Most cyber conversations in insurance start with data breaches, ransomware, business interruption and privacy exposure. Those concerns are real. But for those of us in inland marine, there’s a different conversation that deserves attention.
What happens when a cyberattack ends in a physical loss?
Inland marine has always dealt with tangible things: cargo, equipment, inventory, building materials, specialty property and the movement of goods from place to place. What’s changed is that the systems directing those assets are now largely digital. That puts cyber and inland marine on a collision course, and it’s already happening.
CARGO THEFT IS TURNING INTO A CYBER PROBLEM
In April 2026, the FBI put out a warning about what it calls “cyber-enabled strategic cargo theft.” The FBI reports that cybercriminals are breaking into the computer systems of freight brokers and carriers, then using hijacked accounts, spoofed emails and fake load-board postings to pose as legitimate companies.
The prize isn’t necessarily data. It’s the freight itself.
According to the FBI, these actors can steer the logistics process so that genuine shipments end up at locations the criminals control. High-value loads are the target, and the victims include shippers, brokers, carriers and insurers.
Anyone working in inland marine should take notice. For years we’ve looked at cargo theft through a physical lens: organized theft rings, fictitious pickups, identity fraud and supply-chain weak points. Now there’s another question to ask: was the shipment itself manipulated through a compromised digital system? That’s a very different risk conversation.
THE TRANSPORTATION AND WAREHOUSE ECOSYSTEM IS CONNECTED AT EVERY STEP
The exposure reaches well beyond cargo theft. Today’s logistics operations lean on technology at nearly every stage:
- Warehouse management systems
- GPS and telematics
- Automated storage and retrieval systems
- Port operating systems
- Electronic bills of lading
- Load boards
- Transportation management systems
- Cloud-based inventory platforms
- Automated cranes and material-handling equipment
- Industrial control systems
The line between the physical and digital worlds keeps getting thinner.
Lloyd’s has studied this for several years. Its research on cyber risk and industrial control systems singled out manufacturing, shipping, energy and transportation as sectors where a cyberattack can move out of the digital environment and into the physical one.
That matters for inland marine because a cyber event doesn’t have to destroy a computer to produce a claim. Disrupting the system that decides where an asset goes, when it moves, how it operates or who is allowed to receive it can be enough.
THE FREQUENCY NUMBERS ARE HARD TO IGNORE
Verizon’s 2025 Data Breach Investigations Report reviewed more than 22,000 security incidents and 12,195 confirmed breaches. Ransomware showed up in 44% of the breaches analyzed, up from 32% the year before. Verizon also found that third-party involvement in breaches doubled to 30%.
That last figure stands out for our line of business, because transportation and logistics run on third-party relationships:
The shipper depends on a broker.
The broker depends on a carrier.
The carrier depends on a technology platform.
The warehouse depends on a cloud provider.
The manufacturer depends on its suppliers.
And the insurer may sit somewhere in the middle of all of it.
A weakness several links removed from the insured can still end up causing a physical loss. That’s what makes cyber aggregation so interesting.
WHAT IF ONE CYBER EVENT CAUSES MANY INLAND MARINE LOSSES?
This may be the part I find most compelling.
We’re used to thinking about accumulation in inland marine in terms of geography, catastrophe events, construction projects, concentrations of values and supply chains. Cyber adds another path to accumulation: a shared digital dependency.
Picture a technology provider serving hundreds of warehouses, carriers or logistics firms. An attacker doesn’t need to breach each insured individually. Hitting the platform that connects them could be enough.
Lloyd’s has modeled scenarios along these lines. In one Asia-Pacific scenario involving a cyberattack on major ports, it estimated an economic loss of $110 billion, with the damage spreading from port operators to businesses across the supply chain, including logistics and cargo-handling companies. That scenario was built several years ago, but the core idea holds up: cyber risk doesn’t respect traditional insurance class boundaries.
A single event could touch marine, inland marine, property, business interruption, contingent business interruption, liability and cyber all at once. That’s where life gets complicated for underwriters, brokers and claims professionals.
CLAIMS COULD GET MESSY, TOO
Consider a straightforward example. A carrier’s transportation management system is compromised. A shipment of high-value equipment is redirected. The cargo vanishes.
On its face, that looks like a cargo theft claim. But what actually happened?
- Was it physical theft?
- Was it fraud?
- Was there unauthorized access to a computer system?
- Was the carrier negligent?
- Was a third-party platform compromised?
- Was the shipment deliberately rerouted?
- Was a cyber event the cause of loss?
- Which policy responds?
- And what happens when several insureds are hit by the same event?
These aren’t hypotheticals. They go straight to coverage, causation, subrogation, claims handling and, potentially, litigation. The answers won’t always be obvious.
IT ISN’T JUST CARGO
Equipment faces the same issue. Construction sites rely more and more on connected machinery, telematics and cloud-based systems. Warehouses run on automation. Manufacturers depend on digitally controlled equipment. Ports use increasingly sophisticated technology to manage cargo and equipment.
Lloyd’s has specifically cautioned that the growing link between IT and operational technology opens pathways for cyber events to cause physical consequences.
So the inland marine discussion shouldn’t end at “Does the insured have a cyber policy?” We should also ask, “Which physical assets could be affected if their technology fails or gets manipulated?” That’s a different question entirely.
THEN THERE’S THE SUPPLY CHAIN
Supply-chain cyber risk may turn out to be the most important piece of this puzzle. ENISA’s 2025 research found that 47% of surveyed organizations named supply-chain attacks as one of their top cybersecurity concerns going forward, behind only ransomware at 55%.
That tracks with how commerce really works. No insured operates in isolation. Its warehouse connects to its transportation provider, which connects to brokers, which connect to shippers, which connect to manufacturers and suppliers. And more and more, every one of those organizations relies on the same technology platforms. The more interconnected the system, the harder it is to say where one risk stops and another begins.
WHAT SHOULD INLAND MARINE PROFESSIONALS BE ASKING?
I’m not suggesting every inland marine underwriter needs to become a cyber underwriter. But we should get more comfortable asking some basic questions:
- Which technology platforms are critical to the insured’s operations?
- Does the insured depend on third-party logistics or transportation platforms?
- How reliant is the operation on automated systems?
- Could a cyber event cause physical damage or physical loss?
- Could a compromised account lead to cargo being redirected?
- Do multiple insureds share common technology providers?
- Where might aggregation be hiding?
- Does the policy address cyber-related causation?
- What happens when a cyber event triggers a traditional inland marine loss?
- And maybe most important: will the claims team know what questions to ask when the loss happens?
That last one matters because cyber claims and traditional physical-loss claims can look very different in the early stages.
THE LINE BETWEEN CYBER AND INLAND MARINE IS BLURRING
I don’t believe cyber is replacing traditional inland marine perils. I think it’s becoming one more way those perils can occur.
The cargo is still there. The equipment is still there. The warehouse is still standing. The shipment still has to get from point A to point B. But the systems controlling all of it are increasingly digital.
That means the next inland marine loss might not start with someone breaking into a warehouse, stealing a truck or damaging a piece of equipment. It might start with someone at a keyboard.
For our industry, that raises real questions about underwriting, coverage, aggregation and claims. I think it’s worth talking about now, before a major loss forces us to figure it out the hard way.
Cyber may no longer be a separate inland marine risk. It may simply be part of how the next inland marine loss happens.


