- OVERVIEW
The Impact of Cybersecurity on the Shipping Market
The shipping industry has another threat without physically touching a vessel at all: a cyberattack.
BIMCO notes that the growing integration of information technology (IT), operational technology (OT), and ship-to-shore data links has substantially increased shipping’s exposure to cyber threats.
From Digital Disruption to Physical Congestion
One of the most important characteristics of maritime cybersecurity is that a digital attack can ultimately create a physical shipping problem. If disruption occurs at a sufficiently important port or terminal. particularly during an already tight market, the resulting loss of effective vessel supply could contribute to higher freight rates.
The Vessel Itself Is Becoming More Digital
The International Association of Classification Societies (IACS) introduced Unified Requirements E26 and E27 covering the cyber resilience of ships and onboard systems and equipment. Revised requirements apply to relevant new ships contracted for construction from 1 July 2024.
Cyber resilience is therefore gradually becoming part of the technical architecture of the vessel itself.
Ports Are Equally Vulnerable
The European Union Agency for Cybersecurity (ENISA) has highlighted how the emergence of increasingly digitalised “smart ports”, incorporating technologies such as IoT, cloud computing, automation and artificial intelligence, can increase the exposure of port systems to cybersecurity threats.
Cybersecurity Is Also a Commercial Risk
Shipbrokers, charterers, owners, agents and operators exchange enormous quantities of commercially sensitive information every day. A compromised email account could therefore have serious consequences.
Fraudulent payment instructions could divert funds. Confidential fixture negotiations could be exposed. False instructions could be sent under the identity of a trusted counterparty. Commercial data could be stolen, manipulated or held for ransom.
Regulation Is Catching Up
IMO has a revised Guidelines on Maritime Cyber Risk and industry organisations have moved in parallel. Version 5 of The Guidelines on Cyber Security Onboard Ships, published in November 2024, involved BIMCO, INTERTANKO, ICS, OCIMF, IUMI, Maersk and numerous other maritime organisations.
The Double-Edged Sword of AI
Attackers can use AI to produce more convincing phishing communications, impersonate counterparties, automate reconnaissance and search for vulnerabilities.
DNV’s Maritime Cyber Priority 2024/25, based on a survey of almost 500 maritime professionals, found growing awareness and investment in cybersecurity but also warned of potential overconfidence, particularly regarding supply chains, operational technology, training and skills.
Real-World Examples of Cyberattacks in Shipping
2017 – Maersk: The NotPetya Cyberattack
One of the most significant cyber incidents in shipping occurred in June 2017, when A.P. Moller–Maersk was hit by the NotPetya malware attack. The attack disabled IT systems across Maersk’s global operations and affected APM Terminals at multiple locations.
Although Maersk’s vessels remained operational, shore-based systems supporting bookings, cargo documentation, communications and terminal activities were severely disrupted. Maersk subsequently estimated that the incident caused losses of approximately US$250–300 million.
The incident became a landmark case for the maritime industry because it demonstrated that ships themselves do not necessarily have to be hacked for global shipping operations to be disrupted. An attack on the digital infrastructure surrounding the vessel can be enough to interrupt cargo flows and terminal operations.
2018 – COSCO Shipping: Communications Disrupted
In July 2018, COSCO Shipping Lines experienced a cyberattack affecting its network in the Americas. Local email and network telephone services were disrupted, forcing the company to implement contingency measures while isolating affected networks to prevent the problem from spreading.
COSCO reported that its vessels continued operating normally and its principal business systems remained stable. Nevertheless, the incident demonstrated the importance of communications infrastructure to modern shipping operations.
2023 – DNV ShipManager: Around 1,000 Vessels Affected
In January 2023, DNV suffered a ransomware attack against its ShipManager fleet-management environment. Approximately 70 customers operating around 1,000 vessels were affected by the disruption.
DNV shut down the affected servers in response to the attack. Importantly, vessels were able to continue operating using the onboard offline functionality of ShipManager, while other onboard systems were unaffected.
The incident illustrates the value of redundancy and business-continuity planning. Cyberattacks may be impossible to eliminate completely, but having independent or offline systems can prevent a digital disruption from escalating into a physical vessel-operational crisis.
2023 – Port of Nagoya: Cyberattack Stops Cargo Movements
In July 2023, Japan’s Port of Nagoya suffered a ransomware attack affecting the Nagoya United Terminal System (NUTS), which supports container operations across the port.
The disruption prevented containers from being moved into and out of affected terminals for approximately 2½ days, interfering with logistics operations at one of Japan’s most important ports.
The Nagoya incident demonstrates perhaps the clearest connection between cybersecurity and shipping-market fundamentals:
If a similar incident were to affect a major oil terminal, refinery or storage hub during an already tight tanker market, prolonged vessel waiting could reduce effective tonnage availability and potentially contribute to upward freight pressure.
2026 – Strait of Hormuz: When Cyber Fraud Becomes a Physical Threat
A more recent and unusual example emerged during disruptions surrounding the Strait of Hormuz in 2026.
Maritime security organisations reported fraudulent communications in which scammers impersonated Iranian authorities and offered vessels supposed clearance or “safe passage” through the Strait in exchange for cryptocurrency payments, including Bitcoin and USDT.
The fraudsters reportedly demanded substantial payments and, in some cases, sought sensitive information concerning vessels and senior crew members.
Looking ahead
For maritime professionals, understanding cybersecurity does not mean understanding computer code. It means recognising cybersecurity as another potential source of operational disruption, commercial exposure and market volatility.
- PLATTS TREND
| WORLD SCALE | 11-Aug-26 | 12-Aug-26 | 13-Aug-26 | 7-DAYS AVERAGE |
1-DAY CHANGE |
7-DAYS CHANGE |
7-DAYS- CHANGE |
|---|---|---|---|---|---|---|---|
| SPORE/JPN (30 KT) | 207.5 | 207.5 | 200 | 206.88 | -7.5 | -10 | -4.76% |
| SPORE/OZ (35 KT) | 258 | 258 | 250 | 258.94 | -8 | -15 | -5.66% |
| KOREA /OZ (35 KT) | 278 | 280 | 280 | 280.88 | 0 | -10 | -3.45% |
| INDIA/JAPAN (35 KT) | 215 | 215 | 215 | 216.25 | 0 | 0 | 0.00% |
| $1 = $1K | 11-Aug-26 | 12-Aug-26 | 13-Aug-26 | ||||
|---|---|---|---|---|---|---|---|
| SPORE/HK | 540 | 540 | 530 | 536.25 | -10 | -10 | -1.85% |
| KOREA/SPORE | 830 | 850 | 850 | 827.50 | 0 | 20 | 2.41% |
| KOREA/JAPAN | 590 | 600 | 600 | 586.25 | 0 | 15 | 2.56% |
| KOREA/H.K. | 725 | 735 | 735 | 728.13 | 0 | 0 | 0.00% |
| KOREA/USWC | 2,200 | 2,200 | 2,200 | 2,180.00 | 0 | 0 | 0.00% |
| WORLD SCALE | 11-Aug-26 | 12-Aug-26 | 13-Aug-26 | ||||
|---|---|---|---|---|---|---|---|
| AG/JAPAN (55 KT) | 310 | 312.5 | 320 | 307.81 | 7.5 | 10 | 3.23% |
| AG/JAPAN (75 KT) | 347.5 | 367.5 | 367.5 | 352.50 | 0 | 12.5 | 3.52% |
| OMAN G./JAPAN (55 KT) | 195 | 195 | 202.5 | 194.69 | 7.5 | 7.5 | 3.85% |
| OMAN G./JAPAN (75 KT) | 190 | 210 | 220 | 195.00 | 10 | 35 | 18.92% |
- REPORTED FIXTURES
| VESSEL | SIZE | GRADE | L/C | LOAD | DISCHARGE | FREIGHT | CHTRS |
|---|---|---|---|---|---|---|---|
| CAPE BRISILIA | 35 | CPP | 20 AUG | SPORE | OZ | WS 250 | AMPOL |
| HAFNIA LIONESS | 35 | ULSD | 24 AUG | MUARA | OZ | WS 257.5 | VITOL |
| HAFNIA EXECUTIVE | 55 | NAP | 26 AUG | VADINAR | JAPAN | RNR | KPC |
| ELANDRA KITE | 90 | CPP | 24 AUG | STS SOHAR | UKC | 5.9M | ADMIC |
| LIPSI | 90 | ULSD | 28 AUG | TAIWAN | SPORE | 1.0M | BP |
- GLOBAL BUNKER PRICE REPORT
(US$/MT)
| 11-Aug | 12-Aug | 13-Aug | 3-DAYS AVERAGE |
1-DAY CHANGE |
3-DAYS CHANGE | |
|---|---|---|---|---|---|---|
| VLSFO 0.5 | ||||||
| SINGAPORE | 847.5 | 844.5 | 831.0 | 841.0 | -13.5 | -16.5 |
| FUJAIRAH | 833.0 | 819.5 | 815.0 | 822.5 | -4.5 | -18.0 |
| ROTTERDAM | 660.0 | 662.5 | 661.0 | 661.2 | -1.5 | +1.0 |
| HOUSTON | 712.0 | 716.5 | 695.0 | 707.8 | -21.5 | -17.0 |
| GLOBAL MARKET | 823.5 | 820.5 | 814.5 | 819.5 | -6.0 | -9.0 |
| MGO | ||||||
| SINGAPORE | 1210.5 | 1236.5 | 1226.0 | 1224.3 | -10.5 | +15.5 |
| FUJAIRAH | 1378.5 | 1387.0 | 1387.5 | 1384.3 | +0.5 | +9.0 |
| ROTTERDAM | 1272.0 | 1248.0 | 1234.0 | 1251.3 | -14.0 | -38.0 |
| HOUSTON | 1272.5 | 1260.5 | 1263.5 | 1265.5 | +3.0 | -9.0 |
| GLOBAL MARKET | 1391.0 | 1374.0 | 1373.0 | 1379.3 | -1.0 | -18.0 |
| IFO 380 (HSFO) | ||||||
| SINGAPORE | 639.0 | 635.5 | 627.5 | 634.0 | -8.0 | -11.5 |
| FUJAIRAH | 616.5 | 620.5 | 618.0 | 618.3 | -2.5 | +1.5 |
| ROTTERDAM | 543.0 | 534.0 | 537.5 | 538.2 | +3.5 | -5.5 |
| HOUSTON | 488.5 | 485.5 | 472.0 | 482.0 | -13.5 | -16.5 |
| GLOBAL MARKET | 636.5 | 629.5 | 629.5 | 631.8 | – | -7.0 |
VLSFO prices remained firm during the week, with all major bunkering hubs recording weekly gains. Ongoing tensions around the Strait of Hormuz continued to support oil prices, while concerns over disrupted crude flows kept a geopolitical premium in the market. However, weaker demand expectations and a large increase in U.S. crude inventories have limited further price gains.
MGO recorded the strongest weekly increase among the three bunker grades, supported by tight global diesel supply. Recent refinery disruptions in Russia and Saudi Arabia, together with low U.S. distillate inventories and continued problems around the Strait of Hormuz, have tightened the diesel market and pushed middle-distillate prices higher.
HSFO prices also increased across all major bunkering hubs during the week, although the gains were smaller than those seen in MGO. Continued disruption to global oil flows and higher crude prices provided support to fuel oil prices, while weaker demand expectations and rising U.S. crude inventories limited the upside.
- SHIPPING STOCKS MARKET WATCH
As the Middle East has no sign of significant breakthroughs, the shipping equity market has a bullish run due to increased tone-miles. Torm closed the week by 2.42%, Ardmore +1.73%, and Frontline +1.70%. Meanwhile, the Nordic shares were flat, but D/S Norden managed to gain +1.80%.
- SOURCES
- International Maritime Organization (2024/2026) – Guidelines on Maritime Cyber Risk Management / Maritime Cyber Risk. Accessed August 2026.
- International Association of Classification Societies (IACS) (2023–2024) – UR E26 Cyber Resilience of Ships and UR E27 Cyber Resilience of On-Board Systems and Equipment. Accessed August 2026.
- BIMCO et al. (2024) – The Guidelines on Cyber Security Onboard Ships, Version 5. Accessed August 2026.
- BIMCO – Cyber Risk Management. Accessed August 2026.
- DNV (2024/2025) – Maritime Cyber Priority 2024/25: Managing Cyber Risk to Enable Innovation. Accessed August 2026.
- European Union Agency for Cybersecurity (ENISA) (2019) – Port Cybersecurity: Good Practices for Cybersecurity in the Maritime Sector. Accessed August 2026.
- European Union Agency for Cybersecurity (ENISA) (2024) – ENISA Threat Landscape 2024. Accessed August 2026.
- United States Coast Guard / Federal Register (2025) – Cybersecurity in the Marine Transportation System. Accessed August 2026.
- DNV (2024) – Maritime Cyber Priority 2024/25: Managing Cyber Risk in an Increasingly Connected Maritime Industry. Accessed August 2026. DNV Maritime Cyber Priority 2024/25
- DNV (2024) – Maritime Appetite for Cyber Risk Notably Higher Than Other Key Industries, New Report Reveals. Accessed August 2026. DNV
- DNV – Tackling a Growing Cybersecurity Threat in an Increasingly Connected Industry. Accessed August 2026. DNV Maritime Impact
- European Union Agency for Cybersecurity (ENISA) (2023) – ENISA Transport Threat Landscape. Accessed August 2026. ENISA Transport Threat Landscape
- European Union Agency for Cybersecurity (ENISA) (2023) – Understanding Cyber Threats in Transport. Accessed August 2026. ENISA
- CyberOwl, Thetius & HFW (2022) – The Great Disconnect: The State of Cyber Risk Management in the Maritime Industry. Accessed August 2026. CyberOwl – The Great Disconnect
- Thetius – Connecting Trends: Charting Progress Since The Great Disconnect Report. Accessed August 2026. Thetius
- Maritime and Port Authority of Singapore (2025) – Driving Growth and Innovation to Strengthen Maritime Competitiveness and Resilience. Accessed August 2026.
- S&P Global Commodity Insights (Platts). Clean tanker freight assessments and tanker market intelligence, accessed UG 2026.
- Firstlink Research Team. (2026). Internal Market Analysis on Heatwaves, Energy Demand and Implications for the Shipping Market. Firstlink Global Pte. Ltd., Singapore.
6 Comments
Technology is a powerful leverage. It narrows the knowledge and efficiency gap between smaller and larger companies. The caveat is how well each company can protect and control the mismanagement and threats. Thus digital and technology must be taken care of in every company’s business processes.
Honestly, I used to think cyberattacks were just about stolen passwords or hacked email accounts. It’s crazy to see how a digital hack can physically freeze entire ports and stop ships from moving! Thanks for sharing.
A system is only as strong as its last defence and Hackers should be employed to test the rigours and strengths of the systems.
Digital threats can quickly become operational disruptions and commercial losses.
thanks for this informative cybersecurity topics.
Interesting to see how technology also brings new risks to shipping.