Key facts
- Chinese hacking group Mustang Panda targeted European maritime organizations throughout 2025.
- The attacks impacted at least seven EU member states.
- The group engaged in spying and strategic intelligence collection.
- Mustang Panda is considered a significant threat to EU organizations due to advanced capabilities.
- The group previously targeted EU diplomatic missions in 2022 and Russian defense firms in 2025.
The European Union's cybersecurity agency, ENISA, reported on Tuesday that a China-based hacking group known as Mustang Panda conducted sustained cyberattacks against European maritime organizations throughout 2025. The group, which U.S. justice department officials accuse of being sponsored by the Chinese government, engaged in espionage and strategic intelligence collection, impacting organizations in at least seven EU member states. ENISA described Mustang Panda as a "significant threat" to EU organizations due to its advanced capabilities and capacity for repeated attacks. The agency noted that shipping is a particularly vulnerable sector where disruptive cyberattacks could have substantial knock-on effects on trade and economic considerations, especially within the context of geopolitical developments. Mustang Panda had previously been identified by ENISA as a key threat in 2023 after targeting EU diplomatic missions in 2022, and in 2025, it was also found to have spied on Russian defense and aerospace firms. China has previously demonstrated interest in Western shipping operations, particularly as shipping routes in the Middle East face increasing navigation challenges.
