The Supply Chain Consequences of Maritime Cyber Attacks

In December 2025, the Adriatic Port Authority, which operates Italy’s Port of Ancona, reported a cyberattack later claimed by the Anubis ransomware group. The authority activated protective measures and notified the relevant agencies. Anubis subsequently listed the organisation on its leak site in January 2026. Public reporting has linked the incident to data compromise, although it has not established that a terminal operating system was encrypted or that port operations stopped entirely. The incident still illustrates the operational exposure that can arise when a port authority’s digital environment is compromised.

The incident was part of a broader increase in reported maritime cyber activity. CYTUR’s 2026 Maritime Cyber Threat White Paper recorded 828 maritime cyber incidents in 2025, compared with 408 in 2024, a 103 percent increase. The report also identified significant growth in ransomware and operational-technology-related attacks. These figures come from CYTUR’s own dataset rather than a definitive count of all global maritime cyber incidents, since reporting and classification methods vary between sources.

In early August 2026, North Carolina Ports confirmed that a cyberattack had disrupted IT systems at the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port. The organisation moved to manual processing, which delayed gate and port activities across the network. Public reporting did not identify the attacker or confirm ransomware, an operational-technology compromise or a data breach. Normal gate schedules resumed while IT restoration continued, showing how manual fallback procedures can help maintain some operations while also highlighting their limitations.

For shippers, incidents like these make cyber risk part of the freight-planning conversation. When a critical port system becomes unavailable, the practical questions are how quickly cargo can be processed, whether it can be diverted, and how long the wider network can absorb the disruption.

Why Ports Have Become Deliberate Targets

Recent incidents show that the operational consequences of a maritime cyberattack can vary considerably. A ransomware attack on the Port of Nagoya’s container-terminal system in July 2023 disrupted container gate and trailer operations for roughly two and a half days. Transnet’s July 2021 cyberattacks affected major South African ports, including Durban and Cape Town, forcing a shift to manual processes during the recovery period. The Port of Lisbon, by comparison, reported that its December 2022 cyberattack affected its website and data security without disrupting port operations.

Ports are attractive targets because they sit at important points in tightly scheduled supply networks. Their digital systems coordinate activities such as container movements, gate operations, equipment dispatch, yard planning, vessel operations, documentation and transfers between different modes of transport. When those
systems become unavailable, the effects can spread quickly through the physical network.

The financial impact can also extend well beyond the organisation that was attacked. Shippers, carriers, truckers and warehouse operators may face demurrage, detention, storage and labour costs, along with inventory delays and missed delivery commitments. Even when an operator restores systems through backups, incident response or manual processes, the disruption can continue to create costs for businesses further along the supply chain.

Several factors can increase a port or terminal’s exposure, including legacy technology, unsupported systems, remote-access services, weak identity controls, inadequate network segmentation and third-party connections. Maritime regulation has historically focused more heavily on physical safety and security, although cyber risk is now increasingly incorporated into maritime safety-management expectations. The International Maritime Organization’s revised 2025 guidance recommends managing cyber risk through identification, protection, detection, response and recovery.

Many attacks do not require a previously unknown vulnerability. Known weaknesses such as unpatched systems, inadequate multi-factor authentication, excessive user privileges and poor separation between IT and operational technology can provide attackers with an entry point. The threat also extends beyond ransomware to include state-linked activity, distributed denial-of-service attacks, third-party compromise and other forms of intrusion.

What a Terminal System Shutdown Produces

A terminal operating system is central to container-terminal planning and execution. It typically supports vessel planning, yard management, equipment dispatch, container inventory and gate workflows, while also connecting with truck, rail, customs and carrier systems. Other functions, including berth planning, vessel traffic management, customs release and rail operations, may run on separate platforms, although those systems can still be interconnected.

The consequences of a shutdown therefore depend heavily on the terminal’s architecture and its ability to operate without its main systems. Some facilities can maintain limited activity using paper records, manual gate verification or offline procedures. Others may be unable to handle normal cargo volumes until critical systems are restored.

For arriving vessels, a major outage can make berth allocations, discharge sequencing, equipment planning and yard capacity difficult to confirm. Depending on how long the disruption lasts, carriers may hold vessels at anchorage, reduce discharge activity, omit port calls or redirect cargo to another facility.

Cargo already inside the terminal can face similar problems. If the systems used to verify documentation, customs status, truck appointments or gate access are unavailable, cargo may remain in place even when the physical infrastructure is operating. Manual processing can keep some movements going, but it usually requires more time and reduces the terminal’s normal throughput.

The effects then reach transport providers. Truck appointments may be delayed or re-sequenced, while rail connections can be missed. That can increase driver waiting times, equipment costs, demurrage, detention and drayage expenses.

For importers and distribution centres operating with limited inventory buffers, the consequences can eventually reach production and fulfilment. A cyber incident can be particularly difficult to manage because its duration may not be clear at the outset. Recovery can depend on containment, forensic investigation, system validation, backup restoration and, in some cases, rebuilding affected infrastructure.

The Cascade Beyond the Port

A weather event, vessel delay or road closure will often give logistics teams some indication of the likely impact and duration. A cyberattack can be harder to assess in the early stages because several connected systems may be affected at once, while the operator may not yet know when normal processing will resume.

The disruption can extend well beyond the terminal itself. Freight waiting for rail, road, barge or inland distribution may miss planned connections if containers cannot be discharged, cleared, released or gated out on time. Warehouses may receive inventory later than planned, production sites may face component shortages and retailers may miss fixed promotional or seasonal delivery windows.

The costs are also spread across different parts of the network. The port or terminal may carry the expense of incident response and system recovery, while shippers deal with inventory costs, missed sales, expedited freight, storage, demurrage, detention and customer-service penalties. Trucking and drayage companies can incur additional driver and equipment costs, while carriers and forwarders may have to find alternative routes with limited notice.

Cyber risk also extends beyond IT and terminal systems. Connected ship-and-shore operations create more points of interaction, while navigation and communications systems can be affected by electronic interference. GNSS disruption is a separate risk that can affect vessel navigation. CYTUR- and Cydome-related reporting has estimated that around 1,000 GPS-disruption events are observed daily and may affect more than 40,000 vessels, although the methodology and definition of an “incident” should be made clear when using these figures.

On May 10, 2025, the container vessel MSC Antonia ran aground near Jeddah. Maritime intelligence providers assessed GPS jamming or spoofing as a likely contributing factor, although early public reporting described the cause as suspected rather than definitively established. The incident illustrates how maritime disruption can also arise through interference with navigation systems rather than a direct compromise of port or terminal IT.

The Structural Gap Shippers Cannot Close

Shippers have limited visibility into the cybersecurity posture of the ports, terminals, technology vendors, carriers, customs platforms and inland logistics providers they
rely on. Much of that infrastructure is managed by organisations operating under their own commercial, regulatory and operational priorities.

When a breach occurs, cargo owners can therefore face significant consequences without having any control over the systems, access policies, network architecture or recovery plans involved. A shipper may have containers sitting at a compromised terminal but little influence over which systems are restored first or when normal cargo processing resumes.

The U.S. Coast Guard’s final rule on cybersecurity in the Marine Transportation System took effect on July 16, 2025. It establishes baseline cybersecurity requirements for covered U.S. vessels, facilities and other regulated entities, subject to phased implementation requirements. The International Maritime Organization’s revised Guidelines on Maritime Cyber Risk Management, issued in April 2025, provide high-level, nonmandatory recommendations for managing cyber risk in shipping.

The International Association of Classification Societies’ Unified Requirements E26 and E27 address cyber resilience for ships and onboard systems under relevant classification arrangements. The revised requirements apply to new ships contracted for construction on or after July 1, 2024. These frameworks can affect classification, certification, contracting, insurance and regulatory compliance, although they do not create a universal rule that noncompliant vessels or equipment manufacturers will automatically be denied port entry.

Cyber insurance can help absorb some of the financial consequences, but it does not remove the operational exposure. Policies can contain exclusions, sublimits, waiting periods, aggregation risks and gaps in contingent business-interruption coverage. A major incident affecting a port or several connected logistics providers could also create losses across multiple insured parties at the same time.

For supply-chain leaders, this makes port cyber risk relevant to freight planning, business continuity, supplier risk and inventory decisions, rather than leaving it solely within the corporate security function.

What Freight Planning Looks Like with Cyber Risk Built In

Most supply-chain risk frameworks focus on disruptions involving vessels, carriers, weather, customs, geopolitics and trade lanes. Cyber risk adds another dimension because the physical infrastructure can remain intact while the systems needed to operate it become unavailable.

One practical response is to identify alternative terminals and inland gateways before they are needed. That assessment should consider the type of cargo being moved, hazardous-goods and reefer capabilities, customs arrangements, available berth and yard capacity, carrier services, rail and road connections, congestion and the additional cost and transit time associated with a diversion.

Freight contracts and forwarding arrangements also need workable contingency provisions. Businesses should know who can approve a diversion, how additional costs will be handled, whether cargo can be discharged at another terminal and what changes to documentation or inland transport would be required. These decisions become much harder when they are being made for the first time during an active disruption.

It is also worth looking at concentration risk across the network. A company that routes most of its cargo through one port, terminal operator, customs platform, carrier alliance or inland rail corridor may face significant disruption if that node becomes unavailable. Diversification does not necessarily mean moving away from efficient hubs. It means understanding what losing a critical gateway for one day, three days or a week would actually mean for the business.

For companies sourcing from Asian manufacturing centres and routing through major transshipment hubs, this kind of alternative-terminal mapping can be particularly useful. Singapore, Port Klang, Colombo, Jebel Ali and the major Chinese export gateways each have different operating models, technology dependencies, cargo capabilities and diversion options. The right alternative will depend on the cargo, carrier network, customs requirements, available capacity and inland transport options rather than simply the ocean freight rate.

This is also where a logistics partner can add value beyond freight procurement. Knowing which terminals can accept diverted containers, which inland routes have spare capacity, what documentation is required and how manual processing affects cargo release can determine how quickly an alternative route becomes workable.