For much of the digital age, the operational technology (OT) systems that run a ship’s engines, ballast pumps, cargo equipment, and navigation tools were kept separate from the information technology (IT) systems used for communications, logistics, and crew welfare. This physical separation, often called the “air gap,” acted as a basic but effective security measure. If someone hacked a ship’s email servers, they could disrupt communications but not stop the engines. That separation no longer exists. The rise of high-speed satellite connections, cloud-based maintenance, and sensor-driven monitoring has erased the line between IT and OT on modern ships. Now, a single breach can move from a crew welfare network into the core systems that control whether a ship can move, steer, or stay afloat. Cydome’s 2026 Maritime Cyber Trends Report found a 150 percent increase in maritime OT cyber incidents in 2025, with 87 percent involving ransomware. These attacks have shifted from encrypting office files to stopping ballast water controls and disabling engine monitoring in real time (Industrial Cyber, 2026). This essay looks at the IT/OT convergence threat, ransomware campaigns now targeting ship operations, and what this means for vessel safety, port operations, and global supply chains.
For much of the digital age, the operational technology (OT) systems that run a ship’s engines, ballast pumps, cargo equipment, and navigation tools were kept separate from the information technology (IT) systems used for communications, logistics, and crew welfare. This physical separation, often called the “air gap,” acted as a basic but effective security measure. If someone hacked a ship’s email servers, they could disrupt communications but not stop the engines. That separation no longer exists. The rise of high-speed satellite connections, cloud-based maintenance, and sensor-driven monitoring has erased the line between IT and OT on modern ships. Now, a single breach can move from a crew welfare network into the core systems that control whether a ship can move, steer, or stay afloat. Cydome’s 2026 Maritime Cyber Trends Report found a 150 percent increase in maritime OT cyber incidents in 2025, with 87 percent involving ransomware. These attacks have shifted from encrypting office files to stopping ballast water controls and disabling engine monitoring in real time (Industrial Cyber, 2026). This essay looks at the IT/OT convergence threat, ransomware campaigns now targeting ship operations, and what this means for vessel safety, port operations, and global supply chains.
The merging of IT and OT systems on ships did not happen by accident. It is a result of the maritime industry’s push for greater efficiency. Real-time performance monitoring needs sensor data from OT systems to be sent to shore-based analysis platforms. Predictive maintenance depends on constant connections between engine monitoring software and technical support from equipment makers. Remote operation, now common on modern ships, requires direct network links between shore operators and onboard control systems. Each of these necessary functions creates a route that attackers can use to move from the ship’s IT network into its OT core.
Cydome’s analysis found that 22 percent of organizations experienced an OT/ICS cyber incident in 2025, with OT incidents now accounting for 20 percent of all reported cyber events — a sharp increase driven by attackers’ strategic shift from targeting administrative gateways to directly accessing programmable logic controller (PLC) devices and industrial control systems (Industrial Cyber, 2026). CYTUR’s 2026 White Paper characterized the most alarming current incidents as extending to “worst-case scenarios: destroyed equipment, hacked ECDIS chart systems, and remote control of ballast valves” — physical safety-critical consequences that would have been science fiction a decade ago (Maritime Executive, 2026). As Newport S.A. Group CIO Theofano Somaripa put it with unusual directness: “Operational technology, not internet access, is the hidden risk, and why cybersecurity must become everyone’s responsibility” (Digital Ship, 2025, para. 6).
Attackers often reach OT systems by bypassing even advanced security barriers. Cydome’s CyberOwl analysis showed that USB drives are still the main way malware gets onto ships, making up 75 percent of all malware incidents in 2024 and staying at similar levels in 2025. This is because crew members often use personal or maintenance devices on ships where USB security is not enforced (Maritime Executive, 2025). Remote access routes, which increased from four percent of incidents in 2023 to 13 percent in 2024, are the fastest-growing entry point. This growth is directly linked to the digital changes ship operators and equipment makers have made to improve efficiency (Maritime Executive, 2025).
The ransomware threat to maritime OT has changed a lot since the 2017 NotPetya attack, which cost Maersk $300 million but did not stop ships from operating at sea (MarineLink, 2026). By 2023, when the DarkAngels ransomware group attacked DNV’s ShipManager platform, attackers had started using a “hub-and-spoke” approach. They would compromise one software system to affect the 1,000 vessels that relied on it (MarineLink, 2026). In 2025 and 2026, the threat has grown even more serious. Ransomware now targets not only booking and logistics systems but also the core systems that control how ships operate.
CYTUR reported several cases in 2025 where ransomware encrypted Planned Maintenance Systems (PMS), which control scheduled maintenance and create voyage logs. This forced operators to pay to get back documents needed for regulatory compliance and port clearance (Maritime Executive, 2026). In October 2025, the Japanese company FURUNO, which makes radar and ECDIS systems, was attacked by the Rhysida ransomware group. This attack disabled backup systems and showed how vulnerable OEM software supply chains are (Splash247, 2026). Ransomware attacks at major ports have also increased. CYTUR’s White Paper said that in December 2025, a large terminal operator was hit by ransomware that encrypted Terminal Operating Systems (TOS), stopping all container loading and unloading (Shipping Telegraph, 2026). In early 2025, a European port suffered a major cyberattack by state-sponsored hackers (Shipping Telegraph, 2026). CYTUR pointed out that shutting down even one major hub port “can trigger a severe bottleneck effect across the entire global supply chain,” leading to widespread delays in vessel schedules, cargo handling, customs, and energy markets (Safety4Sea, 2026).
The ransomware groups targeting maritime infrastructure have changed from random criminals to organized crime networks. CYTUR’s 2026 White Paper described growing partnerships between politically motivated hackers and profit-driven ransomware groups. Politically motivated groups, such as Russian-aligned NoName057, pro-Palestinian collectives, and anti-Iranian factions, now provide targeting information and access to ransomware-as-a-service (RaaS) tools (Safety4Sea, 2026). A CCDCOE policy brief reported that NoName057 carried out DDoS attacks on Belgian telecom, health, and defense websites as part of ongoing cyber pressure on EU countries. Pro-Palestinian hackers have also targeted Israeli-linked ships by using AIS data to plan attacks (CCDCOE, 2025; Cyble, 2025). CYTUR calls these trends “cartelisation,” meaning ransomware attacks on maritime targets now have geopolitical motives that standard commercial response plans are not prepared to handle.
The CCDCOE brief named the Russia-linked, China-aligned Chamel Gang as using ransomware against transportation and logistics companies in a campaign aimed at sectors that support Ukraine or align with U.S. interests (Cyble, 2025). Cyble’s dark web researchers found that hackers are selling sensitive maritime data, including a 1TB cache allegedly stolen from a European defense contractor. This cache contains source code for command systems, network details, and classified technical documents (Cyble, 2025). Because criminal ransomware and state-backed spying now use the same attack methods, operators who think they are dealing with a simple ransom may also be targets of strategic information gathering.
When ransomware crosses from IT to OT systems, the costs rise sharply. Cydome’s 2026 analysis found that these dual IT/OT attacks now cost an average of $4.56 million per incident. This amount includes ransom payments, recovery expenses, and the losses from ships being unable to operate safely while OT systems are down (Industrial Cyber, 2026). The most affected operators are those with the most digital integration, making them more dependent on the systems under attack. Large tanker fleets, LNG carriers with complex cargo systems, and container ships with automated loading and stability controls are both the most valuable and the most at risk from OT attacks.
Regulators have started to respond. IACS UR E26 now requires OT security to be built into vessel design from the start, treating the ship as a “system of systems” instead of securing IT and OT separately (MarineLink, 2026). UR E27 adds that equipment makers must include security features like multi-factor authentication and fail-safe modes in engine controls, ECDIS, and cargo management systems (Speedcast, 2025). The U.S. Coast Guard’s 2025 rule calls for network segmentation, supply chain security, and cybersecurity plans that specifically protect OT systems (Pen Test Partners, 2025). Industry experts agree these rules are a good foundation, but there is still a big gap between what regulations require and what happens in practice. Attackers are taking advantage of this gap, tracking compliance deadlines as closely as defenders track software updates.
The threat from IT/OT convergence in maritime is not just a future concern; it is already happening, as shown by recent incidents on active vessels. Ransomware has changed from simply disrupting business to threatening physical safety by disabling systems that control navigation, stability, and cargo management. The groups behind these attacks now mix criminal motives with geopolitical goals, using maritime infrastructure for both profit and as a tool in international conflicts. The IACS and USCG regulations offer a solid starting point for better maritime cyber security, but only if operators see them as a minimum standard and work to build real OT security, not just check off compliance boxes while leaving systems exposed.
Cydome. (2026). Maritime cyber trends report 2026: What shipping executives need to know.https://industrialcyber.co/transport/cydome-report-finds-150-surge-in-maritime-ot-cyberattacks-as-ransomware-tightens-grip-in-2025/
Cyble. (2025, July 29). Cyber threats surge against maritime industry in 2025.https://cyble.com/blog/cyberattacks-targets-maritime-industry/
Digital Ship. (2025). Maritime faces rising cyber threats in 2025.https://thedigitalship.com/news/maritime-satellite-communications/maritime-faces-rising-cyber-threats-in-2025/
Industrial Cyber. (2026, March). Cydome report finds 150% surge in maritime OT cyberattacks as ransomware tightens grip in 2025.https://industrialcyber.co/transport/cydome-report-finds-150-surge-in-maritime-ot-cyberattacks-as-ransomware-tightens-grip-in-2025/
MarineLink. (2026, March). Navigating the “Third Era” of maritime cyber risk.https://www.marinelink.com/news/navigating-third-era-maritime-cyber-risk-536724
Maritime Executive. (2025, November 15). Cyber proofing. https://maritime-executive.com/magazine/cyber-proofing
Maritime Executive. (2026, February 24). Report: Maritime cyberattacks doubled in 2025.https://maritime-executive.com/article/report-maritime-cyberattacks-doubled-in-2025
NATO Cooperative Cyber Defence Centre of Excellence. (2025). Addressing state-linked cyber threats to critical maritime infrastructure. https://ccdcoe.org/uploads/2025/07/CCDCOE_Policy_Brief.pdf
Pen Test Partners. (2025, September 10). New mandatory USCG cyber regulations: What you need to know.https://www.pentestpartners.com/security-blog/new-mandatory-uscg-cyber-regulations-what-you-need-to-know/
Safety4Sea. (2026, February). Maritime cyber incidents jumped 103% in 2025.https://safety4sea.com/maritime-cyber-incidents-jumped-103-in-2025/
Shipping Telegraph. (2026, February). ‘The era of disconnected seas is over’: Maritime cyber incidents in 2025 surged by 103%.https://shippingtelegraph.com/shipping-reports/the-era-of-disconnected-seas-is-over-maritime-cyber-incidents-in-2025-surged-by-103/
Splash247. (2026, March 24). CYTUR issues sector playbooks amid rising maritime cyber threats.https://splash247.com/cytur-issues-sector-playbooks-amid-rising-maritime-cyber-threats/
Speedcast. (2025). Cybersecurity IACS E26 and E27. https://www.speedcast.com/blog-hub/2025/iacs-e26-e27-standards/