Hackers target ships’ satellite links

Growing use of satellite connections to run ships’ onboard systems is making them vulnerable to hacking attacks, a leading maritime cyber security group has warned, following digital assaults on at least two vessels this week.

Attacks infiltrating a ship via “edge devices” that connect vessels to outside satellites jumped from 3 per cent of all attacks in 2024 to 22 per cent in 2025, according to Cydome, with the absolute number of attacks in the “hundreds”.

“Every mechanism on a ship — engine, navigation etc — is connected via satellite online to the shore, so everything is exposed. The whole thing is a floating attack surface,” said Marc Oppenheim, regional business director at Cydome.

Hackers have generally tried to attack ship systems to install ransomware — locking systems until a payment is made — but shipping executives fear that with more vessels using automated systems, attackers could try to take control of critical operations.

Cydome said the trend was likely to be “even more pronounced this year” in part due to geopolitical tensions and the use of AI to discover vulnerabilities.

US officials this week said they were investigating potential Iranian cyber attacks on two tankers travelling to the US from the Middle East as Tehran seeks to control oil flows out of the Gulf.

One, the VL Prosperity, was transiting the Strait of Gibraltar in August when it was hacked, according to US officials and ship-tracking data that showed the vessel slowing sharply.

Iran’s Mehr News Agency claimed that the vessel lost communications for about 30 hours and that the attackers disrupted onboard operations, though that could not be independently confirmed.

The US Coast Guard said it boarded the vessel on August 21 “to ensure integrity of the vessel’s operational and information technology systems”.

The identity of the second tanker, which was first reported by the Wall Street Journal, has not been confirmed.

Cydome said the attack on VL Prosperity, a South Korean-managed ship carrying 2mn barrels of Gulf crude, was “stark evidence that regional tensions have a real impact on civil maritime transportation”.

It said that as ships became more connected to land-based control centres and satellites to run onboard operations, the boundary between operational technology — controlling physical equipment such as navigation and engine — and IT systems such as administrative software was becoming “blurred”.

Cyber attacks were seen as the second-highest risk to maritime operations by shipping executives in the International Chamber of Shipping’s 2026 annual maritime survey. Yet cyber security was only ranked fifth highest — after other issues such as extreme weather events and physical attacks — in terms of the industry’s ability to deal with the risk.

Ships have characteristics that make them exposed to attack, including the involvement of multiple parties from charterers to crew and the need for information to be shared onshore, according to the shipowners’ association Bimco.

Vulnerabilities in a specific device often used to link ships to satellites, called iDirect, were reported by the US Cybersecurity and Infrastructure Security Agency on July 2 and updated on September 10. The advisory credited the report to an engineer at Saudi Aramco, Saudi Arabia’s state oil company.

Infiltration through such a device could be used to launch a ransomware attack or to disrupt onboard systems, experts said.

Shipowners, notably those with ships stuck in the Gulf during the first months of the US-Iran conflict, have also increasingly used Starlink to improve WiFi onboard.

“If you can infiltrate a set-up through the satellite, you can cross over and access some of the onboard systems,” said Oppenheim.

Hackers could potentially then control the temperature, heating systems and speed of the ship, he added. “It opens up a can of worms once you can find your way into the connection.”

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论