The increasing reliance on satellite communications to operate ships’ onboard systems has exposed the maritime industry to a surge in cyberattacks, a leading maritime cybersecurity firm has warned. Recent incidents involving at least two vessels highlight the growing vulnerability of vessels connected to satellite networks.
According to Cydome, a cybersecurity company specializing in maritime systems, attacks targeting “edge devices” that link ships to external satellite networks rose sharply from 3% of all attacks in 2024 to 22% in 2025. The company estimates the number of these attacks reached into the hundreds. Marc Oppenheim, regional business director at Cydome, described the growing risk, noting that virtually all ship systems—ranging from engines to navigation—are networked via satellite to shore-based operations, making ships “a floating attack surface.”
Typically, hackers have attempted to deploy ransomware on ship systems, locking vessels’ digital functions until ransom payments are made. However, shipping executives express concern that as automation increases, attackers may seek direct control over critical ship operations, posing greater risks to maritime safety.
Cydome expects the trend to intensify, driven in part by escalating geopolitical tensions and the deployment of artificial intelligence tools by attackers to identify system vulnerabilities more efficiently.
U.S. officials are currently investigating potential Iranian cyber intrusions targeting two oil tankers en route from the Middle East to the United States. One of these, the VL Prosperity, a South Korean-managed vessel transporting two million barrels of Gulf crude oil, was reportedly hacked while transiting the Strait of Gibraltar in August. Ship-tracking data indicated the vessel experienced an abrupt slowdown during the incident.
Iran’s Mehr News Agency reported the VL Prosperity lost communication capabilities for approximately 30 hours, disrupting onboard operations. These claims have not been independently verified. In response, the U.S. Coast Guard boarded the vessel on August 21 to assess the integrity of its operational and information technology systems. The identity of the second tanker remains undisclosed.
Cydome characterized the attack on the VL Prosperity as clear evidence that regional geopolitical tensions are increasingly influencing civilian maritime transport. The firm also noted that as ships become more integrated with land-based control centers and satellite systems, the distinction between operational technology, which controls physical equipment such as navigation and engines, and traditional IT systems is becoming less distinct, complicating cybersecurity defenses.
The International Chamber of Shipping’s annual survey this year ranked cyberattacks as the second-highest threat to maritime operations. However, cybersecurity preparedness was only rated fifth in terms of the industry’s ability to manage these risks. The shipowners’ association Bimco highlighted factors that increase ships’ exposure to cyberattacks, including the involvement of multiple stakeholders such as charterers and crew members, and the necessity of sharing information between ships and shore-based entities.
