews.com/Politics/coast-guard-fbi-investigating-after-2-oil-tankers/story?id=136482324
  7. Lloyd's List, D. Osler, "One ship is hacked every day on average," July 6, 2021 (subscription; cited by headline, author, and date). https://www.lloydslist.com/LL1137457/One-ship-is-hacked-every-day-on-average
  8. Maritimeinfosec.org, O. Jacq, "Maritime cybersecurity 2025 in numbers," updated Sept. 27, 2026. https://maritimeinfosec.org/maritime-cybersecurity-2025-in-numbers/
  9. Industrial Cyber, on the Cydome 2026 maritime trends report. https://industrialcyber.co/transport/cydome-report-finds-150-surge-in-maritime-ot-cyberattacks-as-ransomware-tightens-grip-in-2025/
  10. Marlink, Cyber intelligence report 2026, executive summary (PDF). https://marlink.com/_Resources/Persistent/1/6/1/c/161c1e9814a0a8a67ca7e45028eef86ff1e1a015/Cyber-intelligence-report-Executive_summary-MARLINK-2026.pdf
  11. CNBC, "Maersk says NotPetya cyberattack could cost $300 million," Aug. 16, 2017. https://www.cnbc.com/2017/08/16/maersk-says-notpetya-cyberattack-could-cost-300-million.html
  12. Clarkson PLC, Notice of Data Breach, July 30, 2018. https://www.prnewswire.com/news-releases/re-clarkson-plc-clarksons-notice-of-data-breach-300688782.html
  13. ZDNET, "All four of the world's largest shipping companies have now been hit by cyber-attacks". https://www.zdnet.com/article/all-four-of-the-worlds-largest-shipping-companies-have-now-been-hit-by-cyber-attacks/
  14. Singapore PDPC, decision: Royal Caribbean Cruises (Asia) Pte. Ltd. [2020] SGPDPC 5 (PDF). https://www.pdpc.gov.sg/-/media/Files/PDPC/PDF-Files/Commissions-Decisions/Decision---Royal-Caribbean-04022020.pdf
  15. iTWire, "World's third largest cruise line Norwegian suffers data breach," March 2020. https://itwire.com/business-it-news/security/world-s-third-largest-cruise-line-norwegian-suffers-data-breach
  16. Carnival Corporation & plc, Form 8-K, Aug. 17, 2020 (PDF). https://s3.documentcloud.org/documents/7038711/Carnival-8K-Other-Events-CCL-17-Aug-20.pdf
  17. NYDFS, Consent Order, Carnival Corporation et al., June 23, 2022 (PDF). https://www.dfs.ny.gov/system/files/documents/2022/06/ea20220623_carnival_co.pdf
  18. CMA CGM, update on the September 2020 cyberattack. https://www.cmacgm-group.com/en/news-media/global-it-update-09-29-2020
  19. The Asahi Shimbun, "Nagoya Port cyberattack may become security wake-up call," July 12, 2023. https://www.asahi.com/ajw/articles/14954966
  20. DP World, Media statement: update on cybersecurity incident (Australia), Nov. 2023. https://www.dpworld.com/en/news/releases/australia/media-statement-update-on-cybersecurity-incident
  21. Port of Seattle, Port cyberattack archive. https://www.portseattle.org/news/port-cyberattack-archive
  22. gCaptain, "Pole Star confirms GPS interference caused MSC ANTONIA grounding". https://gcaptain.com/pole-star-confirms-gps-interference-caused-msc-antonia-grounding/
  23. U.S. MARAD, MSCI Advisory 2026-004, Persian Gulf, Strait of Hormuz and Gulf of Oman. https://www.maritime.dot.gov/msci/2026-004-persian-gulf-strait-hormuz-and-gulf-oman-iranian-attacks-commercial-vessels
  24. USCG Maritime Commons, "Final Rule: Cybersecurity in the Marine Transportation System, Implementation Timeline," July 16, 2025. https://www.news.uscg.mil/maritime-commons/Article/4247529/final-rule-cybersecurity-in-the-marine-transportation-system-implementation-tim/
  25. eCFR, 33 CFR Part 101 Subpart F, Cybersecurity. https://www.ecfr.gov/current/title-33/chapter-I/subchapter-H/part-101/subpart-F
  26. Federal Register, 90 FR 6298, "Cybersecurity in the Marine Transportation System," Jan. 17, 2025. https://www.federalregister.gov/documents/2025/01/17/2025-00708/cybersecurity-in-the-marine-transportation-system
  27. USCG Cyber Regulations Fact Sheet (hosted by UK P&I Club). https://www.ukpandi.com/fileadmin/uploads/ukpandi/Documents/uk-p-i-club/articles/2025/USCG_Cyber_Regulations_Fact_Sheet.pdf
  28. IMO, Maritime cyber risk (including Resolution MSC.428(98)). https://www.imo.org/en/OurWork/Security/Pages/Cyber-security.aspx
  29. IMO, MSC-FAL.1/Circ.3/Rev.4, Guidelines on Maritime Cyber Risk Management, May 28, 2026 (PDF). https://wwwcdn.imo.org/localresources/en/OurWork/Facilitation/FAL%20related%20nonmandatory%20documents/MSC-FAL.1-Circ.3-Rev.4.pdf
  30. IACS, press release on UR E26 and E27. https://iacs.org.uk/news/iacs-ur-e26-and-e27-press-release
  31. IACS, UR E26 Rev.1, Cyber resilience of ships (PDF). https://iacs.s3.af-south-1.amazonaws.com/wp-content/uploads/2022/02/04140503/UR-E26-Rev.1-Nov-2023-CR.pdf
  32. ISA, ISA/IEC 62443 series of standards. https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards
  33. NIST, Cybersecurity Framework. https://www.nist.gov/cyberframework

Request a ship assessment

Start with one ship, plant-safe, with the chief engineer and the bridge team in the room. Then the team fixes the immediate need, and can stay 24x7. +1.877.387.7733 · info@redtigersecurity.com

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.