In July 2025, researchers from Gdynia Maritime University and the German Aerospace Center (DLR) traced nearly daily GPS signal disruptions, including both jamming and spoofing, across the Baltic Sea region. These interferences originate from Russian military electronic warfare units based in Kaliningrad’s Okunevo antenna complex and the Baltiysk area. These GPS interferences, traced within approximately one kilometer of known Russian electronic warfare installations, are viewed as deliberate tactics in hybrid warfare, undermining civil navigation , including maritime, and prompting regional efforts toward resilient alternatives like R-Mode radio navigation.
Jul, 2025In July 2025, NPO Mars, a prominent Russian defense contractor that supplies naval equipment to the Russian Navy, reportedly suffered a cyberattack and data breach. Hackers exfiltrated sensitive internal documents, including engineering diagrams, communications, and procurement details related to maritime defense systems. The leaked data may expose operational vulnerabilities and strategic details about Russian naval capabilities.
Jul, 2025In July 2025, Atlantis Submarines, a tourism and marine excursion company, reportedly became a victim of the Qilin ransomware group. The attackers claimed to have exfiltrated sensitive business data, potentially including operational documents, financial records, and customer-related information. The breach was listed on Qilin’s leak site, although the full extent of the data compromise remains unverified.
Jul, 2025In July 2025, Watermark Marine Systems, a U.S.-based shoreline construction company operating in New Hampshire, was targeted by the Akira ransomware group. The attackers claimed to have exfiltrated over 10 GB of sensitive data, including employee records, financial documents, confidentiality agreements, and NDAs. Although no download links or screenshots were published, the threat actors indicated plans to release the stolen files, posing significant risks to the company’s operational integrity and client trust.
Jul, 2025In July 26 2025, Naval Group, France’s leading defense shipbuilder, suffered a major cybersecurity incident involving the leak of approximately 30 GB of internal data, with claims from the attackers that they possess up to 1 TB more. The exposed information allegedly includes technical documents and combat system files used in French submarines and warships, such as the Suffren-class nuclear submarines and FREMM frigates. While Naval Group stated that no intrusion into its IT infrastructure has been confirmed and operational systems remain unaffected, the breach is being treated as a reputational attack. A full investigation is underway in coordination with French authorities to assess the authenticity and impact of the leaked data.
Jul, 2025In Jully 22, 2025 the Incransom group claimed responsibility for a cyberattack on the National Boat Owners Association (NBOA), a U.S.-based organization serving recreational boaters and marine insurers. The breach, estimated to have occurred on July 21, involved the unauthorized access and listing of internal files e.g. accounting records, tax documents, insurance policies, and personal folders. NBOA, which serves hundreds of thousands of members, has not issued public confirmation, but the incident raises serious privacy concerns for its community.
Jun, 2025On June 11, 2025, the Port of Klaipėda in Lithuania experienced GNSS interference affecting maritime navigation. The disruptions are attributed to Russian military activities intended to shield its Kaliningrad exclave from potential airstrikes. While not directly targeting Lithuania, the interference extended into Lithuanian territory, impacting vessels operating in the region. Lithuanian officials noted that the protective measures implemented by Russia caused these spillover effects.
Jun, 2025According to Lloyd’s List analysis from June 5, 2025, US-sanctioned VLCC Jaya smuggled Iranian oil into China earlier this year. The sanctioned ship employed a range of deceptive tactics to evade detection. These included repeatedly altering its name and MMSI numbers, assuming the identity of a decommissioned vessel, and broadcasting false positional data through AIS and GNSS spoofing to appear as multiple ships. This significantly obstructed monitoring efforts by authorities and analysts. Despite heightened international sanctions and surveillance, satellite imagery and port records confirmed that Jaya, operating under the aliases Quasar and Assos, successfully delivered Iranian crude to a major Chinese port, illustrating the growing sophistication of maritime sanction evasion strategies.
Jun, 2025In June 2, 2025 it was reported that U.S. prosecutors are investigating India’s Adani Group for alleged violations of Iran sanctions, specifically regarding suspected imports of Iranian LPG through Mundra port. Several LPG tankers linked to Adani exhibited movement patterns consistent with AIS‑spoofing, broadcasting false positional data to disguise their true whereabouts. One tanker, the SMS Bros, falsely reported being docked in Iraq’s Khor al Zubair on April 3, 2024, but satellite imagery revealed it was actually loading in Iran. Similar discrepancies were found in multiple other vessels bound for Mundra . The Adani Group has formally denied any intentional sanctions evasion or AIS manipulation, calling the allegations “baseless and mischievous,” and asserts that all LPG imports complied with relevant sanctions frameworks.
Jun, 2025A London-headquartered port agency operating in over 360 global ports has been the victim of a ransomware data theft in June 12, 2025, with attackers claiming to have stolen approximately 140 GB of internal data. The breach from the Bert ransomware gang exposed sensitive documents including employee vaccination records, passports, inspection reports, and other internal communications. Cybernews analysts confirmed the legitimacy of leaked material via dark‑web monitoring. It is noted that Bert ransomware, operational since April 2025, has targeted at least a dozen organizations by infiltrating IT ecosystems through software supply-chain vulnerabilities