In March 2026, a major terminal operator was hit by a ransomware attack that encrypted its Terminal Operating Systems, stopping all container loading and unloading (Shipping Telegraph, 2026). Ships waited at anchor, cargo piled up, and staff switched to paper records and manual coordination. This was like removing the digital brain from a facility that handles tens of thousands of containers each week. This incident was not unique. It matched a pattern predicted by CYTUR’s 2026 Maritime Cyber Threat White Paper: attackers are now focusing on global hub ports such as Rotterdam, Los Angeles, and Busan. As the report notes, “the paralyzation of even a single major port can trigger a severe bottleneck effect across the entire global supply chain,” leading to oil price spikes, inflation, and widespread delays across ocean, rail, and trucking networks (Safety4Sea, 2026). For years, maritime cybersecurity discussions have centered on threats to ships, like GPS spoofing and ransomware on vessel systems. Meanwhile, ports, the land-side infrastructure essential to every vessel and supply chain, have received far less attention. Data from 2025 and 2026 shows that this lack of focus is becoming a major issue for critical infrastructure security.
The rise in cyberattacks on logistics infrastructure is striking. According to Everstream Analytics’ 2026 Annual Supply Chain Risk Report, there were 20 cyber incidents in 2021 affecting carriers, ports, and logistics providers. By 2025, this number had jumped to 213—a 965 percent increase in four years (Supply Chain 24/7, 2026; Logistics Management, 2026). In 2025 alone, incidents rose 61 percent, from 132 to 213 cases. Everstream predicts that cyberattacks on logistics will double again in 2026, driven by more automation, greater digital integration, and increased activity from state-sponsored groups (Supply Chain 24/7, 2026). The 2026 report called 2025 “a watershed moment for cyberattacks on logistics,” marking a major shift in the scale and coordination of these attacks (Talking Logistics, 2026).
In 2025, global ransomware incidents rose by 32 percent, reaching 7,419 cases, according to Check Point Research’s Manufacturing Threat Landscape 2026 report (Industrial Cyber, 2026). In manufacturing, which is closely tied to port activity, ransomware cases increased by 56 percent compared to the previous year. The attackers are no longer just criminals. Everstream found that more attacks in 2025 came from state-sponsored groups linked to Russia, China, and Iran. These groups targeted maritime infrastructure, airports, and transport networks in several countries at once, showing a level of coordination beyond typical criminal organizations (Supply Chain 24/7, 2026). Cyble’s analysis counted 6,604 ransomware attacks across all industries in 2025, a 52 percent jump from 2024, with Qilin, Akira, and Play as the main criminal groups (Cyble, 2026). The average cost of a maritime cyber incident is now over $550,000, and ransom payments can reach $3.2 million when attackers are not removed (Breached.company, 2025).
The Terminal Operating System: The Port’s Unprotected Brain
Modern container ports rely on Terminal Operating Systems (TOS) to manage crane assignments, berth schedules, container tracking, vessel stowage, gate operations, and customs paperwork in real time. A TOS is not just extra software that can be turned off for a while; it is the port’s brain. Without it, equipment like cranes and trucks can still move, but they lose the coordination needed to work efficiently. As CYTUR’s White Paper explains, when attackers encrypt a Terminal Operating System, they “completely halt container loading and unloading operations” not by damaging equipment, but by disrupting the digital system that tells everyone what to do. The machines keep moving, but nothing gets done because no one knows where anything should go (Safety4Sea, 2026).
This is exactly what happened during the December 2025 ransomware attack on a terminal operator, and again on a smaller scale at the Port of Vigo in early 2026. When ransomware struck Vigo, Spain’s largest fishing port and a key cargo hub, it encrypted the servers that managed cargo traffic and digital services. The port had to disconnect affected systems from external networks and switch to paper records and manual processes (The Record, 2026). Port president Carlos Botana said systems would stay offline until security teams were sure there was no remaining threat, with no set timeline for restoration (The Record, 2026). The Border Inspection Post, which handles all cargo from outside the EU, was also disrupted. This caused not just delays but also legal compliance issues for ships unloading regulated cargo (Apolo Cybersecurity, 2026). The real lesson from the Vigo attack was not its size, but how easily a port’s reliance on digital systems can lead to a complete shutdown when those systems are attacked.
Shore-side ransomware threats have been around for years. The maritime industry has not made the structural changes needed, despite a clear history of attacks. The NotPetya attack in June 2017 is a key example. This Russian GRU-linked malware spread through compromised Ukrainian accounting software. After entering Maersk’s network via one infected computer in Odessa, NotPetya quickly spread to 4,000 servers and 45,000 PCs in over 130 countries (SOS Intelligence, 2024). Maersk had to switch to manual operations at terminals in 76 ports, leaving ships stranded and cargo stuck in places like Los Angeles, New York, and Rotterdam (StaunchTec, 2025). Maersk alone lost over $300 million, and the total supply chain damage, including losses at TNT Express ($400 million) and Merck ($870 million), reached about $10 billion (Control Engineering, 2025). White House Homeland Security adviser Tom Bossert called it “the equivalent of using a nuclear bomb to achieve a small tactical victory” (Control Engineering, 2025, para. 8).
Six years after NotPetya, the maritime industry still had not made needed changes. In July 2023, LockBit 3.0 attacked the Port of Nagoya, Japan’s largest port, which handles over two million containers and 165 million tonnes of cargo each year, including all of Toyota’s exports. The attack shut down container terminal operations for two and a half days (Dragos, 2023; Industrial Cyber, 2023). Toyota’s supply chain was disrupted, and the LockBit group demanded a ransom for the decryption key. The port restored operations by isolating affected servers and using backups, but the shutdown showed that the NotPetya approach had become a service that any criminal could buy. In November 2023, DP World Australia was hit by a cyberattack that stopped operations at ports handling 40 percent of Australia’s container trade, causing a backlog of over 30,000 containers and days of delays (NATO CCDCOE, 2025). The BlackCat ransomware group, linked to state actors, attacked German oil companies in 2022, and the Conti group targeted the international terminal operator Sea-Invest in Ghent (NATO CCDCOE, 2025). According to a CCDCOE policy brief, at least 45 maritime organizations were hit by ransomware in 2024, and “the actual number is likely to be much higher” because many incidents go unreported in the maritime sector (NATO CCDCOE, 2025, para. 5).
Everstream Analytics explains why ports and logistics infrastructure are now top targets for both criminal and state-sponsored ransomware groups. Attackers have moved from hitting single companies to targeting shared transportation networks, where one breach can affect thousands of connected businesses at once (Supply Chain 24/7, 2026). Ports are a prime example. Each major container port is a shared hub for many shipping lines, freight forwarders, trucking companies, and customs agencies, all relying on the same digital systems. When these systems fail, the impact spreads quickly to everyone whose cargo and operations depend on the port’s digital coordination.
Reports from Fox Business and CBS News show that losing a major West Coast port could cost the local economy $2 billion per day (CBS News, 2025). This number highlights how attackers know that the economic fallout from a successful ransomware attack is much greater than the cost to carry it out. CYTUR’s analysis details the effects: when port terminal systems are encrypted, “container operations grind to a halt, forcing tankers and cargo ships in nearby waters to wait indefinitely,” which leads to oil price spikes and inflation (Safety4Sea, 2026). Rotterdam, Europe’s busiest port and main entry point for energy and goods to the EU, has faced DDoS attacks from Russian NoName057(16) and is considered at high risk (NATO CCDCOE, 2025). Los Angeles and Busan, along with Rotterdam, are among the world’s most important container ports. All three have high throughput, heavy digital integration, and security systems that were not built for today’s threats.
Securing ports is much more complex than securing vessels, though this is rarely discussed in policy circles. Ships are self-contained systems with clear boundaries and limited points of attack. In contrast, a major container port is a network of hundreds of connected organizations like the port authority, terminal operators, shipping agents, customs brokers, trucking companies, fuel suppliers, and maintenance contractors, all with different levels of access and security (Everstream Analytics, as cited in Supply Chain 24/7, 2026). The NotPetya attack on Maersk started with accounting software on a single computer in Odessa, not a port or maritime system, but a regular business application used by an employee (Control Engineering, 2025). The entry point for the DP World Australia attack is still unknown, but many recent attacks have come through third-party providers, suggesting that supply chain infiltration is a growing risk (Supply Chain 24/7, 2026).
The CCDCOE policy brief identified the specific governance failure that compounds this structural complexity: “supply chain partners struggle to share cybersecurity information, preventing lessons learned at one port from aiding others. A lack of data centralization and inconsistent damage-estimation methods further degrade cybersecurity information quality” (NATO CCDCOE, 2025, para. 8). Every major port attack generates forensic knowledge about attack vectors, dwell times, and lateral movement patterns that could be used to harden defenses at other facilities, and that knowledge systematically fails to circulate because no mandatory incident reporting and intelligence sharing architecture exists that would require it to. The USCG’s 2025 final cybersecurity rule mandates incident reporting to the National Response Center — a necessary step — but does not create the analytical and dissemination infrastructure that would translate those reports into actionable intelligence for other port operators.
Ransomware attacks on port infrastructure are not traditional maritime security problems. They do not show up on vessel tracking systems, cause visible incidents at sea, or create dramatic scenes like ships running aground or tankers on fire. Instead, these attacks look like software outages at land-based facilities, handled first by IT teams, while ships wait at anchor and cargo misses connections across global supply chains. The hidden nature of these attacks makes them especially useful for state-sponsored groups who want to cause economic harm without starting open conflict. Everstream predicts that logistics cyberattacks will double in 2026, on top of an already huge increase. This is not just a future risk—it is the reality that port security managers and risk professionals face today. The shore side of the maritime industry is under attack, but most security spending is still focused on threats at sea.
Apolo Cybersecurity. (2026, March). Cyberattack on the Port of Vigo: What happened and why it matters.https://www.apolocybersecurity.com/en/blog-posts/ciberataque-al-puerto-de-vigo-que-ha-pasado-y-por-que-importa
Breached.company. (2025, September 17). Pirates in the digital seas: The global maritime cybersecurity crisis.https://breached.company/pirates-in-the-digital-seas-the-global-maritime-cybersecurity-crisis/
CBS News. (2025, February 12). Chinese cranes at U.S. ports raise homeland security concerns.https://www.cbsnews.com/news/chinese-cranes-at-u-s-ports-raise-homeland-security-concerns/
Control Engineering. (2025, August 14). Throwback attack: How NotPetya ransomware took down Maersk.https://www.controleng.com/throwback-attack-how-notpetya-accidentally-took-down-global-shipping-giant-maersk/
Cyble. (2026, January 23). Ransomware attacks and supply chain threats in 2025.https://cyble.com/blog/ransomware-attacks-supply-chain-threat-landscape/
Dragos. (2023, July). OT cybersecurity breach disrupts operations at the Port of Nagoya, Japan.https://www.dragos.com/blog/ot-cybersecurity-breach-disrupts-operations-at-the-port-of-nagoya-japan
Industrial Cyber. (2023, July 6). Operations at Japan’s Port of Nagoya resume after probable LockBit ransomware attack.https://industrialcyber.co/transport/operations-at-japans-port-of-nagoya-resume-after-probable-lockbit-ransomware-attack/
Industrial Cyber. (2026, January 8). Everstream warns cyberattacks, hybrid warfare, and trade policy weaponization set to disrupt supply chains in 2026.https://industrialcyber.co/supply-chain-security/everstream-warns-cyberattacks-hybrid-warfare-and-trade-policy-weaponization-set-to-disrupt-supply-chains-in-2026/
Industrial Cyber. (2026, April). Manufacturing absorbs 56% ransomware surge of global attacks in 2025.https://industrialcyber.co/manufacturing/manufacturing-absorbs-56-ransomware-surge-of-global-attacks-in-2025-as-raas-legacy-ot-supply-chains-fuel-spike/
Logistics Management. (2026, January 12). Cyberattacks on logistics are expected to double in 2026, says Everstream Analytics.https://www.logisticsmgmt.com/article/cyberattacks_on_logistics_are_expected_to_double_in_2026_says_everstream_analytics
NATO Cooperative Cyber Defence Centre of Excellence. (2025). Addressing state-linked cyber threats to critical maritime infrastructure. https://ccdcoe.org/uploads/2025/07/CCDCOE_Policy_Brief.pdf
Safety4Sea. (2026, February). Maritime cyber incidents jumped 103% in 2025.https://safety4sea.com/maritime-cyber-incidents-jumped-103-in-2025/
Shipping Telegraph. (2026). ‘The era of disconnected seas is over’: Maritime cyber incidents in 2025 surged by 103%.https://shippingtelegraph.com/shipping-reports/the-era-of-disconnected-seas-is-over-maritime-cyber-incidents-in-2025-surged-by-103/
SOS Intelligence. (2024, October 18). Case study: Maersk’s response to NotPetya.https://sosintel.co.uk/case-study-maersks-response-to-notpetya-how-cybersecurity-best-practices-mitigated-a-major-cyberattack/
StaunchTec. (2025, August 29). Maritime cyber incidents and digital threats 2025.https://staunchtec.com/maritime-cyber-incidents-digital-threats-2025
Supply Chain 24/7. (2026, January 12). Cyberattacks on logistics are set to double in 2026, report finds.https://www.supplychain247.com/article/cyberattacks-on-logistics-set-to-double-2026-report
Talking Logistics. (2026, January 27). Is your supply chain ready for a cyberattack? https://www.talkinglogistics.net/p/is-your-supply-chain-ready-for-a
The Record. (2026, March). Ransomware attack disrupts operation at major Spanish fishing port.https://therecord.media/port-of-vigo-ransomware