Suspected State-Sponsored Cyberattack Hits GNV Fantastic Ferry

Year

2025

Month

December

Reference number

20251214

Impact area

Vessel

Incident location

Port of Sète, Mediterranean coast

Incident country

France

Victim country

France, Italy

Victim identity

Grandi Navi Veloci (GNV), a MSC subsidiary

Victim Type

Passenger ferry operator

Method

Remote Access Trojan (RAT)

Summary:

In December 2025, French authorities discovered malware physically installed on the GNV Fantastic passenger ferry at Port of Sète. The Remote Access Trojan was deployed via Raspberry Pi devices with cellular modems installed on shipboard computer systems by a Latvian crew member, who was arrested and charged with conspiring to infiltrate computer systems on behalf of a foreign power. French counter-intelligence service DGSI is leading the investigation into what appears to be a state-sponsored operation targeting vessel control systems. The ferry, operated by MSC subsidiary Grandi Navi Veloci and carrying 2,000+ passengers on France-North Africa routes, was temporarily detained. This incident marks a significant escalation in maritime cyber threats from financially-motivated attacks to potential state-sponsored sabotage targeting navigation systems.

Reference URL

https://www.bleepingcomputer.com/news/security/france-arrests-latvian-for-installing-malware-on-italian-ferry/
https://www.france24.com/en/live-news/20251217-france-probes-foreign-interference-after-malware-found-on-ferry-1
https://www.tomshardware.com/tech-industry/cyber-security/french-ferry-malware-arrest-exposes-fragile-boundaries-between-ship-it-and-navigation-systems
https://www.csoonline.com/article/4108328/the-raspberry-pi-wakeup-call-why-enterprises-must-rethink-physical-security.html