
AI in Maritime Logistics
6 October 2025
At the Center of Geopolitical Turmoil
24 August 2026Today, seaports in Northern Europe operate in a threat environment of unprecedented complexity. The convergence of the conflict in Ukraine, destabilization in the Middle East, and the activities of state-sponsored APT (advanced persistent threat, i.e., highly specialized hacking teams, typically sponsored by states, that carry out long-term, precisely targeted espionage or sabotage attacks) creates a situation in which port cybersecurity ceases to be a technical issue and becomes a matter of national security.
APT groups do not attack at random. The selection of targets in their operations is a methodical process, conducted in accordance with intelligence and military logic. Understanding this logic allows us to assess how attractive Polish ports are as targets for these groups. In practice, these groups use a calculation based on several criteria when selecting targets, which can be reconstructed based on documented campaigns:
* strategic value of the target—the adversary assesses how important a given facility is to the functioning of the opposing state. High-value targets are those whose disruption undermines defense capabilities, energy security, or economic stability;
* cascading effect—the more sectors and entities depend on a given facility, the more attractive it is as a target. Studies on critical infrastructure interdependencies show that a failure in a single system—such as a port’s power supply—can have a cascading effect on telecommunications, water distribution, transportation networks, and supply chains;
* Vulnerability and accessibility—they systematically scan the target for known vulnerabilities, identifying hosts with specific security gaps. They assess the target’s cybersecurity maturity: whether it uses network segmentation, monitors OT (operational technology) traffic, and whether employees undergo anti-phishing training. Targets with outdated OT systems, staffing shortages, and fragmented oversight are naturally preferred;
* the ability to remain hidden for an extended period—they operate in “low-profile” mode—their goal is not to cause immediate damage, but to maintain a presence on the victim’s network for as long as possible. During this time, they conduct internal reconnaissance, map networks, collect data, and prepare the capability to inflict serious damage on demand;
* the ability to deny involvement—they prefer targets and methods that make it difficult to unequivocally identify the perpetrator.
How do Polish ports fare in this analysis? The answer is troubling—they meet virtually all the criteria for attractiveness. Their strategic value is maximal. Polish ports generate 10% of budget revenue, serve as the sole maritime supply route for oil to Polish and German refineries, function as a NATO logistics hub on the eastern flank, and handle support shipments to Ukraine. The ripple effect can also be considered very high. Disruption to port operations simultaneously impacts energy security (Naftoport supplies refineries in Poland, Germany, and the Czech Republic), container trade (the Baltic Hub handles feeder services to Scandinavia and the Baltic states), NATO military logistics, and the supply chains of more than a dozen countries. Vulnerability is also heightened. Outdated IT and OT systems, limited staff expertise, fragmentation of responsibility among many entities (numerous operators are active within the port, each with their own, often immature, cybersecurity management systems), and a growing attack surface generated by dynamic infrastructure investments.
Unfortunately, attackers have ample opportunities to conceal their activities. The port ecosystem is complex, involving many entities and systems; monitoring of OT segments is typically insufficient, and there is a lack of a sector-wide mechanism for sharing threat intelligence. Denial is also facilitated. The multitude of entities, overlapping IT systems, and unclear boundaries of the Information Security Management System (ISMS), as well as insufficient monitoring of security incidents, make it difficult to identify the perpetrators of an attack.
Recently, the maritime sector in our region has seen a marked increase in activity by the APT28 group, which is linked to the GRU. This group has a documented track record: the attack on the Bundestag (2015), interference in the U.S. presidential election (2016), and campaigns against international organizations and the energy sector. The goal of its operations is not always to immediately disrupt port operations. Often, the aim is long-term reconnaissance: mapping networks, identifying key systems, and obtaining authentication credentials. This is a preparatory activity—building the capability to strike at a chosen moment, for example, in the event of a conflict escalation. The data processed in port systems also constitutes valuable booty for foreign intelligence services. Meanwhile, the belief persists that if we haven’t detected an attack, then there was no attack.
There is yet another reason why cyberattacks are such an attractive tool in the arsenal of state adversaries—and it has less to do with their technical effectiveness than with how they are perceived. Cyberattacks can have effects comparable to physical sabotage, yet they are treated—by international law, public opinion, and political decision-makers—as something far less serious. This asymmetry in perception is a strategic advantage for the aggressor.
Let’s compare the reaction to the recent detonation of an explosive device near the tracks on the Warsaw East–Dorohusk railway line. Operation “Horizon” was launched immediately, involving up to 10,000 soldiers equipped with reconnaissance drones, helicopters, and advanced monitoring equipment, patrolling 80 critical railway sections across the country.
International law does not provide a clear answer to the question of when a cyberattack constitutes a “use of force” within the meaning of the United Nations Charter. There is no consensus among states regarding the threshold above which a cyberoperation constitutes a use of force or an armed attack. In practice, this means that a cyberattack that paralyzes a port for a week does not carry the same legal and political consequences as planting an explosive device on the tracks—even though its actual economic impact may be a hundred times greater.
For an adversary, this is an ideal scenario: maximum damage with minimal political and legal consequences. A cyberattack on port infrastructure allows for a de facto diversionary operation—with effects comparable to or greater than those of physical sabotage—while maintaining the perception that the action remains “below the threshold of war.” As long as the public and decision-makers treat cyberattacks as “IT incidents” rather than acts of hostile action with strategic implications, this asymmetry will work to the aggressor’s advantage.
The scale of the problem is best illustrated by specific incidents and warnings directly concerning our region. In May 2025, NATO and 21 intelligence agencies from 11 allied nations issued a joint warning describing a two-year cyberespionage campaign by APT28 targeting Western logistics and technology companies coordinating aid for Ukraine. The campaign targeted the maritime, aviation, rail, and road sectors in at least 13 countries, including Poland. It was also revealed that APT28 targets IP cameras at logistics facilities—over 80% of the compromised cameras were located in Ukraine, with the rest in Poland and Romania, near border crossings and military installations. In early 2026, Trellix disclosed an APT28 campaign directly targeting entities in the maritime and transportation sectors.
Let’s keep in mind that there are a dozen or so—or even several dozen—entities operating simultaneously within a seaport: the port authority, terminal operators, customs agencies, freight forwarders, IT and OT service providers, and government agencies. Each of them has its own IT systems and its own—or no—security policies. Defining the boundaries of the Port Information Security Zone (SZBI) in such an environment is extremely difficult. Who is responsible for the security of the interface between a terminal operator’s TOS system and the port authority’s Port Community System platform? Who monitors network traffic in an area where the IT infrastructure of several entities shares physical cabling? Many IT and OT systems in Polish ports were implemented at a time when the cybersecurity of industrial systems was not a priority. Upgrading these systems is costly and operationally risky: it requires downtime, compatibility testing, and often hardware replacement. As a result, many ports operate with systems that have known vulnerabilities, secured only by network segmentation—which is often insufficient.
On top of all this, there is yet another challenge facing Polish ports. An amendment to the Act on the National Cybersecurity System is now coming into force, transposing the EU’s NIS2 Directive into Polish law. This poses a major challenge for many institutions—including ports—as it introduces strict requirements regarding cybersecurity, risk management, incident management, business continuity, supply chain security, and human resources. This regulation cannot be implemented “on paper”—it is essential to consistently take concrete actions, monitor their effectiveness, and have the system’s proper functioning verified by independent auditors. However, this is not only a challenge but also an opportunity, as implementing the provisions of this law will significantly reduce the risks of successful attacks by APT groups, technical failures, and human error.
The article was written in collaboration with Namiary Na Morze i Handel – a biweekly magazine providing expert information on the most important events and issues in the Polish maritime economy.





