ShipCalculators.com

Baltic Exchange Cyber Incident 2020

E1. Maritime security, geopolitics and risk

Definition

Notable industry awareness episode for maritime cyber risk.

On 22 May 2020 the International Maritime Organization’s own IT systems were hit by a cyber attack that knocked imo.org and public-facing services offline for several days; the IMO confirmed it on 30 September 2020 (the same window in which CMA CGM disclosed a ransomware breach). The episode is widely cited in maritime cyber awareness because it struck the sector’s central regulator months before MSC.428(98) cyber-risk requirements took effect at the first annual Document of Compliance verification after 1 January 2021. It hardened the case for treating shore and shipboard systems as one attack surface.

Source: IMO public statement on cyber attack against its IT systems, 30 September 2020; IMO Resolution MSC.428(98), adopted 16 June 2017