Chinese hackers targeted shipping in at least seven EU countries, cyber agency reports
A notorious Chinese hacking group carried out cyberattacks against European maritime organizations at a “sustained tempo” throughout 2025, the EU’s cyber agency said on Tuesday.
Mustang Panda, a China-based cyber-espionage group that U.S. justice department officials accuse of being sponsored by the Chinese government, hit shipping-related organizations with “continuous campaigns impacting at least seven EU member states,” EU agency ENISA said in its annual report outlining the cyber threats facing the bloc.
The hacks included spying and strategic intelligence collection, ENISA said, adding that Mustang Panda is a “significant threat” to EU organizations as it is equipped with advanced capabilities and capable of carrying out repeated attacks against the maritime sector and public administration organizations.
The Chinese group was caught targeting EU diplomatic missions in 2022, then cited the following year by ENISA as a key threat. In 2025, it was also found to have spied on Russian defense and aerospace firms.
Shipping is a particularly vulnerable industry where disruptive cyberattacks could have major knock-on effects on trade. China has previously shown an interest in how Western shipping companies operate, particularly as shipping routes in the Middle East become more difficult to navigate.
In an earlier report, ENISA included maritime as being in the “risk zone.” On Tuesday, the cyber agency concluded that: “Transport, including maritime, and logistics targeting is particularly interesting as it pertains to economic and political considerations, especially when contextualised within geopolitical developments.”

