Is There a Cyber Disinformation Campaign Targeting Shipping? TradeWinds Examines the Growing Threat
For an industry that carries more than 80 percent of global trade by volume, shipping has always had to navigate more than storms, pirates, and geopolitics. Today, it must also navigate lies. The question of whether a cyber disinformation campaign is actively targeting shipping has moved from theoretical concern to urgent operational reality, as maritime companies, insurers, and governments report a rising tide of false alerts, spoofed signals, fabricated documents, and deliberately distorted images designed to confuse, misdirect, and profit from the people who move the world’s goods. According to TradeWinds News, which has spoken with maritime security analysts, cyber-intelligence firms, and commercial operators, the sector has become a primary battlefield in a different kind of warfare—information warfare. Unlike a conventional cyberattack that disables a port crane or locks a ship’s navigation software, disinformation attacks exploit the trust that underpins global commerce. They can make a captain reroute a vessel, cause an insurer to spike a premium, or force a commodity trader to overpay for cargo that does not exist. The result is not just a data breach; it is a direct threat to maritime safety, supply-chain continuity, and the stability of the global economy. And while the full scale of the campaign remains hidden in the dark corners of the web, the evidence is now too broad to dismiss.
At its core, cyber disinformation in shipping is not simply about hacking a computer network; it is about hacking the confidence on which maritime trade depends. The toolkit is broad and increasingly sophisticated. It includes fake “Notice to Mariners” messages, official-looking navigational warnings, and cloned email accounts from charterers instructing a captain to change destination and “await orders via a secure link.” It uses spoofed Automated Identification System, or AIS, data to show a warship, a live-fire exercise, or a minefield where none exists. It can take the form of a doctored photograph of a burning product tanker posted to social media, or a synthetic voice message from a port captain demanding that an inbound vessel alter course. In one case flagged by security experts, a well-crafted fake Port of Los Angeles notice claimed that the port had closed all terminals for three days because of a “cyber security emergency,” leading to a flurry of worried calls from agents and trucking companies before the hoax was exposed. In another, a vessel in the Gulf of Guinea received a “piracy alert” geolocated hundreds of miles from its actual position, prompting an unnecessary emergency deviation that cost thousands of dollars in fuel and delay. These are not random pranks; they follow a pattern of deliberate, repeatable, and often profit-driven operations. The “false pivot” technique is particularly dangerous: a cyber actor gains access to a legitimate email thread between a charterer and a ship, monitors it in real time, and at the last minute injects a message that changes the discharge port or the delivery location, hoping the payment reroute will land in a money-laundering account. Such attacks have been documented by maritime cybersecurity companies, and they blur the line between cybercrime and disinformation.
The question of who is behind these operations leads inevitably into the world of state-sponsored influence, hacktivism, and geopolitical gray zones. TradeWinds News notes that the largest share of suspected disinformation activity is attributed to Russian actors, particularly since the full-scale invasion of Ukraine in February 2022. Moscow has a long history of using so-called “active measures” against its adversaries, and the maritime domain is a natural extension. In the early months of the war, Russian intelligence agencies were linked to false reports of floating mines drifting in the Black Sea, including fake satellite images purporting to show mines near the Bosphorus, which triggered panic among merchant crews and a temporary disruption in Turkish ports. More recently, a steady drip of fabricated Ukrainian grain export figures has been circulated on Telegram, aimed at creating distrust among buyers and sellers, distorting commodity markets, and undermining the Black Sea Grain Initiative. But Russia is not the only actor. Chinese-language social media platforms have hosted disinformation about Chinese-flagged vessels being “illegally detained” by Western allies, a narrative intended to stoke nationalist outrage and influence port state control decisions. Anonymous hacktivist groups have also joined the fray, leaking stolen emails and then selectively quoting them to create false stories about tanker ownership, sanctions evasion, or environmental disasters. These operations rarely announce themselves; they work by muddying the waters, by making it impossible for a decision-maker to distinguish between true and false. In the words of one former U.S. Navy intelligence officer interviewed by TradeWinds, “The goal is not to convince you of a specific narrative, but to make you doubt every narrative.”
The economic consequences of cyber disinformation are anything but abstract. A single piece of false information can send a $100 million containership on a thousand-mile detour, burn thousands of tons of bunker fuel, and delay high-value cargo for days. During the Red Sea crisis in early 2024, after a wave of Houthi missile attacks on commercial shipping, a parallel wave of disinformation magnified the impact of the real attacks. Old videos of blazing tankers were recirculated as if new, fake hijackings of product carriers were reported, and exaggerated claims of “fleet annihilation” spread on X (formerly Twitter). As a result, insurance war-risk premiums spiked far faster than the actual security situation warranted. Several carriers canceled all Red Sea transits for weeks, even for ships that had been scheduled to pass through after the immediate threat had passed. The effect was felt in global inflation, as container rates from Asia to Europe doubled and then tripled in the space of a month. Disinformation also enables financial market manipulation. A false rumor about a fire at the Port of Rotterdam or a cyberattack on the Suez Canal could move oil futures, freight derivatives, and shipping stocks within seconds. Regulators in the United States and Europe have begun to investigate whether certain traders are intentionally using disinformation to profit from volatility. One well-known case involved a fake “security alert” from an obscure naval intelligence company that claimed a Chinese warship had fired warning shots at a U.S. merchant vessel in the South China Sea. The story was shared by several legitimate news websites before being retracted, but not before the shipping company’s share price fell 7 percent in a single trading day.
How is the industry responding? Unevenly. Large operators like Maersk, MSC, and Hapag-Lloyd have invested in in-house security operations centers, cyber-threat intelligence feeds, and 24/7 incident response teams. They are also part of information-sharing platforms such as the Maritime Cyber Alliance and the National Cyber Security Centre’s industry network, where suspicious emails, spoofed AIS signals, and fake documents are shared in near real time. The International Maritime Organization, IMO, has issued guidelines for cyber risk management and, more recently, for countering disinformation and false information affecting maritime navigation. Classification societies and flag states have developed alert systems to verify port circulars and navigational warnings. But the response is far from uniform. Smaller shipowners, particularly those operating coastal tankers, feeder container vessels, and bulkers under open registries, often lack the resources and the technical expertise to detect a sophisticated disinformation campaign. Their crews are overworked and underpaid, often reliant on personal smartphones and free email services. A well-crafted phishing email that mimics an email from the port state control inspector—complete with a malicious attachment or a fake “deficiency report”—can easily fool an officer who has not been trained to spot the tell-tale signs. In some cases, disinformation is delivered not via the internet but via the old-fashioned AIS radio channel, where a legitimate harbor station’s call sign is spoofed and a fake message warns of “suspicious divers near anchorages” in order to steer a vessel into a hijacking or a cargo theft trap. This is the maritime version of the “false flag,” and it is deeply dangerous.
So, is there a cyber disinformation campaign targeting shipping? The answer, according to the evidence assembled by TradeWinds News and maritime security researchers, is a qualified and troubling yes. It is not a single, monolithic campaign orchestrated from one dark room, but rather a diffuse, adaptive, and often opportunistic ecosystem of state intelligence services, criminal syndicates, hacktivists, and even competing commercial interests. Sometimes the motive is geopolitical—to disrupt an adversary’s supply chain or to undermine support for sanctions. Sometimes it is financial—to steal a cargo, manipulate an insurance claim, or defraud an unwary charterer. Sometimes it is simply to test the resilience of a target and create chaos. What is certain is that the barrier to entry has fallen. Anyone with a modest budget and a working knowledge of social media algorithms can create a believable-looking port notice, a fake emergency broadcast, or a short video claiming that a containership has run aground in the Suez Canal. The maritime industry is a uniquely vulnerable target because it is global, heavily regulated, and dependent on clear, reliable information. A captain thousands of miles from shore has no way to call a fake rumor line to check the truth. The future, therefore, depends on building what one analyst calls “cognitive resilience”—the ability of seafarers, shore staff, and commercial decision-makers to pause, verify, and corroborate before acting on information. It means treating the information environment with the same seriousness as the physical environment, and investing in technologies that can authenticate the origin of digital messages, block spoofed communications, and quickly debunk false claims. The sea may be vast, but the space for lies is larger. If the last two years have taught the maritime world anything, it is that a vessel must be protected not only from the waves and the missiles, but also from the words and images that seek to send it off course. And that is a voyage no ship can make alone.

