Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On August 31, 2026, the Connected Fleets Under Siege – CSN ICT 2026 Cyprus & Greece Satellite and Cyber Security Report documents that the commercial fleets of Cyprus and Greece no longer face sporadic cyber incidents, but a systematic, daily campaign. According to the research, reported maritime cyber incidents doubled during the 2025-2026 period, with a 103% year-over-year increase for overall cases and a 150% jump for attacks specifically targeting OT systems. Industry professionals surveyed describe an operational convergence of cyber warfare, electronic warfare, and intelligence operations against critical naval infrastructure: not a future scenario, but the current sailing condition in the Eastern Mediterranean, the Red Sea, and the Strait of Hormuz corridor.
- Reported maritime cyber incidents doubled in the 2025-2026 period; the year-over-year increase is 103% for overall cases and 150% for OT-targeted attacks, according to industry intelligence cited in the report.
- 31% of maritime professionals surveyed experienced at least one cyber incident in the past year, according to DNV research cited in the dossier.
- GPS spoofing incidents recorded an approximate 340% year-over-year increase, reported by KVH.
- A €4 million BEC fraud against a Greek shipping company, investigated by the Hellenic Police in July 2026, illustrates the shift from untargeted cybercrime to deliberate targeting of the shipping sector.
From Exceptional Incident to Daily Operating Condition
Dr. Matthew Maheras, President of AMMITEC and CIO of Metrostar Management Corp., summarizes the shift: "Untargeted cybercrime has given way to the deliberate targeting of shipping as critical global infrastructure." The statement is not rhetoric. The report records that average ransomware losses in the maritime sector exceed $10 million in direct and indirect damages, according to industry intelligence cited by Vlassis Papapanagis, CCO of Tototheo Global.
The difference from previous reports lies not in risk recognition, but in its operational normalization. Apostolos Giannetsos, ICT Manager of Cyprus Sea Lines, describes "the concept of connected fleets under siege" as "an everyday operating condition." The language is that of daily management, not strategic alarm: no longer the possibility of an attack, but the frequency with which it occurs.
The Perimeter Dissolves: Every Ship a Remote Branch Office
The report traces a structural transformation of the attack surface. Dimitris Marinis, ICT Manager of Angelakos (Hellas) S.A., treats every vessel as a "remote branch office" with a continuous ship-to-shore attack surface. The cause is the convergence of three phenomena: LEO (Low Earth Orbit) constellations, onboard cloud services, and permanent connectivity of OT systems.
Dr. Maheras adds a tactical detail: "An attacker no longer needs to penetrate the vessel hull directly; compromising someone who talks to the vessel is sufficient to disrupt operations." The attack favors indirect compromise — vendors, agents, remote maintenance, BEC — over direct intrusion. Marinis notes that attacks "are meticulously shaped around shipping workflows, referencing real charter party agreements, actual vessel positions, and port calls." The brief does not specify initial access techniques or detected indicators of compromise.
The Kinetic-Cyber Overlap: Jamming and Intrusion in Tandem
Vlassis Papapanagis, CCO of Tototheo Global, reports that "threat actors increasingly combine electronic jamming with network intrusion attempts, attacking connectivity, navigation, and corporate ERP systems in tandem." The report cites the grounding of MSC Antonia on Eliza Shoals (Jeddah) as a reference case for weaponized navigation and deliberate signal interference. The dossier does not classify the event as a verified network intrusion nor detail the technical cause-and-effect chain.
Melanie Dias, Senior Network & Applications Engineer at KVH, records an approximate 340% year-over-year increase in GPS spoofing incidents. The brief does not specify the exact time baseline of the comparison nor the geographic detection area. The figure is cited in the context of a convergence between electronic and cyber threats that the report presents as operational, not theoretical.
"Modern attacks are meticulously shaped around shipping workflows, referencing real charter party agreements, actual vessel positions, and port calls" — Dimitris Marinis, ICT Manager, Angelakos (Hellas) S.A.
The Disclosure Abyss: Why Public Visibility Is Near Zero
The report highlights a structural contradiction. On one hand, interviewed CISOs and ICT managers describe a daily siege. On the other, public visibility of these incidents is near zero due to the lack of mandatory disclosure obligations. The maritime sector does not operate under a mandatory reporting regime analogous to that of terrestrial critical infrastructure; companies manage individual events in silence to avoid insurance, contractual, and reputational repercussions.
The €4 million BEC fraud against a Greek company, investigated by the Hellenic Police in July 2026, emerges as a confirmed exception. The company name and investigative status are not specified in the dossier. The figure is significant not for its absolute size, but for the mechanism: the deliberate targeting of a management company through social engineering techniques, not technical intrusion into onboard systems.
Why It Matters
The CSN ICT 2026 report is not an academic study with reproducible methodology, nor a technical advisory with CVEs or indicators of compromise. It is an aggregation of interviews and professional assessments documenting a transition: cyber risk in the maritime sector has moved from an IT category to a variable of commercial governance and navigational safety.
The dossier does not specify technical remediation measures nor independently verify the aggregated quantitative data. The source of the percentage increases (doubling of incidents, +150% OT, +103% overall, +340% spoofing) is identified as "industry intelligence" or as DNV/KVH research, but the specific report is not cited by title or URL. The actual number of interviewees and selection criteria are not declared. No CVEs, specific technical advisories, or details on the kill chain of described attacks emerge in the dossier.
For shipping companies and fleet managers, the document confirms that the convergence between cyber threats and electronic warfare is a field condition in the Eastern Mediterranean and vital corridors. For regulators, it intensifies pressure for NIS2 implementation and IACS E26/E27 requirements with qualitative evidence from CISOs of major management companies. For technology vendors, it records accelerated demand for IT/OT segmentation and vendor audits. For insurers and boards, it makes explicit the shift from technological risk to operational and commercial risk.
The editorial reading is that the maritime sector has reached a maturity threshold where the debate is no longer on the reality of the threat, but on the visibility that governance structures can build around it. As long as mandatory disclosure is absent, shipping's cyber chronicle will remain an iceberg: the visible mass of annual reports hides the submerged structure of incidents managed in silence.
Sources
- https://cyprusshippingnews.com/2026/08/31/connected-fleets-under-siege-the-2026-csn-ict-cyprus-greece-satellite-and-cyber-security-report/
- https://cyprusshippingnews.com/2026/05/19/intelligent-skies-secure-seas-charting-the-digital-future-at-the-7th-csn-cyprus-ict-conference/
- https://cyprusshippingnews.com/
- https://cyprusshippingevents.com/the-4th-csn-greece-ict-conference/
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.