Chinese hacking group 'Mustang Panda' targeted EU maritime organizations throughout 2025
Executive summary: The EU cybersecurity agency reported that the Chinese-linked hacking group Mustang Panda carried out multiple cyberattacks on maritime organizations in at least seven EU countries throughout 2025. The targeting of maritime infrastructure poses a significant risk to European supply chains, logistics security, and economic stability.
Who is involved: Mustang Panda (Chinese-based espionage group), EU cybersecurity agency, and maritime organizations across seven EU member states.
Likely next: Increased EU-wide coordination on maritime cybersecurity protocols and heightened monitoring of shipping network traffic.
The EU cybersecurity agency reported that the China-linked hacking group Mustang Panda conducted a sustained campaign against maritime organizations in 2025, affecting at least seven member states. The intrusions focused on entities involved in shipping operations, logistics and port management, highlighting how state-linked actors are increasingly targeting critical infrastructure that underpins European trade flows. While the agency did not disclose the volume of data exfiltrated or the specific techniques used, the confirmation of a broad geographic spread underscores the persistent nature of cyber espionage in the maritime sector. This development coincides with other pressures on global shipping noted in recent analyses. UN envoys have warned that Houthi advances in the Red Sea pose a risk to vessel safety, and G7 nations have reiterated their commitment to preserving freedom of navigation through the Strait of Hormuz amid heightened regional tensions. Together, these factors point to a complex environment where cyber threats intersect with geopolitical risks, potentially prompting EU and international stakeholders to enhance both cyber defenses and maritime security coordination in the near term.
What's next — scenarios
Base: Increased cybersecurity spending (60%)
Maritime companies allocate more capital to digital infrastructure protection and threat detection.
- Official EU directive on maritime cyber-resilience
Upside: Geopolitical escalation (25%)
Stricter EU sanctions or trade restrictions targeting Chinese tech providers involved in critical infrastructure.
- Formal attribution of systemic attacks to state entities by EU leaders
Downside: Supply chain disruption (15%)
Successful breach leads to operational downtime in major European ports, impacting logistics costs.
- Reported physical or digital stoppage of freight movement in EU ports
What to watch
- EU cybersecurity agency's follow-up report on specific maritime vulnerabilities
- Implementation of new NIS2 directive requirements for maritime operators
- Potential retaliatory cyber activities or intelligence reports on Mustang Panda
Timeline
- — EU-Cyberbehörde: Chinesische Hacker haben 2025 die Schifffahrt in mindestens sieben EU-Staaten angegriffen (Politico Europe)
- — +++ Iran-Krieg +++: UN-Gesandter warnt vor Gefahr für Schifffahrt durch Huthi-Vormarsch (Handelsblatt)
- — Sicherheitspolitik: G7 pochen auf freie Schifffahrt durch die Strasse von Hormus (Handelsblatt)
Analysis — what this means
Likely next events
- Potential EU regulatory review of maritime digital assets
Sectors affected
- Maritime logistics
- Shipping companies
- Port authorities
- Supply chain management
Regulatory implications
- Strengthened enforcement of EU cybersecurity standards for critical infrastructure
- Mandatory reporting of cyber incidents for maritime operators under EU law
Historical parallels
- Houthi-led maritime threats in Yemen (2026)
- G7 warnings on freedom of navigation in the Strait of Hormuz (2026)
Key entities
Sources
- EU-Cyberbehörde: Chinesische Hacker haben 2025 die Schifffahrt in mindestens sieben EU-Staaten angegriffen — Politico Europe
- +++ Iran-Krieg +++: UN-Gesandter warnt vor Gefahr für Schifffahrt durch Huthi-Vormarsch — Handelsblatt
- Sicherheitspolitik: G7 pochen auf freie Schifffahrt durch die Strasse von Hormus — Handelsblatt