Lawyer Henry Clack has extensive experience with Nigerian criminal gangs.
Clack, a solicitor at London-based law firm HFW, represents shipping companies struck by cyber crime. He says Nigerian groups are the most frequent counterparties. They have carried out numerous high-value “man-in-the-middle” frauds in recent years.
How hackers manipulate communication
This type of fraud lets hackers intercept exchanges between two parties. They then impersonate both sides to steal login details, financial data, or full system access. Criminals later demand ransom to return stolen information or surrender computer control.
HFW data shows cyber attacks on ships and ports are increasing. Between 2022 and 2023, the average cost of an attack doubled to $550,000 (£410,000). When removal fails, ransom payments now average $3.2m.
Maritime trade under pressure
Around 80% of world trade travels by sea. Any disruption raises costs and cuts capacity.
John Stawpert, environment and trade manager at the International Chamber of Shipping (ICS), warns that shipping is a prime target. “Cyber security is a major concern for shipping, given how interconnected the world is,” he says. “The sector is among the top 10 global targets for cyber criminals. The damage from disruption or ransomware can be severe.”
Alarming surge in attacks
Research from the Netherlands’ NHL Stenden University shows maritime cyber attacks climbed sharply. The number rose from just 10 in 2021 to at least 64 last year.
Jeroen Pijpker of the Maritime IT Security research group says many incidents link to Russia, China, North Korea, and Iran. He recalls one case where equipment bound for Ukraine became a target. Attackers shared details on Telegram to disrupt supply chains.
Other gangs, including groups in Nigeria, pursue financial extortion.
Digital growth widens the risks
The industry’s rapid digitalisation has created new entry points for hackers. Services such as Starlink increase connectivity but also exposure.
In one case, a US Navy chief lost her post after installing an unauthorised satellite dish so officers could access the internet.
Shipping’s digitisation remains fragmented and outdated. The average cargo ship is 22 years old, and firms cannot dock vessels often for updates.
Digitalisation also fuels risks like GPS jamming and spoofing.
“GPS spoofing feeds a false position to navigation systems,” explains Arik Diamant of security firm Claroty. “It can redirect ships or even push them into shallow waters.”
In May, the container ship MSC Antonia ran aground in the Red Sea after suspected spoofing. While no group was blamed, Houthi rebels have attacked other ships in the area. In the Baltic, Russia is accused of GPS interference.
Defending against costly threats
Anti-jam technology is available but expensive. Many operators cannot afford it.
Emission sensors, which transmit data, also create new points of entry for hackers.
New rules for stronger protection
In 2021, the International Maritime Organization (IMO) tightened cyber rules within its safety management code.
HFW lawyer Tom Walters explains that ships must now include mandatory cyber risk management. Measures cover basic IT security and advanced operational safeguards.
“I think the industry is in a stronger place than six or seven years ago,” says Stawpert. “Awareness of cyber threats has risen dramatically and will keep growing.”
Talking with hackers
Clack says communication with cyber criminals is short and deliberate. It usually occurs during ransomware negotiations. “Often it is just one message a day, rarely longer than two sentences,” he explains.
