Bluspark Global’s shipping platform (Bluvoyix) was publicly exposed due to serious security weaknesses, including an unauthenticated API and plaintext password exposure, creating risk of unauthorized access to logistics systems and customer shipment data.
Dec, 2025In December 2025, French authorities discovered malware physically installed on the GNV Fantastic passenger ferry at Port of Sète. The Remote Access Trojan was deployed via Raspberry Pi devices with cellular modems installed on shipboard computer systems by a Latvian crew member, who was arrested and charged with conspiring to infiltrate computer systems on behalf of a foreign power. French counter-intelligence service DGSI is leading the investigation into what appears to be a state-sponsored operation targeting vessel control systems. The ferry, operated by MSC subsidiary Grandi Navi Veloci and carrying 2,000+ passengers on France-North Africa routes, was temporarily detained. This incident marks a significant escalation in maritime cyber threats from financially-motivated attacks to potential state-sponsored sabotage targeting navigation systems.
Dec, 2025In December 2025, TERPORT S.A., a major river port terminal operator in Paraguay, was listed as a victim of the Lynx ransomware group. Terport operates the Parana-Paraguay Waterway's most sophisticated container terminal (TERPORT-VILLETA) and the TERPORT-SAN ANTONIO facility handling general cargo, RORO, and warehousing. The Lynx group exfiltrated and encrypted confidential business data including operational records, financial documents, and logistics data using double extortion tactics. As a critical node in South American waterway trade, the breach carries cascading supply chain risks for shipping companies, freight operators, and customs authorities dependent on the terminal's coordination systems.
Dec, 2025In December 2025, escalating geopolitical tensions between the United States and Venezuela triggered a large-scale GPS jamming and spoofing campaign affecting civilian maritime and aviation traffic across the Caribbean. The US military, including the USS Gerald R. Ford carrier strike group, deployed GPS jamming as a defensive countermeasure against potential drone and missile attacks, while Venezuelan armed forces similarly jammed signals around critical infrastructure (military bases, oil refineries, power stations) in response to perceived US military threats. The electronic warfare operations caused widespread disruption: approximately 20% of Caribbean flights experienced GPS navigation failures; multiple commercial vessels reported 4+ hour GPS signal loss; AIS signals were manipulated showing vessels at false positions; at least one near-collision occurred between a civilian aircraft and a US military plane due to GPS/navigation failures; tanker operations were delayed with at least six vessels engaging in AIS spoofing or disabling transponders; and multiple documented incidents of vessels forced to navigate manually using radar and visual bearings. The incident represents the first large-scale military GPS jamming campaign directly and intentionally affecting civilian maritime and aviation infrastructure in the Western Hemisphere, highlighting the spillover effects of geopolitical conflict on commercial transportation networks. Both the Trump administration's enhanced enforcement against Venezuelan sanctions evasion and Venezuela's military response have transformed the Caribbean into an active electronic warfare zone.
Dec, 2025Brodosplit, Croatia’s largest shipyard, suffered a ransomware attack by the Qilin group. Attackers exfiltrated around 1 TB of sensitive data, including engineering documents and internal business files, and published samples online. The event represents a significant maritime-sector security breach affecting a major European shipbuilder.
Dec, 2025Piriou, a major French shipbuilding group, suffered a ransomware attack by the DEVMAN group. Attackers exfiltrated internal corporate data and published samples online as part of a double-extortion scheme. The shipyard did not report operational disruption, and no incident response details have been publicly released.
Dec, 2025Venezuela’s state oil company PDVSA suffered a cyberattack described by a company source as ransomware impacting administrative systems. Reporting indicates PDVSA’s export/import data network at the José crude terminal remained offline, delaying scheduled loadings and suspending export loading instructions, with knock-on effects visible in tanker movements.
Nov, 2025An Iran-linked threat group compromised multiple maritime-sector organization and accessed specialized tools used to visualize AIS signal coverage globally. The actors used these tools to identify geographic AIS blind spots where vessel tracking is limited or absent. This intelligene enables covert vessel repositioning, sanctions evasion, smuggling, military deception and potentation support for physical operations at sea. The intrustion demontrates a shift from simple AIS manipulation to pre-operational cyber-espionage targeting AIS infrastructure itself.
Nov, 2025In November 2025, Stark Shipping LLC, a Ukrainian maritime logistics and shipping agency operating in the Black Sea and Azov Sea ports, was listed as a victim of the Nova ransomware group. Threat-intelligence and data-breach trackers report that Nova exfiltrated and published roughly 226–275 GB of internal corporate data from Stark Shipping’s network, including operational shipping documents, port agency records, cargo manifests, client and vendor communications, financial documents and employee-related files. The incident is described as a data breach and ransomware attack using Nova’s typical double-extortion model, although open sources do not clearly confirm whether Stark’s systems were encrypted or services were interrupted. No detailed public incident-response statement from Stark Shipping has been identified so far. The case illustrates how criminal ransomware-as-a-service groups are increasingly targeting maritime support and logistics providers whose data covers multiple ports and trade partners, creating systemic exposure even when a single company is compromised.
Nov, 2025In November 2025, the Clop ransomware group claimed responsibility for a cyberattack against Fleetship, a ship management and operations company listed on ransomware.live as Fleetship.com. On 21 November, Fleetship appeared on Clop’s leak site, where the group alleged that it had gained access to the company’s internal systems and exfiltrated sensitive data related to its maritime management activities. Fleetship provides crew management, technical support and operational services for vessels, so compromise of its corporate IT environment poses supply-chain risks for the wider maritime sector. While there was no publicly confirmed disruption to vessel operations, the threat of data leakage and extortion highlights how ransomware actors increasingly target intermediary maritime service providers whose systems hold valuable operational and personal information.