Malware on the Bridge: What It Means for ECDIS Chart Security
A remote access trojan was found on a ferry’s onboard systems and a crew member has been charged with planting it. How it got there has never been made public — which is exactly why the routes you already know about deserve attention.
In December 2025 a remote access trojan was found on the onboard systems of a passenger ferry alongside in the south of France. A crew member has since been charged with planting it on behalf of a foreign power. The detail that should hold a shipowner’s attention is not the malware itself. It is that how it got on board has never been made public.
What is on the record
In mid-December 2025, French authorities opened an investigation after Italian intelligence alerted them to malware detected on the Fantastic, a Grandi Navi Veloci ferry docked at Sète on the Mediterranean coast. The software was identified as a remote access trojan — a tool whose purpose is to give someone else control of a machine from a distance.
Two crew members were detained. One, a Latvian national, remains in custody in France and has been charged with conspiring to infiltrate computer systems on behalf of a foreign power, attempted intrusion, and possession of tools intended to interfere with navigation. These are charges, not convictions, and the investigation is ongoing. The operator stated that the breach was contained and neutralised, and that no damage was done to operational systems.
The detail that was never disclosed
The route the malware took onto the ship has not been published. Not by the operator, not by the investigating authorities, not in any of the primary reporting. A number of industry write-ups have since asserted that it arrived on a USB stick. That is an inference, not a finding, and it is worth resisting — partly because it may be wrong, and partly because treating it as settled lets everyone move on from the more uncomfortable point.
"The route in is the one detail you do not get. Planning around only the routes that get published is planning around the incidents that are already over."
Decorum Engineering Team
An undisclosed vector is the normal condition, not an unusual one. Investigations stay open, operators say as little as their counsel permits, and the technical detail that would most help the rest of the industry is the first thing withheld. Which means a fleet cannot build its defences out of case studies. It has to look at its own ships and ask which routes into safety-critical systems are open — not which ones have been proven to have been used.
The routes you already know about
On most vessels there is one such route that opens every single week, by design, with everyone’s knowledge and nobody’s attention: the ECDIS chart update.
Charts have to be brought up to date continuously, and we have set out what a modern chart workflow looks like in full elsewhere. On a great many ships it still happens the way it did fifteen years ago — a file is downloaded ashore or over satcom, copied onto removable media, carried up to the bridge, and plugged into the navigation computer. It is the one object on board that touches the ECDIS directly, and in most fleets nobody can say with certainty where it has been.
- Nothing has to be broken into — something only has to be plugged in, which is why this is the route that gets used rather than a harder one
- The media is rarely dedicated, rarely controlled, and almost never scanned under a documented procedure
- The ECDIS has no way to distinguish a chart package that was handled correctly from one that was not
It fails quietly, which is the worse problem
Deliberate compromise is the dramatic failure mode, and the rare one. The common failure is mundane: an update that installed only partially, a cell that was missed, a package that never made it across. No alarm is raised and nothing is reported, because from the bridge everything looks as it did yesterday.
Chart currency is checked during Port State Control inspections. A vessel that cannot demonstrate its charts are current risks a finding, and in the worst case detention — and that cost arrives as lost hire, wasted bunkers and a missed berth long before anyone files it under cyber security. Asked when the charts were last updated and by whom, most fleets still answer from somebody’s memory and a handwritten log, rather than from a fleet-wide record they can put in front of an inspector.
The scale of it
CYTUR recorded 828 maritime cyber incidents in 2025, against 408 in 2024 — an increase of 103 per cent, with notable growth in ransomware and in attacks touching operational technology. The same body puts the average reported cost of a single maritime cyber attack at USD 550,000. Neither figure describes a likely month on any given ship. Across a fleet, across a decade, they describe something close to certain.
What closing the route looks like
The answer is not more vigilance about removable media. It is removing the need for it. Chart updates can be delivered over the ship’s existing internet connection, verified before installation, and passed into the ECDIS across a link that runs one way only — updates go in, nothing comes back out. This is how DIDI Chart works, and the mechanism is worth seeing rather than reading about. The ECDIS itself is not modified and never goes online. There is no stick to control, because there is no stick.
That also changes what an owner can demonstrate. Every delivery is recorded, so the state of every vessel’s charts is a screen ashore rather than an email to the ship — which is the difference between believing your fleet is compliant and being able to show it.
None of this would necessarily have changed what happened on the Fantastic. That is rather the point: nobody can say what would have, because nobody outside the investigation knows how the malware got there. What can be said is that a route which is open by design, every week, on every ship, does not need to be the subject of an investigation before it is worth closing. If you want to see what that looks like on one of your own vessels, we will set it up on a ship of your choosing.
About this article
- Category
- Security
- Published
- Sep 2026
- Read time
- 7 min read
More from News
All articlesTake the riskiest routine off your bridge this quarter.
Tell us about your fleet and routes. A maritime engineer — not a sales script — confirms fit, pricing, and a non-intrusive rollout.

