At 23:34 local time on Wednesday 9 September 2026, a cyber attack hit the operating systems of the container terminal at Tanjung Pelepas, in the Malaysian state of Johor. To contain the attack, the operator isolated the affected systems and suspended cargo-handling operations as a precaution. A controlled, phased restart began the following day. The disruption affected one of the world's largest container transhipment hubs. In 2025, PTP handled 14,028,375 TEU, exceeding the 14 million mark for the first time. The port lies at the eastern entrance to the Strait of Malacca, opposite Singapore, and is one of the main hubs used by the Gemini Cooperation between Maersk and Hapag-Lloyd on Asia-Europe and intra-Asia routes. The terminal is operated by a joint venture between Malaysian group MMC and APM Terminals, a Maersk subsidiary.
The shutdown lasted several hours and, by 10 September, the terminal had already introduced manual procedures for the entry of full and empty export containers at its gates, including transfers between terminals in the free zone. Maersk confirmed that it was working in close coordination with the operator. "Some vessels may experience delays, but the recovery is progressing well," a spokesperson for the Danish group said, adding that minimising disruption for customers was the priority. In the first few days, the impact on traffic appeared limited. Lloyd's List Intelligence data showed arrivals and departures operating largely as normal and, on the morning of 11 September, no container ships were waiting at anchor. The only anomaly identified involved the 15,226 TEU Maersk Hanoi, sailing from Pointe Noire: on 10 September, the vessel deviated from its route for around ten hours in the Strait of Malacca before resuming its voyage towards the Malaysian port.
The operator has provided few details about the nature of the attack. In a notice to freight forwarders, PTP said it was working with cyber security experts to investigate the incident and strengthen its defences. At an early stage, it also said there was no evidence of unauthorised access to customer data, an assessment that the ongoing forensic analysis may confirm or disprove. Neither the type of malicious code nor the perpetrators have been disclosed. However, a claim of responsibility has emerged. On 11 September, PTP appeared on the website where the Direwolf group publishes details of its cyber attacks, according to Ransomware.live. Active since May 2025, Direwolf uses double extortion, according to AhnLab researchers: it encrypts victims' data and threatens to release it. PTP has not confirmed that it suffered a ransomware attack and has not officially attributed the incident to the group.
The incident adds to a series of attacks on port infrastructure. In 2017, the NotPetya malware paralysed Maersk's systems, affecting the group's vessels and terminals. In February 2022, an attack on the Jawaharlal Nehru Port Container Terminal in India caused a five-day shutdown, while in July 2023 the LockBit 3.0 group brought operations at Japan's Port of Nagoya to a halt for two days.









































































