Marlink has published a new maritime cyber threat report, produced by its own Security Operations Centre (SOC) based on data gathered during the first half of 2024, demonstrating a significant increase in malicious activity in the first six months compared to the previous year.
The report highlights some of the changing tactics being employed by cyber criminals, who are increasingly attempting to bypass previously effective security controls using new tools.
Marlink’s maritime SOC monitored more than 1,800 vessels over the period, including all types of cargo ships as well as cruise ships, superyachts and offshore vessels. SOC analysts observed a continued rise in common threats such as Command and Control attacks, along with the evolution of botnet attacks, which are growing in both complexity and volume.
Phishing remains the top method attackers use to access corporate networks, while an increase in blacklisted malicious traffic was also detected. The volume of botnet activity grew substantially with new botnets emerging, leveraging more advanced techniques including AI-enhanced botnets targeting IoT devices.
The SOC registered 23,400 malware detections and 178 ransomware detections in the first half of 2024. Firewall events, which occur when a process or application attempts to make a connection that violates a client’s Network Security Policy, rose above 50 billion while security events reached 14.8bn. The number of alerts increased to 1.4m and the number of major incidents managed by the SOC reached 79.
“During the first half of the year, the threat landscape in the maritime environment monitored through the SOC has continued to evolve and surprise us compared to what we saw in 2023,” said Nicolas Furgé, President Marlink Digital, Marlink.
“Malicious actors are evolving their attack patterns and launching fraudulent campaigns that bypass previously effective security controls, such as two-factor authentication, forcing us to react and raise the security level to ensure operations are safeguarded.”
The full report is available here.



