French authorities are investigating a suspected cyberattack targeting the GNV ferry Fantastic, which operates between Sète and North Africa. The investigation was initiated after Italian intelligence, acting on information from GNV, alerted French officials about two sailors—one Latvian and one Bulgarian—suspected of espionage for a foreign power. During a search of the vessel in the port of Sète, French intelligence agents detained the two individuals and discovered a device containing RAT-type malware capable of remotely controlling the ship's navigation systems. The Latvian sailor was charged in Paris with conspiracy to serve a foreign power, attempted computer system intrusion, and possession of devices intended to interfere with navigation, while the Bulgarian was released.
GNV reported that it had identified and neutralized the attempted intrusion, stating that its systems remained protected and unaffected. The company has fully cooperated with authorities throughout the investigation, which is reportedly focusing on possible Russian involvement amid broader concerns about hybrid warfare in European waters. The vessel was temporarily sealed for safety checks but has since resumed operations. Italian police and Eurojust have also conducted searches in Latvia as part of the ongoing inquiry into whether the ship's systems were exposed to malware designed for remote hijacking.

TTPs, infrastructure, and targeting history in one profile.
9 events from the most recent confirmed update back to the earliest known activity.
In response to the incident and broader maritime cyber risk concerns, the International Association of Classification Societies introduced new cybersecurity requirements for ships. The move reflected growing concern over the exposure of digitally connected maritime systems.
By the time of later reporting, the investigation had broadened into an international probe involving French authorities, Italian counterparts, and reported coordination with Eurojust. Emergency searches and evidence seizures were carried out as investigators examined the scope of the attempted compromise.
As details emerged publicly, media reports and officials indicated the inquiry was focusing on possible foreign-state involvement, with Russia cited as a suspected actor. The case was increasingly framed as a potential example of hybrid interference targeting maritime infrastructure.
The ferry was temporarily sealed and subjected to security and safety inspections after the malware discovery and arrests. After checks were completed, the vessel was cleared to return to service.
French prosecutors formally began investigating the suspected cyberattack on the GNV Fantastic, examining whether the malware was part of foreign interference and whether it could have supported a remote hijack attempt. French and Italian authorities, including DGSI, were reported to be cooperating on the case.
Following the initial detentions, French investigators released a Bulgarian national while continuing to hold a Latvian crew member. The Latvian suspect was charged in Paris with conspiracy to infiltrate computer systems for the benefit of a foreign power.
French authorities detained two crew members of the Fantastic in Sète as part of the investigation into the malware incident. The detentions were tied to suspicions that the malware had been installed from onboard by insiders.
After being prompted by GNV, Italian intelligence alerted French authorities about two sailors on the ferry suspected of espionage or acting for a foreign power. This triggered a cross-border security response focused on the vessel while it was in France.
Grandi Navi Veloci (GNV) detected and neutralized malware on the Italian passenger ferry Fantastic before any reported operational consequences occurred. The malicious code was described as capable of enabling unauthorized remote access to onboard systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcetechrepublic.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceen.ilsole24ore.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.