In October 2025, the Qilin ransomware group publicly claimed an attack against Montship Inc. (montship.ca), describing it as Canada’s largest shipping agency. Ransomware.live, Dexpose and other ransomware-monitoring sources show Montship added to Qilin’s leak site on 16 October 2025, with claims that internal financial reports and other sensitive data had been exfiltrated. Montship provides liner and port agency services for vessels at ports across Canada, so the incident represents a cyberattack against a key maritime service provider. While there is no clear public evidence of operational shutdown at Canadian ports, the compromise of Montship’s corporate IT environment and documents poses serious confidentiality, reputational and supply-chain risks for the Canadian maritime sector.
Oct, 2025On October 4, 2025, Qatar's Ministry of Transport issued an unprecedented suspension of all maritime navigation activities in Qatari territorial waters following discovery of what officials termed a "technical malfunction in GPS" that threatened navigation system accuracy and maritime safety. All vessel owners were ordered to immediately cease navigation operations until the technical issue was resolved. The suspension remained in effect for approximately 48 hours before being partially lifted on October 6 to allow daytime navigation for conventional vessels, with evening and extended-range restrictions on smaller craft remaining. No detailed technical explanation was provided by Qatari authorities regarding the root cause of the GPS malfunction. The incident occurred during a period of widespread GPS jamming and spoofing incidents across the Arabian Gulf and Strait of Hormuz related to Middle East regional tensions and ongoing conflicts. While officially attributed to a technical malfunction, the timing and nature of the disruption suggest potential state-level GPS interference operations. The incident represents a significant maritime cyber/electronic warfare event affecting national maritime operations and international shipping routes in a critical trade corridor.
Sep, 2025On 5 September 2025, Russian shadow fleet tankers were found using AIS spoofing to conceal ship-to-ship (STS) transfers of sanctioned crude oil in the Gulf of Oman. Since February 2024, intelligence firms Vortexa and SynMax tracked cases such as Aframax Rozmarine and Suezmax Canara, which manipulated location data while transferring oil to non-sanctioned vessels Prisma and Vernal. These AIS spoofing tactics allowed sanctioned tankers to offload cargo for delivery to India and China while quickly returning to Russia for reloading.
Sep, 2025In September 2025, Dutch shipbuilder Ferus Smit Shipyard B.V. (ferus-smit.home) was listed as a victim of the Warlock ransomware group. BreachSense and ransomware.live recorded the case as a data breach discovered on 17 September 2025, with Warlock claiming "all data". Additional reporting by DeXpose and other threat-intel sources confirms that Warlock is an emerging ransomware group active in 2025, typically combining network intrusion with data exfiltration and extortion. Ferus Smit Shipyard, which operates shipyards in Westerbroek (NL) and Leer (DE), thus became one of several maritime-related industrial victims in Warlock’s 2025 campaign. No detailed public information is available about operational disruption at the yard, but the exposure of internal corporate data poses ongoing risks.
Aug, 2025A cyberattack on August 19, 2025 struck Yemen’s Houthi-run Red Sea Ports Authority, crippling systems for logistics, vessel tracking, and customs at the ports of Hodeidah, Ras Isa, and As-Salif. The hacker group S4uD1Pwnz claimed responsibility on a Telegram channel, saying it had accessed data from more than 33,000 maritime voyages, including ship names, agents, bill of lading numbers, and cargo details. The attackers deployed ransomware and data-wiping malware, demanding political concessions. Houthi officials acknowledged the breach but insisted no sensitive data was compromised.
Aug, 2025In August 2025, AIS data for nearly 98 ships, primarily tankers, was disrupted across Russia’s Far East, specifically around Nakhodka Bay and the Kozmino oil terminal, as interference began on August 6. This AIS blackout, attributed to third-party GNSS manipulation, rendered real-time vessel tracking ineffective, especially during cargo loading, and severely hindered maritime visibility. Analysts interpret this interference as a strategic effort to conceal oil export operations, possibly linked to sanction evasion, amid a broader pattern of Russian naval and electronic warfare activity across the region.
Aug, 2025In August 3, 2025, Ukraine’s military intelligence (HUR) reportedly infiltrated the digital systems of Russia’s newest Borei-A class nuclear submarine, Knyaz Pozharsky, obtaining highly classified technical documents. The stolen data included combat manuals, engineering schematics, crew rosters with detailed fitness and role information, operational schedules, and procedures for critical functions like evacuation and towing. This breach not only exposes possible weaknesses in Russia’s newest naval asset but potentially reveals vulnerabilities across the entire Borei-A fleet, a cornerstone of Moscow's nuclear deterrent strategy.
Aug, 2025In August 14, 2025, it was reported that Nigeria Customs Service (NCS) suffered a cyberattack targeting its ICT infrastructure, disrupting cargo clearance operations across Nigerian ports. This outage forced customs agents to incur substantial demurrage and storage fees, and distorted import timelines and costs. While the platform, known as “B’Odogwu”, has since been restored and fortified against further breaches, the incident highlighted vulnerabilities in the system. Government officials are in discussions with stakeholders about relief measures for affected importers.
Aug, 2025In August 22, 2025, the hacktivist group Lab-Dookhtegan (also known as "Sewn Lips") executed one of the most consequential cyberattacks on Iran’s maritime infrastructure. After a similar attack in March and through compromising Fanava Group, the IT provider for state-controlled maritime giants NITC and IRISL, the group gained root-level access to Linux systems on board approximately 39 tankers and 25 cargo ships and disabled the critical Falcon satellite communication software. This plunged affected ships into total communication blackout, severing AIS tracking and ship-to-shore links. Additionally, the attackers carried out destructive overwrites of six storage partitions, wiping navigation logs, system configurations, recovery files, and even IP phone systems, escalating the disruption to require manual reinstallation of communications gear aboard each vessel. Forensic evidence shows that the hackers held access as early as May and June before launching the August attack which demonstrates prolonged infiltration and proving how a single supplier breach can lead to widespread operational collapse.
Jul, 2025Ships passing through the Baltic are increasingly engaging in AIS spoofing, using fake flags and false AIS positions to disguise their true identities and voyage routes. At least five tankers—reportedly sanctioned Russian vessels—have been observed broadcasting bogus flags of countries like Malawi and Sao Tome, while simultaneously transmitting incorrect location data.. Lacking an official flag and known for AIS spoofing, the Falcon LPG tanker entered the Gulf of Finland claiming Tallinn as its destination. Consistent with earlier journeys, the Falcon's AIS data falsely showed it anchored near Estonia while it was actually loading gas in Russia.