Year2025 |
MonthDecember |
Reference number20251214 |
Impact areaVessel |
Incident locationPort of Sète, Mediterranean coast |
Incident countryFrance |
Victim countryFrance, Italy |
Victim identityGrandi Navi Veloci (GNV), a MSC subsidiary |
Victim TypePassenger ferry operator |
MethodRemote Access Trojan (RAT) |
In December 2025, French authorities discovered malware physically installed on the GNV Fantastic passenger ferry at Port of Sète. The Remote Access Trojan was deployed via Raspberry Pi devices with cellular modems installed on shipboard computer systems by a Latvian crew member, who was arrested and charged with conspiring to infiltrate computer systems on behalf of a foreign power. French counter-intelligence service DGSI is leading the investigation into what appears to be a state-sponsored operation targeting vessel control systems. The ferry, operated by MSC subsidiary Grandi Navi Veloci and carrying 2,000+ passengers on France-North Africa routes, was temporarily detained. This incident marks a significant escalation in maritime cyber threats from financially-motivated attacks to potential state-sponsored sabotage targeting navigation systems.