Telescope
Create an Account

Tanjung Pelepas Cyberattack: Lessons for Your Cargo

Tanjung Pelepas Cyberattack: Lessons for Your Cargo

The cyberattack at Tanjung Pelepas demonstrated that a terminal can come to a standstill even when its cranes and yards remain available. For importers, the practical consequence is a chain of uncertain schedules, disrupted connections and urgent decisions. Previo en Origen provides evidence that enables them to respond without losing documentary control of their cargo.

What happened at the Port of Tanjung Pelepas?

Malaysia’s Port of Tanjung Pelepas (PTP) suspended operations for several hours following an attack that occurred shortly before midnight on a Wednesday, according to The Loadstar. The publication reported that AP Møller Maersk had confirmed the incident and described it as a cybersecurity issue.

PTP is operated through a joint venture between AP Møller Maersk and Malaysian conglomerate MMC. Following the incident, the affected systems were restored and operations began to resume gradually, although Maersk warned that some vessels could experience delays.

The terminal’s notice also stated that there was no evidence of unauthorised access to customer data. This distinction matters: a digital incident can disrupt the physical handling of cargo even when no data breach has been identified.

For an import manager, the operational question is not limited to whether company data was exposed. The manager must also determine which containers were loaded in time, which missed their window, whether connections will change and which documentation remains valid under the revised schedule.

How does a digital failure end up delaying cargo?

A modern terminal coordinates physical processes through digital systems. Truck entry, slot allocation, yard planning, equipment instructions and the authorisation of movements form an interdependent sequence. If the terminal temporarily loses the ability to record or validate an instruction, continuing to move containers may create more uncertainty than suspending operations.

From an importer’s perspective, an hours-long disruption does not always end when the system comes back online. The terminal must sequence pending movements, manage displaced time slots and normalise the information transmitted to supply chain participants. The impact may emerge later in the form of:

  • changes to the estimated departure or arrival date;
  • a missed connection during transshipment;
  • discrepancies between the planned schedule and the movement actually recorded;
  • rescheduling of inland transport or receiving appointments;
  • less time to review the shipment file before arrival at Mexican Customs;
  • pressure to make decisions based on incomplete information.

The incident is not an isolated case within the industry. In June 2017, the NotPetya ransomware affected 17 APMT terminals, including Rotterdam and New York, disrupting booking tools, communications and cargo handling. The Loadstar also reported shutdowns linked to cyberattacks at Transnet terminals in 2021, Jawaharlal Nehru Port Container Terminal in 2022 and Nagoya in 2023.

These precedents cannot predict how long each disruption will last. They do reveal a recurring vulnerability: port continuity depends as much on the systems that authorise movements as on the infrastructure that performs them.

What should an importer review during a port disruption?

The first response should not be to request indiscriminate updates from every supplier. It is better to build a verifiable picture of the shipment and separate confirmed facts from estimates that may still change.

1. Confirm the last known physical event

Determine whether the goods remain at the factory, have already been consolidated, have entered the terminal or have been confirmed as loaded on board. An estimated departure date is no substitute for evidence of the last completed movement.

2. Reconcile the physical cargo with the shipment file

Review the packing list, quantities, SKUs, UPCs, shipping marks, labelling and photographic evidence. If the schedule changes, the file must continue to describe accurately the goods actually being transported. Our container loading inspection checklist provides a starting point for structuring this review.

3. Identify decisions subject to a cut-off time

Not every action is equally urgent. Separate those that can wait for an update from the port from those affecting a connection, a transport appointment or the preparation of the customs pre-entry. This prioritisation reduces repeated changes to documents that are still subject to revision.

4. Maintain a single version of the shipment file

Emails, spreadsheets and photographs without a common reference can produce conflicting versions. The importer and its customs broker need to identify the current document, know who authorised each change and retain the decision history.

What does Previo en Origen contribute when the port comes to a standstill?

Previo en Origen, or Container Loading Inspection, cannot prevent a port cyberattack or replace a carrier’s protocols. Its function is to control a different aspect of risk: verifying the goods while they are still at the loading point and converting the observations into usable evidence before departure.

At Telescope Inspection, we focus this review on the questions that remain relevant even when the schedule changes: what was loaded, in what quantity, with what packaging, shipping marks and labelling, and what discrepancies exist against the commercial documentation. A complete explanation is available in Inspection at origin for imports: an explanation.

This file enables the foreign trade team to work from a firmer foundation while awaiting news from the terminal. The evidence does not eliminate the delay, but it helps prevent a cyber disruption from being compounded by uncertainty regarding quantities, product identification or documents.

1. Evidence before information congestion

Our inspectors document the process at the factory so that the importer does not have to rely solely on subsequent messages exchanged among multiple participants. The aim is to retain a clear record of the condition of the goods when loading was completed.

2. Traceability for coordinating decisions

Efficax structures the evidence and inspection report around the shipment. During a contingency, this traceability makes it easier to retrieve the correct records and share them with procurement, logistics, compliance and the customs brokerage firm.

3. Separating physical risk from transit risk

A properly inspected container may still be delayed at the port. Likewise, an on-time departure does not prove that its contents comply with the declaration. Managing both dimensions separately helps prevent incorrect conclusions and assign each incident to the appropriate responsible party.

4. Preparing documentation during the wait

The time before operations resume can be used to reconcile the packing list, review detected discrepancies and prepare tariff classification or compliance enquiries. Shipment document verification complements this discipline when several departments need to work from the same file.

How can the incident be turned into a continuity policy?

The lesson from Tanjung Pelepas is not that every port will experience the same disruption. It is that continuity planning must also address a temporary loss of digital visibility or capacity.

An effective policy for importers should define:

  • which source confirms the container’s last physical event;
  • who validates a schedule change;
  • what information the factory must retain before releasing the cargo;
  • how photographic evidence and digitised reports are shared;
  • when the customs broker should become involved;
  • which discrepancies require correction before export;
  • how the decision is recorded to maintain traceability.

The test of this policy is not the number of alerts received, but the ability to answer specific questions without reconstructing the shipment from scratch. When the terminal announces that operations are gradually resuming, the importer should know which cargo is affected, which documentation remains valid and which next decision cannot be postponed.

At Telescope Inspection, we understand resilience as the combination of evidence at origin, traceability and documentary coordination. Previo en Origen does not replace the cybersecurity measures of ports and shipping lines; it protects the part of the first mile that the importer can verify before an external disruption reduces the available options. In this way, we help transform operational risks into better-supported decisions for the supply chain. Continuity begins with knowing what was loaded.