Skip to content

Security1 publisher2 min readPublished

Ship assurance skips the onboard IT that ransomware can knock out fleet-wide, Pen Test Partners says

Pen Test Partners says ship rules never test onboard IT, and nine years of shipping ransomware has yet to be confirmed on a vessel's own computers. Fleets moving to a single Windows domain can lose every ship's IT to one intrusion.

The Watch · Security desk

Illustration accompanying Ship assurance skips the onboard IT that ransomware can knock out fleet-wide, Pen Test Partners says
Generated illustration

What happened

  • Publicly known incidents hit ports or shipping firms' shore systems, and every victim kept trading, whether by hand, through other channels, or by pausing and catching up.
  • The firm says most ransomware against shipping companies, managers and ports is never disclosed, because disclosure follows what customers notice.
  • It attributes the clean vessel record to older conditions: less onboard IT, less connectivity, fewer Windows domains and slow links, and says all four have changed.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision A clean survey covers safety systems only, so an operator who wants to know whether the fleet can keep trading through an IT outage has to commission that test separately.
  • exposure On a shared fleet domain, one set of stolen admin credentials reaches every vessel and the shore office, so how the domain is divided sets how many ships one intrusion can stop.
  • cost The bill for a fleet-wide hit falls on schedules and results; Maersk put NotPetya, a shoreside wiper, at $200 million to $300 million.

The entry point Pen Test Partners describes is one workstation on one ship. An attacker gets software onto it, perhaps by persuading an officer to install something that looks like an update, and runs as an ordinary user [6]. From there the attacker moves to servers and file shares and encrypts every file and database in reach [6]. The fast way across is the Windows domain, though reused local passwords and remote management tools also work [8]. Administrator rights in the domain can let the attacker run software on every machine in it at once [8].

The attacker in this picture is a financially motivated crew using generic ransomware, and it may not know it is on a ship [7]. "To them it is another Windows network," the firm wrote [7]. It rates ransomware as more likely than the scenario most people picture, a state actor working towards a collision [16]. Nothing in the chain needs maritime tooling [7].

Fleet-wide domains are where the industry is heading, because managing ninety ships any other way does not work, according to the firm [9]. A ship that loses her IT runs degraded and arrives late, and one late ship is not much of a problem [4]. The concern is the same systems going down on every ship at once, with the shore office on the same domain [4][9].

The rules cover the fire pumps, steering gear, main engine and power management. Those systems are certified and surveyed, and crews drill running them degraded [1]. According to Pen Test Partners, nothing examines whether a ship can keep operating commercially, and the IT that decides it gets no assurance work at all [2]. Its testers often compromise those computers, the firm says, though the post does not say how many vessels or fleets that covers [3].

The firm's case against reading the clean vessel record as resilience rests on what has moved aboard. Every function that came off paper arrived as another application. Data replicates ashore, and the office works from the same records as the ship [14]. On that basis the firm calls the absence of reported vessel ransomware "unlikely to be the whole story" [15].

Pen Test Partners calls ransomware against shipping companies, managers and ports routine [12]. That is a sustained, opportunistic pattern aimed at shore networks, run with generic tools [7][12]. Vessel IT is now joined to those networks [14]. The evidence for ship-level risk is one firm's test experience plus a public incident list it says is incomplete [3][12].

What to watch

  • A publicly confirmed ransomware case running on a vessel's own computers.
  • Any move by the rule-makers to extend certification or surveys to onboard IT and commercial continuity.
  • Test firms publishing counts of fleets whose domains they have compromised, which would firm up a claim now resting on one firm's word.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories