Atlantic Council maps maritime cyber risk
A policy report examines systemic cyber risks across ships, ports, and cargo systems in the global maritime transportation system, citing past incidents like NotPetya and Ryuk.
This Atlantic Council report is a policy-oriented analysis of cybersecurity risk across the maritime transportation system (MTS), treating it as a 'system of systems' spanning ships, ports, and cargo. It categorizes systemic risk into human factors (social engineering, poor cyber hygiene, unauthorized/insider access, overcomplicated technology) and systems risk (OT/ICS, IT networks, PNT/GPS-AIS spoofing, and ransomware), drawing on historical incidents to illustrate each category.
The report cites well-known past events rather than new intelligence: the 2017 NotPetya attack on Maersk, the 2018 COSCO ransomware incident, the 2019 Ryuk attack on a US port facility disrupting cargo monitoring for 30 hours, 2020 ransomware hits on Carnival, CMA CGM, Garmin, Hurtigruten, Port of Kennewick, and Toll Group, plus the 2019 Holland America/Princess Cruises phishing breach. It also references OT-focused attacks such as Stuxnet, Shamoon (Saudi Aramco/RasGas), and Triton/Trisis, alongside long-documented weaknesses like default passwords on satellite terminals (Globalstar, SAILOR 900 VSAT) and GPS/AIS spoofing including reported Russian activity.
Overall, this is a retrospective and structural risk assessment rather than a report of new active threats, intended to inform maritime cybersecurity policy and industry coordination. Severity is assessed as low since it presents no new exploited vulnerability, active campaign, or fresh incident—only synthesis of historical case studies to support risk-based recommendations.
Mentioned in this report
Source reporting: https://www.atlanticcouncil.org/in-depth-research-reports/report/cooperation-on-maritime-cybersecurity-a-system-of-systems
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free