Skip to content
China-linked hackers step up attacks on European shipping

China-linked hackers step up attacks on European shipping

Splash247 • September 23, 2026

Chinese state-linked hackers are mounting sustained cyberespionage campaigns against maritime organisations across Europe, with shipping emerging as a consistent target for Beijing-linked threat groups, the European Union’s cybersecurity agency has warned.

ENISA’s newly published Threat Landscape 2026 says China-nexus groups maintained a particular interest in telecommunications, maritime, semiconductor, manufacturing and government organisations during 2025.

Most prominent in shipping was Mustang Panda, also known as Earth Preta, which ENISA says conducted continuous campaigns against maritime-related organisations across at least seven EU member states. The group uses spear-phishing, compromised USB drives and a range of malware including customised versions of the PlugX remote-access tool.

The activity was primarily aimed at cyberespionage and strategic intelligence collection rather than immediate operational disruption.

Transport accounted for 8% of all cyber events recorded by ENISA across the EU last year, with water transport making up 16.4% of transport-sector incidents. Maritime and railway transport are both classified by the agency as being in a cyber “risk zone”, reflecting their strategic importance and dependence on heterogeneous and increasingly interconnected systems.

The latest findings continue a pattern Splash has been tracking for years.

In 2022, Splash reported that CyberOwl had discovered nation-state malware from the PlugX family aboard seven ships belonging to a major liner fleet. PlugX gives attackers remote access and potentially full administrative control of compromised computers, allowing them to manipulate files, execute commands and spread through local networks.

More recently, SplashTech reported in February that recorded maritime cyber incidents jumped 103% during 2025, with infected USB devices among the main routes used to introduce remote-access malware onto bridge systems.

That combination is particularly relevant to Mustang Panda, whose use of infected removable media potentially offers a route into maritime systems that owners may consider isolated from the internet.

ENISA also highlighted wider Chinese campaigns targeting network infrastructure. China-linked groups increasingly compromise routers and other edge equipment, both to steal information and to use hacked infrastructure as relay points for subsequent attacks.

The warning lands as ship connectivity continues to accelerate. Yesterday SplashTech reported that assessments by Korean cyber specialist CYTUR found vulnerabilities requiring risk treatment across the overwhelming majority of shipboard systems it examined.

Extracted Entities

Attack Types (1)

Malware (1)

MITRE ATT&CK (1)