Maritime Cybersecurity Risks Grow as Ships Get More Connected
Experts warn that GPS spoofing and network breaches on connected vessels pose growing national security and supply chain risks.
IMPACT SNAPSHOT
- Who is affected
- Worldwide
In this article
FBI Boarding Highlights Rising Maritime Cyber Risk
According to a report by Maritime Executive, an oil tanker headed for Texas was recently boarded by the FBI amid concerns that its onboard networks may have been compromised by hackers. The incident has renewed attention on the vulnerability of increasingly connected ships and ports to cyberattacks.
Dr. Amulya Gurtu, professor and department head of the Maritime Business Administration Department at Texas A&M University at Galveston, said the asymmetry between attackers and defenders makes maritime cybersecurity especially difficult. “Cyberhackers can fail 99% of the time and still succeed in their mission, but a protector cannot afford to fail even 1% of the time,” Gurtu said.
A Systemic Risk to Global Trade
Gurtu noted that maritime shipping carries roughly 80% of world trade by volume, meaning a single compromised vessel could disrupt global supply chains. Because ports function as critical infrastructure and ships transit both national and international waters, cyber incidents can escalate quickly from digital intrusions into national security concerns. He pointed out that a breach doesn’t remain confined to computer systems — it can physically alter a ship’s course, a risk compounded when passengers are aboard.
According to Gurtu, global cybersecurity spending across connected industries is projected to reach $500 billion by 2026, while the maritime cybersecurity market specifically is estimated at around $4 billion in 2026, with growth projected beyond $10 billion by 2034.
GPS Spoofing and Mobile Network Vulnerabilities
Gurtu explained that hackers can manipulate GPS and AIS data to redirect vessels or interfere with port coordination. Once inside a ship’s systems, an attacker could reroute the vessel to an unintended destination, complicating any search-and-rescue response.
He added that much of current maritime cybersecurity infrastructure assumes fixed network boundaries, an approach unsuited to ships and port vehicles that continuously move between different networks. Traditional navigation aids like GPS and AIS remain especially susceptible to spoofing and jamming.
Research and Education Efforts
Gurtu described ongoing research at Texas A&M at Galveston aimed at strengthening maritime cyber defenses. Dr. Dursun-Ozguven has tested machine-learning methods for detecting cyberattacks on mobile, GPS-tracked port equipment using container terminal operations as a case study, while Dr. Daneshgar’s research focuses on organizational cyber resilience — the capacity to recover after an attack.
The university has also introduced a cybersecurity minor within its maritime program and participates in industry and policy discussions on the issue. Gurtu said the goal is to ensure maritime students understand both the risks and the importance of cybersecurity as connectivity across the sector continues to expand.
Apeks view — This underscores a hard truth for owners and technical managers: navigation and control systems are now attack surfaces, not just IT ones. A spoofed GPS feed or compromised network can alter a vessel’s course as surely as mechanical failure, yet defenses often lag because ships move across network boundaries by design. The asymmetry cited here is real — resilience depends on layered detection, trained crews, and organizational recovery plans, not a single technical fix.
Spot an error? Request a correction
Apeks Tech Editorial Team
Sourced curation
The Apeks Tech editorial team — sourced briefs and engineering-led curation; sources are listed on every brief. Editorial policy →
Forward this to a colleague
Should your DPA, technical superintendent or a fellow owner see this? Forwarding costs nothing.
Was this forwarded to you? Take your own copy → subscribe here.