Search Beyond News…

Chinese hacking group 'Mustang Panda' targeted EU maritime organizations throughout 2025

Executive summary: The EU cybersecurity agency reported that the Chinese-linked hacking group Mustang Panda carried out multiple cyberattacks on maritime organizations in at least seven EU countries throughout 2025. The targeting of maritime infrastructure poses a significant risk to European supply chains, logistics security, and economic stability.

Who is involved: Mustang Panda (Chinese-based espionage group), EU cybersecurity agency, and maritime organizations across seven EU member states.

Likely next: Increased EU-wide coordination on maritime cybersecurity protocols and heightened monitoring of shipping network traffic.

The EU cybersecurity agency reported that the China-linked hacking group Mustang Panda conducted a sustained campaign against maritime organizations in 2025, affecting at least seven member states. The intrusions focused on entities involved in shipping operations, logistics and port management, highlighting how state-linked actors are increasingly targeting critical infrastructure that underpins European trade flows. While the agency did not disclose the volume of data exfiltrated or the specific techniques used, the confirmation of a broad geographic spread underscores the persistent nature of cyber espionage in the maritime sector. This development coincides with other pressures on global shipping noted in recent analyses. UN envoys have warned that Houthi advances in the Red Sea pose a risk to vessel safety, and G7 nations have reiterated their commitment to preserving freedom of navigation through the Strait of Hormuz amid heightened regional tensions. Together, these factors point to a complex environment where cyber threats intersect with geopolitical risks, potentially prompting EU and international stakeholders to enhance both cyber defenses and maritime security coordination in the near term.

What's next — scenarios

Base: Increased cybersecurity spending (60%)

Maritime companies allocate more capital to digital infrastructure protection and threat detection.

Upside: Geopolitical escalation (25%)

Stricter EU sanctions or trade restrictions targeting Chinese tech providers involved in critical infrastructure.

Downside: Supply chain disruption (15%)

Successful breach leads to operational downtime in major European ports, impacting logistics costs.

What to watch

Timeline

Analysis — what this means

Likely next events

Sectors affected

Regulatory implications

Historical parallels

Key entities

Sources

Related cases

Browse the full archive →