INTRODUCTION
Contracts of carriage in maritime trade are increasingly conducted through electronic systems. Electronic bill of lading platforms, port community systems, and integrated computer systems used for vessels’ navigation, communications and operational management expedite carriage operations, but also give rise to cyber risks such as data manipulation, system disruption, unauthorised access and interference with a vessel’s operational control.
Losses arising from cyberattacks constitute an area requiring separate consideration within the traditional distinctions governing the carrier’s liability. Such losses may, in some cases, be connected with a security vulnerability existing at the commencement of the carriage, and, in others, with an operational intervention or omission occurring during the voyage. This article examines the forms that cyberattacks may take in relation to electronic bills of lading, port systems and the vessel’s operational control, and considers how the carrier’s liability for the resulting losses should be assessed.
IN WHAT FORMS DO CYBERATTACKS ARISE IN MARITIME TRANSPORT?
Cyberattacks may take the form of interference targeting the confidentiality, integrity or availability of electronic systems used in maritime transport operations. In addition to causing direct physical damage, such attacks may, through data manipulation, system disruption or unauthorised access, produce legally consequential effects on the representation or delivery of cargo, port operations or the safety of navigation. In practice, losses arising from cyberattacks are principally discussed under three scenarios.
First, an attack may target electronic bill of lading systems. In such circumstances, the description or quantity of the cargo or the delivery instructions contained in the bill of lading may be altered, or fraudulent instructions may be generated, resulting in delivery of the cargo to an unauthorised person. In such a scenario, the loss will often arise not from physical damage to the cargo, but from the impairment, through data manipulation, of the bill of lading’s functions of representing the cargo and directing its delivery.
Second, an attack may target port systems or port community systems. Disruption of port systems may cause large-scale operational interruptions affecting not only a particular carriage relationship, but also loading, discharge, delivery, storage and customs procedures. The NotPetya attack of 2017, for example, caused serious disruption to maritime transport and port operations, as it did in many other sectors, through the spread of malware across corporate systems. Maersk, which was affected by the attack, had to rebuild certain systems, and stated in its 2017 Annual Report that the impact of the attack on profitability was approximately USD 250-300 million. Losses arising from such attacks generally take the form of delay, additional storage costs, disruption of the delivery process or commercial losses sustained by cargo interests.
Third, an attack may target the vessel’s operational control. Spoofing GPS signals, interfering with ECDIS (Electronic Chart Display and Information System), or compromising the vessel’s machinery, navigation or communication systems may pose serious risks to navigational safety and cargo security even where the vessel’s physical integrity is not immediately damaged. This scenario is particularly significant for the carrier’s liability, since it may raise the question whether the loss should be assessed under the obligation of seaworthiness or under the exceptions relating to the navigation or management of the vessel.
The common feature of these three scenarios is that the loss does not invariably arise from direct physical damage; in certain cases, it results from disruption of the carriage process caused by the loss of functionality of electronic systems, corruption of data integrity or unauthorised interference. Accordingly, the carrier’s liability for losses arising from cyberattacks must be assessed in each individual case by reference to the system targeted, the stage at which the loss occurred and whether the carrier took the requisite measures against the relevant risk.
ON WHAT GROUNDS MAY A CARRIER BE EXEMPTED FROM LIABILITY FOR LOSSES ARISING FROM CYBERATTACKS UNDER ENGLISH LAW?
Under English law, a carrier’s liability for losses arising from cyberattacks is assessed primarily within the framework of the relationship between the obligation of seaworthiness under the Hague-Visby Rules and the exceptions available to the carrier. Pursuant to Article III, rule 1 of the Hague-Visby Rules, the carrier is bound, before and at the beginning of the voyage, to exercise due diligence to make the ship seaworthy, properly man, equip and supply the ship, and make the parts of the ship in which goods are carried fit and safe for their reception, carriage and preservation. By contrast, Article IV, rule 2(a) provides, subject to certain conditions, an exception for the carrier in respect of loss arising from the act, neglect or default of the master, mariner, pilot or servants of the carrier in the navigation or management of the ship.
The central issue in relation to losses arising from cyberattacks is whether the loss resulted from an initial cybersecurity deficiency of the vessel or from an intervention or omission relating to the vessel’s navigation or management during the voyage. In the first case, the question is whether the cybersecurity vulnerability may be treated as falling within the obligation of seaworthiness; in the second, it is whether an exception connected with the navigation or management of the vessel may be invoked in respect of the loss.
Under English law, seaworthiness is not confined to the vessel’s physical condition; it is assessed by considering whether the vessel is in a condition to encounter the ordinary perils of the particular voyage. Hong Kong Fir Shipping Co Ltd v Kawasaki Kisen Kaisha Ltd [1962] is significant in demonstrating the flexible and fact-sensitive nature of the obligation of seaworthiness. Riverstone Meat Co Pty Ltd v Lancashire Shipping Co Ltd (The Muncaster Castle) [1961] further establishes the non-delegable nature of the carrier’s duty under the Hague Rules to exercise due diligence to make the vessel seaworthy. Accordingly, even where the carrier has entrusted the task of making the vessel seaworthy to third parties or independent contractors, it may be unable to escape liability for unseaworthiness resulting from a failure to exercise due diligence in that process. In another important decision, Alize 1954 v Allianz Elementar Versicherungs AG [2021], the UK Supreme Court held that a defective passage plan could render the vessel unseaworthy. Although passage planning is an activity relating to navigation, the Court held that a deficiency existing at the commencement of the voyage and endangering safe navigation could fall within the obligation of seaworthiness. Consequently, the carrier could not rely on the exception in Article IV, rule 2(a) of the Hague Rules merely by characterising the deficiency as a “error in navigation”. This decision is also significant in the context of losses arising from cyberattacks. Depending on the circumstances, a serious security vulnerability existing at the commencement of the voyage in the vessel’s navigation, route-planning or operational-control systems may be treated not merely as an operational malfunction, but as a deficiency falling within the obligation of seaworthiness. The foregoing decisions do not, however, concern cyberattacks directly. Whether cybersecurity deficiencies fall within the concept of seaworthiness therefore remains a matter of doctrinal debate.
In this context, the concept of “cyber-seaworthiness” is discussed in legal scholarship. The concept proceeds from the importance of cyber systems to the operational integrity of modern vessels and the view that an assessment of seaworthiness should not be confined to the vessel’s physical condition. Under this approach, losses caused by a cybersecurity vulnerability existing at the commencement of the voyage and capable of being prevented had the carrier exercised due diligence may fall within the obligation of seaworthiness. By contrast, where loss results from an individual act or omission by a crew member or an operational intervention during the voyage, whether the nautical fault defence under Article IV, rule 2(a) of the Hague-Visby Rules may be invoked must be considered separately in light of the nature of the incident.
Nevertheless, there is as yet no settled English case law directly addressing this distinction in the context of losses arising from cyberattacks. Any assessment under English law must therefore be undertaken by considering the existing Hague-Visby regime, the case law on seaworthiness and the developing scholarly views on cyber risks together.
ON WHAT GROUNDS IS A CARRIER’S LIABILITY FOR LOSSES ARISING FROM CYBERATTACKS ASSESSED UNDER TURKISH LAW?
Under Turkish law, the distinction between the obligation of seaworthiness and the navigation or management exception is important when assessing a carrier’s liability for losses arising from cyberattacks. Pursuant to Article 1141 of Turkish Commercial Code No. 6102 (the “TCC”), the carrier is under an obligation, in every contract of affreightment, to ensure that the vessel is seaworthy, voyage-worthy and cargo-worthy. To be relieved from liability for breach of this obligation, the carrier must prove that, despite exercising due diligence, it was not possible to discover the deficiency before the commencement of the voyage.
Seaworthiness is governed by Article 932 TCC. A vessel’s ability, in respect of essential elements such as its hull, general equipment, machinery and boilers, to withstand the perils of the voyage relates to seaworthiness; its readiness for the intended voyage in respect of its organisation, loading condition, fuel, provisions and the number and competence of its crew relates to voyage-worthiness. Cybersecurity vulnerabilities in navigation, communication, machinery and operational-control systems may therefore be assessed under seaworthiness or voyage-worthiness, having regard to the affected system and the risk created. As there is no settled Turkish case law on this issue, however, the assessment must be made in each case by reference to the system targeted, the nature of the vulnerability and whether the carrier exercised due diligence. Set against this obligation is the nautical fault exception under Article 1180 TCC. Under that provision, where loss results from an act relating to the navigation or other technical management of the vessel, the carrier is liable only for its own fault. Accordingly, as a rule, the carrier may not be held liable for faults of the crew relating to the navigation or technical management of the vessel. Nevertheless, since the same provision stipulates that, in cases of doubt, the loss shall be deemed not to have resulted from technical management, the nautical fault exception must be applied narrowly and with caution. Against this background, the legal characterisation of losses caused by a cyberattack on the vessel’s operational control may be assessed under two alternatives. If the cybersecurity vulnerability exploited by the attack existed at the commencement of the voyage and the carrier could have prevented it by exercising due diligence, the loss may fall within the obligation of seaworthiness. Conversely, if the loss arose from an isolated omission or operational intervention relating to the navigation or technical management of the vessel during the voyage, whether the nautical fault exception in Article 1180 TCC may be invoked will depend on the circumstances of the case.
Accordingly, the decisive considerations under Turkish law are not merely whether the cyberattack constituted external interference, but rather the system affected by the attack, when and how the vulnerability arose, the stage of the carriage at which the loss occurred, and whether the carrier exercised the requisite due diligence in relation to that risk.
CONCLUSION AND OUR ASSESSMENT
A carrier’s liability for losses arising from cyberattacks is not automatically excluded merely because the attack originated externally. The assessment must focus on the system targeted, whether the vulnerability existed at the commencement of the voyage, whether the carrier exercised due diligence, and the connection between the loss and the navigation or technical management of the vessel. Losses arising from a cybersecurity vulnerability that existed at the commencement of the voyage and could have been prevented through reasonable measures may therefore fall within the obligation of seaworthiness. Conversely, where the loss results from an isolated omission or intervention relating to the navigation or technical management of the vessel during the voyage, the nautical fault exception may be invoked, depending on the circumstances of the case. For carriers, cyber-risk management should therefore be treated not merely as a technical security measure, but as a matter of legal compliance linked to seaworthiness, due diligence and the burden of proof. The identification of cyber risks, implementation of necessary measures, training of personnel and application of measures in accordance with IMO guidelines may directly affect the carrier’s legal position in potential disputes.
In conclusion, liability for losses arising from cyberattacks must be assessed in each case by considering the technical and legal elements together. Particularly in attacks targeting electronic bills of lading and port systems, the contractual allocation of risk among platform providers, port operators and other service providers must also be separately examined.
Frequently Asked Questions
Does a navigational error caused by a cyberattack exempt the carrier from liability?
A navigational error caused by a cyberattack does not, in itself, exempt the carrier from liability. Where the security vulnerability existed at the commencement of the voyage and the carrier failed to exercise due diligence, the loss may fall within the obligation of seaworthiness. Conversely, where the loss arose from an isolated omission or intervention relating to the navigation or technical management of the vessel during the voyage, the application of the nautical fault exception may be considered in light of the circumstances of the case.
Do cybersecurity measures form part of the obligation of seaworthiness?
Whether the concept of seaworthiness encompasses cybersecurity measures has not yet been the subject of settled case law under Turkish law. Nevertheless, given the importance of cyber systems used in modern vessel operations to the vessel’s navigation, communications and operational safety, cyber-risk management may be treated as a factor connected with the assessment of seaworthiness.
Who is liable for delivery to the wrong person following an attack on an electronic bill of lading?
Liability will be determined according to the actor whose act or omission caused the loss. The contractual relationships among the carrier, platform provider, consignee, shipper and other service providers, their system-security obligations, and the process for verifying delivery instructions must be assessed together.
Does P&I insurance cover losses arising from cyberattacks?
The scope of P&I insurance will vary according to the relevant club rules, policy terms, cyber-risk exclusion clauses and the nature of the loss. Whether a loss arising from a cyberattack falls within cover must therefore be determined by examining the applicable insurance terms and exclusions in the particular case.
References
- A.P. Møller – Mærsk A/S, 2017 Annual Report, Risk Management section
- Afenyo, Mawuli / Caesar, Livingstone D., “Maritime cybersecurity threats: Gaps and directions for future research”, Ocean and Coastal Management, Vol. 236, 2023, Article No. 106493.
- Alize 1954 and another v Allianz Elementar Versicherungs AG and others (The CMA CGM Libra) [2021] UKSC 51.
- Hong Kong Fir Shipping Co Ltd v Kawasaki Kisen Kaisha Ltd [1962] 2 QB 26.
- IMO, Guidelines on Maritime Cyber Risk Management, MSC-FAL.1/Circ.3/Rev.3, 4 April 2025.
- International Convention for the Unification of Certain Rules of Law relating to Bills of Lading (Hague Rules), 1924, as amended by the 1968 Protocol (Hague-Visby Rules), Article III(1), Article IV(2)(a).
- Riverstone Meat Co Pty Ltd v Lancashire Shipping Co Ltd (The Muncaster Castle) [1961] AC 807.
- Schinas, Orestis / Metzger, Daniel, “Cyber-seaworthiness: A critical review of the literature”, Marine Policy, Vol. 151, 2023, Article No. 105592.










