October is Cybersecurity Awareness Month, and the theme this year for critical infrastructure operators is hard to miss: the systems that move the world's cargo are being attacked, and the attacks work. Ports are where physical trade, customs enforcement and digital systems meet, so a cyber incident at a terminal is also a border security event. Here is what the recent public record shows, what regulators now require, and what to watch.
September: Tanjung Pelepas
On September 10, 2026, the Port of Tanjung Pelepas in Malaysia began a controlled, phased restart of its container terminal after a cyber attack on its operating systems forced a temporary suspension of terminal activity, according to Lloyd's List as summarized by OODA Loop. PTP handled more than 14 million TEU in 2025 and is a key hub for the Gemini Cooperation network run by Maersk and Hapag-Lloyd. Public detail on the attacker and the full impact is limited so far, so we are not attributing it to any group.
The Pattern Across Ports
Threat intelligence firm Resecurity has catalogued recent port incidents, including the 2017 NotPetya attack on Maersk (estimated at $200 to $300 million in losses), the 2023 LockBit ransomware attack that halted container operations at Japan's Port of Nagoya for roughly two to three days, and a 2026 incident at the Port of Vigo in Spain that pushed cargo handling onto manual processes. Its report on the Anubis ransomware attack on the Adriatic Port Authority describes a reported $10 million ransom demand, data theft for double extortion, and a likely entry point of phishing or exposed remote-access systems. Resecurity is a vendor, so treat its forecasts as informed opinion, but the incident list is consistent with other public reporting.
A common thread is that attackers did not need to touch operational technology like cranes or scanners. Compromising ordinary IT accounts was enough to stop physical cargo movement.
When terminal systems go down, the problem is not only delayed cargo. Manifests, gate records, customs processing and security plans all live in the same networks. Resecurity noted that in the Adriatic case, attackers went after security-operations information, which could be valuable to groups involved in smuggling and insider recruitment. That is an analyst inference about motive, not a confirmed finding, but it is why ports belong in the border security conversation.
What Regulators Now Require
In the United States, the Coast Guard's final rule on cybersecurity in the Marine Transportation System, published in January 2025, took effect in July 2025. It requires regulated vessels and facilities to report cyber incidents to the National Response Center, with further requirements phasing in, including training and the designation of a cybersecurity officer and a cybersecurity plan over the following years. Check the Coast Guard and Federal Register text for exact dates and applicability. In the EU, ports are covered as essential entities under the NIS2 framework.
What to Watch
Three signals are worth tracking this month: whether more port operators publicly disclose incidents as reporting rules bite; whether the PTP investigation names a cause; and whether peak-season cargo volumes make terminals a more attractive extortion target, since downtime costs are highest when shipping is busiest. If you work in logistics, customs or trade compliance, a practical question for your own organization is what your manual fallback looks like if a port you depend on goes dark for three days.
You can browse coverage of nearly 360 ports in the BorderTrend Port Directory, including Nagoya, and follow breaking incidents on the live feed.