Oslo-based shipping software maker DNV reports a ransomware attack, impacting its ShipManager system and around 1,000 vessels, the latest attack on the industry
About 1,000 vessels have been affected by a ransomware attack against a major software supplier for ships.
Context & Ripple Effects
DNV's ShipManager outage is the latest entry in a pattern that started with the 2017 outbreak that hit Maersk, where the carrier famously fell back on manual operations for weeks after its systems went down. The difference now is the target: not a shipper itself but the software supplier whose platform runs roughly 1,000 vessels at once.
That makes DNV part of a second wave alongside Blue Yonder, whose ransomware attack on supply chain software rippled out to Starbucks and UK grocers — attackers have learned that one compromised vendor touches more operations than one compromised carrier ever could.
First-order effects
- Around 1,000 vessels lose access to ShipManager functions, forcing their operators into paper- or spreadsheet-based workarounds much as Maersk did after its 2017 malware incident.
- DNV must contain the infection, restore service, and manage disclosure for a customer base spanning many shipping companies simultaneously.
Second-order effects
- Fleet operators now have fresh evidence that concentrating vessel management in one vendor creates single-point-of-failure risk, sharpening demands for segmented deployments, offline fallbacks, and contractual uptime guarantees from DNV and rival maritime software providers.
- Insurers and charterers are likely to weigh vendor cyber posture when assessing counterparties, since a supplier breach now translates directly into operational disruption across fleets they underwrite or charter.
Third-order effects
- If attacks keep landing on shared logistics software — Maersk in 2017, Blue Yonder in 2024, DNV today — maritime and supply chain software vendors will be treated as critical infrastructure in their own right, inviting regulatory disclosure and resilience requirements similar to those debated after incidents like the Port of Seattle's Rhysida breach.
- The industry's recovery playbook shifts from per-company incident response to sector-level coordination, since a single vendor outage now strands hundreds of vessels at once.
The trend: Ransomware is migrating up the logistics stack from individual carriers to the shared software platforms that run them, turning single vendors into sector-wide points of failure.