Year2025 |
MonthNovember |
Reference number20251121 |
Impact areaShore |
Incident locationMumbai, India |
Incident countryIndia |
Victim countryIndia |
Victim identityFleetship |
Victim TypeShip management and operations company |
MethodRansomware |
In November 2025, the Clop ransomware group claimed responsibility for a cyberattack against Fleetship, a ship management and operations company listed on ransomware.live as Fleetship.com. On 21 November, Fleetship appeared on Clop’s leak site, where the group alleged that it had gained access to the company’s internal systems and exfiltrated sensitive data related to its maritime management activities. Fleetship provides crew management, technical support and operational services for vessels, so compromise of its corporate IT environment poses supply-chain risks for the wider maritime sector. While there was no publicly confirmed disruption to vessel operations, the threat of data leakage and extortion highlights how ransomware actors increasingly target intermediary maritime service providers whose systems hold valuable operational and personal information.