
The traditional separation between shipboard hardware and onboard software is quickly disappearing in today’s maritime sphere. Ships are combining IT and OT systems to provide navigation, propulsion, and control, creating new attack surfaces where physical interference may be caused by digital interference. According to the SCIRP case study of cyber-physical attacks in port settings, it is possible to use control and navigation data manipulation to cause blocked channels, collisions, and operational shutdowns.
Fundamentally, a replay attack involves transmitting valid signals repeatedly to trick a navigation system, which is a misleadingly easy method with disproportionately large implications.
Altering only a mere replay of GPS data can divert an entire ship by a few feet, and it has already happened more than you might imagine, in the era of connected ships.
From ship collisions to GPS deception — how real maritime incidents and cyber-physical tests reveal the silent threat of replay attacks.
The Concept of a Replay Attack
Replay attacks in cases of maritime navigation do not require hacking into encrypted systems; it is simply a matter of trust. According to the paper published by ResearchGate, the attack is carried out by intercepting valid GNSS signals and replaying them to cheat a vessel navigation system. The ship still gets valid-looking satellite data and does not realize that the point it is computing is no longer real.
Moreover, a large amount of marine control and navigation tend to exchange encrypted or loosely authenticated NMEA sentences, which are standardized data formats for positioning and control. Since they are not cryptographically protected or even verifiably timed, an attacker can intercept, postpone, and replay them later to alter the apparent movement or state of operation of a ship.
Concisely, the replay attack does not compromise systems; it deceives them with their trustworthy information.
Real Maritime Context: When Fiction Meets Reality
On Reddit, one of the investigators shares a haunting memory: the disappearance of a cargo ship off radar, only to re-emerge hours later, heading toward an empty horizon. The digital logbook of the vessel indicated a position that did not exist, and the bridge crew testified that they had accurately followed the GPS. Naturally, this is a fiction, a work of creative horror. However, it raises the frightening question that maritime cybersecurity specialists pose in the real world: what will happen when the digital fate of a ship is subtly compromised?
In practice, the case study of Safety4Sea about the piracy attack in the Gulf of Guinea mentions how the communication systems were jammed, and the Ship Security Alert System (SSAS) was unable to send distress signals in time. Although the attackers employed brute strength, their attack was aided by time-lapsed information, hindered reporting systems, and confusion of circumstances, exactly the type of situations that replay attackers would exploit.
Both fictional and factual, the two stories emphasize the same fact: it is too easy to lose the demarcations between cyber illusion and the real threat at sea.
Case Study 1: The 2017 Black Sea GPS Spoofing Incident
In June 2017, multiple vessels passing through the Black Sea off Novorossiysk, Russia, reported that their GPS positions had drastically changed to be miles inland, while radar and visual bearings indicated their continued position in the sea. The U.S. Maritime Administration (MARAD) subsequently verified the anomaly and raised an alert, marking one of the first recorded large-scale GPS spoofing or replay attacks in maritime history.
According to reports from Inside GNSS and Wired, the ships received what appeared to be valid satellite signals with real timestamps but fake coordinates, a characteristic feature of replayed or spoofed GNSS data. Although there was no collision, the incident demonstrated how easily trusted navigation systems could be fooled by canned or altered satellite transmissions. The episode with the Black Sea highlights an essential lesson: maritime safety depends not only on GPS accuracy but also on verifying the authenticity of signals.
Case Study 2: Maersk – The NotPetya Cyber Attack
The NotPetya malware attacked A.P. Moller-Maersk, the largest container shipping company in the world, in June 2017. What began as a specific cyberattack on Ukrainian infrastructure soon extended to Maersk’s global network, encrypting systems that manage vessel navigation, terminal operations, and cargo monitoring. Maersk lost control of its systems and port access systems in 76 terminals in 34 countries within hours.
The company was brought to a standstill for nearly 2 weeks, leading to more than 300 million dollars in losses. The event demonstrated a vulnerability in maritime digital infrastructure, where interdependent IT and OT systems, despite their efficiency, can amplify the impact of a single cyber-attack.
The case was a breakthrough in maritime cybersecurity as it highlighted that one hacked network can shut down the entire global trade.
The technology protection
The protection for these kinds of attacks cannot be the generic OT or, even worse, the classical IT Security with vulnerabilities, CVEs, IT risk factors.
The protection here can only come from specialized solutions, able to dissect, digest, and operate on top of the NMEA protocol (versions -0183 and 0200), while considering the whole Maritime OT risks with the different specific attacks due to maritime protocols, usage, device and vessel’s architecture
Critical Appreciation & Concluding Thoughts
The examples and studies considered in this blog show how the maritime industry has become increasingly reliant on digital ecosystems without the resources to respond to cyber manipulation. Replay attacks, despite their deceptive simplicity, reveal a significant vulnerability in maritime systems, as authenticity is confused with truth.
We get to witness how the deception of localized signals and a worldwide infrastructure can disrupt navigation, logistics, and trade, as seen with the Black Sea GPS spoofing incident and the NotPetya attack on Maersk. They are no longer rare incidents but signs of a structural fault: old systems built to be stable rather than secure.
Maritime cybersecurity currently requires a change in the compliance mode to constant verification. The future of safe navigation lies not only in the accuracy of weather forecasts or radar visibility but also in the validity of all data packets of a vessel. Replay attacks are an important reminder that in the digital ocean, danger no longer comes in the form of a storm; it comes in the form of an ideal echo.








