Type of Maritime Cyberattacks

Today, ships have become more than steel-and-engine-powered vessels; they are highly connected, digital platforms. Current ships depend on combined IT and OT systems for navigation, propulsion, cargo, and safety, and that interconnectivity is increasing rapidly. According to IMO, this digital change is accompanied by an increase in cyber vulnerabilities due to the greater frequency of ship-to-ship connections via the internet. Critical systems, including engine control, bridge navigation, and cargo management, are new targets of cyber attackers, endangering ship safety and operational continuity.

As ships become floating networks of interconnected digital systems, maritime cybersecurity is no longer optional. It is a core pillar of safe operations, compliance, and resilience across global shipping

The Modern Maritime Cyber Threat Landscape

In the maritime sector, cyber threats are broadly categorized into untargeted and targeted attacks. As the SKAN Registry Guidelines on Cyber Security Onboard Ships explain, untargeted attacks occur when a ship or company is just one of many potential victims, often using readily available malware such as ransomware, viruses, spyware, or worms. Such attacks are also based on unpatched systems or generic vulnerabilities.

Conversely, targeted attacks are planned by attackers who specifically target a particular vessel or maritime company. These attacks can take the form of credential stuffing, phishing, or even GPS spoofing to control navigation systems, as well as IBS/Bridge systems or Marine Radar Systems environments. Indicatively, ENISA (2023) identified ransomware and malware as major threats, often perpetrated by state-sponsored or politically motivated attackers seeking to disrupt operations.

Common Maritime Cyberattack Techniques

Cyber attackers at sea employ a variety of sophisticated strategies. Malware, including trojans, ransomware, worms, and spyware, can infiltrate ship systems, for example via infected USB drives or unpatched software. Brute-force attacks and credential stuffing are common techniques used to crack weak login credentials for remote-access systems. More concerning are supply chain compromises: the infamous NotPetya virus infected Maersk through a compromised software update, underscoring the significant security risks posed by third-party suppliers. Finally, outdated or unpatched OT systems remain prime targets, as attackers exploit known vulnerabilities in poorly maintained control infrastructure.

How Cyber Incidents Unfold: The 4 Attack Stages

The four stages of cyberattacks on ships closely mirror the general cyber kill chain model, but are tailored to the unique challenges of the maritime environment.

1. Survey / Reconnaissance: In this initial stage, attackers can gather open-source intelligence from social media, technical forums, company websites, and published documents. They identify procedural, physical, and technical weaknesses, and may even monitor live network traffic to understand system behaviors.

2. Delivery: After identifying vulnerabilities, attackers attempt to deliver malicious payloads. This can occur through infected emails, fraudulent web pages, compromised USB drives (such as during software updates), or corrupted cargo-tracking services.

3. Breach: If delivery is successful, attackers establish an initial foothold. The intrusion is often invisible; systems continue operating normally while attackers may tamper with navigation data, steal manifests or crew information, or even assume control of onboard equipment.

4. Pivot: Once access is established, attackers often move laterally, from less secure systems to more critical ones. They deploy scripts, scan adjacent networks, install backdoors, and launch further attacks that can disrupt operations, exfiltrate data, or demand ransom.

This progression makes such attacks especially dangerous: once a foothold is established, attackers can remain undetected, explore the environment, and expand their control.

Vulnerabilities Onboard: Where Ships Are Most Exposed

  • Most ships have outdated or unsupported operating systems, such as older versions of Windows that are not updated and lack easy access points.
  • Lack of network segmentation, e.g., intruders can cross boundaries laterally within IT and, even more dangerous, OT systems, without adequate protection.
  • There is still a risk of using unsafe removable media, particularly for chart or software updates; poor scanning policies exacerbate this.
  • Safety-critical systems (e.g., navigation and engine systems) remain constantly connected to shore, increasing the focus of cyberattacks on them.
  • Third-party access vulnerabilities, i.e., contractors, vendors, and remote service providers, are often granted access to ship systems without strict controls.
  • The communication systems (VSAT) are particularly susceptible to it, with default passwords, weak encryption, and open ports being among the most vulnerable points of remote exploitation.

Critical Systems That Require Immediate Assessment

Bridge Systems (GPS, ECDIS, Radar, AIS): Contemporary navigation is based on digital bridge systems, including Electronic Chart Display (ECDIS), AIS, GNSS, and radar. Cyber threats to these systems are caused, for example, by removable media or shore-side network interfaces.

Propulsion & Machinery Control: Machinery and steering are now digitally controlled and monitored, and are therefore particularly prone when connected to remote monitoring or integrated bridge systems.

Cargo Management/Container Tracking: Loading, stowage, and remote monitoring of refrigerated (reefer) or dangerous cargo systems are usually connected to onshore systems; these ports are potential attack points.

Access Control Surveillance: Digital access to surveillance systems, electronic person-on-board modules, and access control are highly vulnerable and need to be hardened.

Ship-to-Shore Interfaces & Remote Access: Remote diagnostics, voyage data, or performance telemetry (via satellite) interfaces must have strong cyber defences – they are often used as a point of entry in case they are not properly secured.

Assessing Likelihood & Impact Using the CIA Model

When assessing the risk of cyber-attack onboard ships, probability is typically defined as Threat × Vulnerability, encompassing an attacker’s capability, motivation, and opportunity. The impact of such risks is then evaluated using the CIA (Confidentiality, Integrity, Availability) model:

  • Confidentiality: Unauthorized disclosure of sensitive information related to crew, cargo, or ship systems.
  • Integrity: Unauthorized modification of critical data, such as navigation information or OT set-points.
  • Availability: Disruption or denial of access to essential systems and services.

The importance of each CIA dimension depends on the system; in safety-critical OT environments, integrity and availability often take precedence over confidentiality. This approach aligns, for example, with IMO MSC.428(98), making cyber risk assessment and mitigation integral components of the ship’s Safety Management System.

Strengthening Maritime Cybersecurity: Defence in Depth and Breadth

Maritime cyber risk management needs to embrace defence-in-depth, which involves implementing a range of technical and procedural controls to secure shipboard systems. This is the combination of network segmentation, firewalls, intrusion detection, software whitelisting, access/user controls, and stringent removable-media policies.

But depth alone isn’t enough. The ships also require defence in depth, so that once one system is breached, the breach cannot be used to attack other important systems.

Concluding Thoughts

With the globalisation of shipping, the maritime transportation industry is exposed to ever-increasing and endemic cyber threats that could disrupt seafarers’ navigation, propulsion, cargo, and safety systems. Defending vessels now involves continuous, real-time, and proactive defence in both IT and, even more important, the OT spaces. Ship owners and operators can mitigate risk and enhance resiliency by implementing IMO-compatible cybersecurity-related practices.

Cybersecurity is no longer an option but a part of safe navigation, the reliability and stability of the world supply chain.

Nessun commento ancora

Lascia un commento