When a cyberattack becomes a maritime crisis
- Art Samaniego
- PHT
- Cyberattack, Marina
DECODED: TECH, TRUTH, AND THREATS
In todayβs maritime world, the most damaging attack may not come from pirates at sea, but from criminals behind keyboards thousands of kilometers away.
A pirate attack can seize a ship, endanger its crew and disrupt a voyage. A cyberattack against critical maritime infrastructure can reach much farther. It can affect thousands of seafarers, disrupt deployments and crew changes, delay livelihoods and send consequences across an entire industry without the attacker ever setting foot on a vessel.
That is the troubling lesson from the cyberattack that hit the Maritime Industry Authorityβs Seafarerβs Identity Document (SID) and Seafarerβs Record Book (SRB) systems on August 13. Regular processing was suspended nationwide, and as of August 27, the systems remained offline while MARINA rebuilt its database and server environment and conducted a forensic investigation.
Fourteen days is a very long time when the system involved helps determine whether a Filipino seafarer can board a ship and earn a living.
MARINA deserves credit for introducing temporary measures. Temporary certifications have reportedly been issued for urgent deployments, while MARINA Administrator Sonia Malaluan has assured the public that no seafarer has lost a job because of the disruption.
But βno seafarer lost a jobβ cannot be the measure of whether damage was done.
Were deployments delayed? Were flights rebooked? Were crew changes disrupted? Did seafarers and manning agencies incur additional expenses? Did Filipino crew already at sea have to remain aboard longer because replacements could not secure documents?
A seafarer does not have to permanently lose a job before government recognizes the consequences.
The bigger question is why one cyberattack could disrupt a critical government service nationwide for this long.
No organization can guarantee it will never be breached. Even well-defended institutions have suffered successful attacks. The real measure of cybersecurity is not simply whether you can keep attackers out. It is whether you can continue operating when they get in.
According to an independent report sent to TechWatchPh, MARINAβs affected database and server environment required a complete rebuild rather than a simple restoration from backup. As of August 26, a temporary system was still undergoing security and functionality testing.
That demands answers.
Where was the disaster-recovery environment? How often were recovery procedures tested? Was there an isolated backup capable of quickly restoring essential services? If adequate redundancy existed, why has recovery taken this long? If it did not, why was such a critical system allowed to operate without it?
These questions become more serious because MARINA had already been warned.
The agency suffered another cyberattack in June 2024 involving four web-facing applications. Cybersecurity professionals are now raising the possibility that the latest incident could be connected to that earlier compromise, including a theory that attackers may have maintained persistent access inside MARINAβs environment.
There is no public evidence proving the two incidents are connected. Other possibilities include a new vulnerability, compromised credentials, an insider-related incident or a weakness involving a third-party provider.
But MARINA must answer a simple question: What changed after 2024?
What vulnerabilities were identified? Which were fixed? Were independent security assessments conducted? Were disaster-recovery exercises performed? Most importantly, was it verified that the previous attackers had been completely removed?
If investigators eventually find that weaknesses discovered in 2024 remained unresolved and contributed to the 2026 attack, this becomes more than a story about sophisticated cybercriminals. It becomes a story about institutional failure.
Then there is the data.
Authorities have not yet determined whether information was exfiltrated. The SID and SRB systems reportedly contain sensitive information, including biometric data such as facial recognition scans and fingerprints.
Passwords can be changed. Fingerprints cannot.
If personal or biometric information was stolen, the danger will not disappear when MARINAβs servers return online. That information could potentially be exploited for identity theft, phishing, fraudulent recruitment and social-engineering attacks against seafarers.
MARINAβs immediate responsibility is to safely restore normal services. But restoration cannot be the end of this story.
The agency must eventually explain how the attackers entered, what systems were compromised, whether information was stolen, whether the incident was connected to the 2024 attack, why recovery took so long and what will change.
If systems need rebuilding, rebuild them. If disaster recovery is inadequate, strengthen it. If vendors failed, hold them accountable. If known vulnerabilities or required security procedures were ignored, there must be accountability.
Because behind every SID and SRB is a Filipino waiting to board a ship, a family waiting for income and a crew member waiting to come home.
Pirates can stop a ship. A cyberattack can potentially stop thousands of seafarers from boarding one.
After two major cyber incidents in barely two years, MARINA must do more than recover. It must prove that it has learned.
