Public Database Reveals 20 Years of Maritime Cyberattacks

A newly launched public database is shining light on more than two decades of cyber incidents at sea, from spoofed warships to ransomware in ports. The archive highlights how digital threats are reshaping maritime security and the flow of global trade.

From Spoofed Ships to Port Disruptions

The Maritime Cyber Attack Database (MCAD), developed by NHL Stenden’s Maritime IT Security research group, contains details of over 160 documented cases since 2001. Among the most high-profile is Russia’s 2021 spoofing of NATO warships visiting Ukraine, when signals falsely showed British and Dutch vessels near Crimea’s naval base. Other entries highlight cyberattacks on port operating systems, ransomware incidents, and disruptions to vessel navigation, reflecting the diverse range of risks that extend far beyond military maneuvers.

Professor Stephen McCombie, who leads the project, said the database was created to help governments and companies recognize both the scale and the intent behind these attacks. “The scope of what is possible today is surprising,” he noted, emphasizing that cyber intrusions in maritime environments often aim not just to steal data, but to provoke responses, disrupt commerce, or test resilience.

Rising Stakes for Global Trade

The release of MCAD comes at a time when cyber vulnerabilities in critical infrastructure are under heightened scrutiny. Recent data from Allianz shows that ransomware remains the top cyber threat for transport and logistics operators, with downtime costs often exceeding direct ransom payments. For the maritime sector, where 90% of world trade depends on predictable shipping flows, even short-lived disruptions can ripple across supply chains.

By drawing from open-source reporting and encouraging new submissions, MCAD aims to provide both an archive for researchers and a practical reference point for operators. Analysts say the database could help shape more realistic simulations, strengthen incident response planning, and inform future regulation, particularly as governments in the EU and U.S. push for higher cybersecurity standards in transport and critical infrastructure.

The Unseen Risk in Digital Transparency

While MCAD’s public release strengthens industry awareness, it also raises a less discussed concern: attackers can study the same records to refine their tactics. Cybersecurity experts note that adversaries often exploit open-source intelligence as effectively as defenders do. For maritime operators, the value of shared visibility will depend on pairing transparency with active investment in resilience, ensuring the database becomes a deterrent, not a roadmap, for the next wave of attacks.

Subscribe to Newsletter

Don’t miss tomorrow’s supply chain industry news

Let Supply Chain 360’s free newsletter keep you informed, straight from your inbox.

Tip: select one or more digests.

EVENTS

03 MAR
LIVE EVENT | The Belfry, Birmingham, UK

SupplyChain360 Summit

3rd & 4th March 2027
06 OCT
LIVE EVENT | Soho Hotel London

SupplyChain360 Forum

6th October 2026