A report released by Marlink analysing data traffic monitored by its Security Operations Centre (SOC) in the second half of 2024 showed a rise in targeted attacks on maritime by cybercriminals using generative AI tools.
The SOC recorded 9 billion security events and 39 billion firewall events across 1,998 merchant and leisure vessels, resulting in 718,000 alerts and 10,700 malware incidents. 50 major cyber incidents were also handled by the team during the six-month period.
The report notes that threat actors have begun using commercially available large language models to accelerate malware development, automate phishing campaigns, and refine social engineering techniques. Some have also used AI to generate malicious scripts targeting known security vulnerabilities.
Access brokers have become more prominent within the cybercriminal ecosystem, with the sale of network access doubling in the past year as attackers seek more efficient routes into corporate systems.
“H2 2024 saw a marked evolution in cyber threats, as malicious actors adopted increasingly efficient, structured, and business-like approaches to cybercrime, putting additional pressure on the maritime industry,” said Nicolas Furge, President, Marlink Cyber.
“Looking ahead to 2025, the cyber security landscape is expected to become increasingly complex and challenging, increasing the pressure on users to improve protection of assets and people.”



