SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Maritime and logistics threat intelligence report — 27 April – 3 May 2026

The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…

  • Reference: TI-2026-0504-002 (public edition)
  • Sector: Maritime and logistics
  • Reporting period: 27 April – 3 May 2026
  • Issued: 4 May 2026 · Lead analyst: P. Bassill (SOC Lead) · Reviewed by: SOC Reviewing Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents — and by the consolidation of ransomware activity against terminal-operating systems at major hub ports. DDoS, ransomware and malware infections remain the dominant categories. Smart-ship and OT exposure remains a structural concern.

Key Judgements

1. It is highly likely that ransomware against terminal-operating systems and shore-side ERP / freight-management platforms will remain the principal material-risk scenario for the vertical, with Qilin, Akira and DragonForce the most operationally-relevant affiliates. (HIGH confidence)

2. It is likely that the convergence of politically-motivated hacktivism with ransomware-as-a-service infrastructure will continue, with hub ports in the United Kingdom, North-West Europe and East Asia the highest-likelihood targets for disruptive activity. (MEDIUM-HIGH confidence)

3. It is likely that smart-ship and bridge-systems exposure will continue to be exploited for reconnaissance and credential harvesting, although the absolute volume of confirmed at-sea incidents remains low relative to shore-side systems. (MEDIUM confidence)

4. There is a realistic possibility that Citrix NetScaler CVE-2026-3055 / 4368 exploitation will affect maritime-sector edge appliances within the next reporting cycle; emergency-patch posture is warranted. (MEDIUM confidence)

2. Sector threat landscape

The maritime and logistics vertical absorbed a 103 per cent year-on-year rise in cyber incidents into 2025 according to CYTUR figures, with DDoS, ransomware and malware infections accounting for the dominant share of activity. The trajectory has not flattened in 2026: ransomware continues to consolidate, and large-scale infections at major hub ports across Europe and North America during the past twelve months have demonstrated the operational risk of terminal-operating-system compromise. Rotterdam, Los Angeles and Busan have all featured as prominent targets in recent reporting.

Inland and shore-side targets — freight-forwarding, customs-broking, warehouse-management — continue to be victim-targeted by the same ransomware affiliates that dominate the wider corporate-victim leak-site profile. The Transportation / Logistics tracker on Ransomware.live recorded sustained activity through the reporting period across Qilin, Akira, LockBit, DragonForce and ShinyHunters posts.

Operational-technology exposure remains a structural concern. CYTUR's 2026 reporting calls for a secure-by-design overhaul of smart-ship architectures, citing repeated reconnaissance against bridge systems, ECDIS and engine-management telemetry. Although the at-sea incident count remains substantially lower than shore-side, the criticality of any successful at-sea compromise is materially higher.

Geopolitically, the reporting period continues to carry elevated risk for maritime operators with Black Sea or Eastern Mediterranean exposure. NCSC has reiterated guidance for UK organisations to review their cyber security posture in light of evolving Middle East events, and Russian state-aligned hacktivist activity remains a credible disruption vector — albeit one whose operational impact is materially below that of ransomware.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.

THREAT ACTOR PROFILE — Qilin
AliasesAgenda, Qilin.B
Suspected OriginRussophone
Suspected SponsorOrganised criminal — RaaS
Primary MotivationFinancial — ransomware and data extortion
Sector TargetingLogistics, manufacturing, healthcare, financial services
Geographic FocusGlobal; sustained activity against UK / EU / North American logistics operators
Signature TTPsInitial access via stolen credentials and exposed RDP/VPN; rapid double extortion
Tooling / Malware FamiliesQilin/Agenda Rust- and Go-based encryptors; AnyDesk, RustDesk, ScreenConnect
Recent ActivityLeading position in April 2026 — 103 leak-site postings; logistics victims include freight-forwarders and 3PL operators
Assessed Threat to VerticalHIGH
Analytic ConfidenceHIGH
THREAT ACTOR PROFILE — DragonForce
AliasesDragonForce Malaysia (historical) / current ransomware brand
Suspected OriginMixed — RaaS with Western affiliates
Suspected SponsorOrganised criminal
Primary MotivationFinancial — ransomware
Sector TargetingRetail, hospitality, logistics, financial services
Geographic FocusGlobal; high-tempo UK operations during 2025–2026
Signature TTPsHelpdesk social engineering (Scattered-Spider-style affiliate use); commercial RMM abuse; rapid time-to-encrypt
Tooling / Malware FamiliesDragonForce encryptor; ScreenConnect; living-off-the-land
Recent ActivityCo-deployed in the M&S / Co-op campaigns; continues to move up the ransomware leaderboard
Assessed Threat to VerticalHIGH
Analytic ConfidenceHIGH
THREAT ACTOR PROFILE — Akira
AliasesStorm-1567
Suspected OriginRussophone
Suspected SponsorOrganised criminal — RaaS
Primary MotivationFinancial — ransomware
Sector TargetingManufacturing, logistics, professional services
Geographic FocusGlobal; significant UK and European presence
Signature TTPsInitial access via VPN credential abuse and exposed remote services; double extortion
Tooling / Malware FamiliesAkira / Megazord encryptor; Cobalt Strike; AnyDesk
Recent Activity48 leak-site postings in April 2026; logistics victims include road-freight and warehousing operators
Assessed Threat to VerticalHIGH
Analytic ConfidenceHIGH
THREAT ACTOR PROFILE — Russian state-aligned hacktivist clusters (NoName057(16) / KillNet-adjacent)
AliasesVarious
Suspected OriginRussia
Suspected SponsorState-aligned
Primary MotivationDisruption — political signalling
Sector TargetingGovernment, transport, ports, critical national infrastructure
Geographic FocusUnited Kingdom, Western Europe, NATO members
Signature TTPsVolumetric DDoS; defacement; opportunistic data leak
Tooling / Malware FamiliesBooter/stresser services; commodity DDoS infrastructure
Recent ActivityNCSC alert 19 Jan 2026; sustained low-grade DDoS targeting UK transport and public-sector portals
Assessed Threat to VerticalMEDIUM — disruption-grade rather than data-impact
Analytic ConfidenceMEDIUM

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1190Exploit Public-Facing ApplicationCitrix NetScaler CVE-2026-3055 / 4368 expected to be weaponised against maritime edge appliances during the next reporting cycle.M
Initial AccessT1078Valid AccountsStolen / brute-forced VPN and RDP credentials remain the dominant initial-access vector for ransomware affiliates targeting the vertical.H
Initial AccessT1566PhishingFreight-and-customs themed lures continue to be used against shipping-line and 3PL inboxes.H
ExecutionT1059.001PowerShellPowerShell -ExecutionPolicy Bypass remains the most prolific in-network execution signature in shore-side estates.H
ImpactT1486Data Encrypted for ImpactQilin / Akira / DragonForce encryptors continue to deploy against shore-side ERP and freight-management platforms.H
ImpactT1498Network Denial of ServiceRussian state-aligned hacktivist DDoS against UK transport and port portals continues at low operational tempo.M

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
Apr 2026Multiple logistics leak-site listings (global)Qilin, Akira, DragonForce, ShinyHunters772 victims claimed across 70 groups in April; logistics subset includes 3PL operators and freight-forwardersRansomware leak-site tracking
2025 — carry-forwardHub ports (Rotterdam, LA, Busan and others)Mixed ransomware / hacktivistTerminal-operating-system disruption; container-handling stoppage exemplars cited in CYTUR 2025/2026 reportingCYTUR / SAFETY4SEA / industrialcyber.co
2025–2026Smart-ship reconnaissance — multi-victimMixed; CYTUR-flaggedNo confirmed disruption-impact at sea but sustained reconnaissance against bridge / ECDIS / engine-management exposureCYTUR

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-31431Linux Kernel (resource transfer)7.8YesYesApply distro patches; prioritise Internet-facing & multi-tenant hosts
CVE-2026-3055Citrix NetScaler ADC / Gateway9.3YesYesPatch immediately; rotate session keys; review for known-exploit IOCs
CVE-2026-4368Citrix NetScaler ADC / Gateway8.8YesYesPatch; audit Gateway session logs
CVE-2026-41940WebPros cPanel / WP Squared / WHM9.8NoSuspectedPatch; audit panel admin auth events
CVE-2026-20122Cisco Catalyst SD-WAN Manager8.8YesYesPatch immediately; restrict admin plane to mgmt VLAN
CVE-2026-20128Cisco Catalyst SD-WAN Manager7.5YesYesRotate SD-WAN passwords; patch
CVE-2026-20133Cisco Catalyst SD-WAN Manager7.5YesYesPatch; review information disclosure logs
CVE-2025-2749Kentico Xperience9.0YesYesPatch; audit upload paths
CVE-2025-32975Quest KACE SMA8.8YesSuspectedPatch; restrict KACE management UI
CVE-2025-48700Synacor Zimbra Collaboration6.1YesYesPatch; restrict webmail to authenticated users
CVE-2024-27199JetBrains TeamCity7.3YesYesPatch; rotate CI secrets

7. Indicators of compromise

Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. IP Insights reputation feed currently lists 812,641 distinct IPv4 addresses across active blocklists (snapshot 04 May 2026 08:15 UTC). AS200651 (FlokiNET) currently lists 110 of 131 known IPs as blacklisted (risk score 100/critical); the AS continues to host bulletproof-style infrastructure observed in the reporting period across phishing, RAT C2, and brute-force activity.

TypeIndicatorFirst SeenConf.Notes
IPv4136[.]232[.]11[.]1020 Apr 2026HSSH brute-force; IP Insights threat 100/critical, 6 active blacklists; Reliance Jio IN
IPv487[.]236[.]176[.]4502 May 2026MConstantine Cybersecurity Ltd (GB) — IP Insights threat 100/critical, 6 blacklists
IPv4185[.]220[.]101[.]3003 May 2026MTor exit (for-privacy.net) — IP Insights threat 100/critical, 7 blacklists
ASNAS20065104 May 2026HFlokiNET — 110/131 known IPs blacklisted; risk 100/critical; bulletproof-style hosting

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical.

Threat ScenarioLikelihoodImpactComposite Rating
Ransomware deployment against terminal-operating-system / freight-managementMHCRITICAL
Edge-appliance compromise via Citrix NetScaler / Cisco SD-WAN CVEsMHHIGH
Helpdesk social engineering of shore-side IT support (Scattered-Spider pattern)MHHIGH
Hacktivist DDoS against port and transport public portalsHLMEDIUM
Smart-ship / OT reconnaissance leading to confidentiality compromiseMMMEDIUM
Customs / freight-themed phishing leading to credential theftHMHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection priorities for the next reporting cycle are: extension of edge-appliance hunting to cover Citrix NetScaler CVE-2026-3055 / 4368 indicators as soon as Sigma rules are released; tuning of perimeter-DDoS rule thresholds for low-grade Russian-aligned hacktivist activity (volumetric but predictable in source-AS pattern); deployment of detection content for terminal-operating-system anomalous behaviour (off-hours administrative actions on TOS hosts) where customer telemetry permits; and continued promotion of the IP Insights blocklist into customer perimeter-block lists, with particular attention to AS200651 (FlokiNET) and similar bulletproof-style hosting.

Defend

Patching priorities are dominated by Citrix NetScaler ADC / Gateway and the Linux kernel CVE-2026-31431. Network segmentation between corporate IT and shore-side OT networks remains the highest-impact structural control; ISO/IEC 27001 Annex A controls A.8.20 (network segregation) and A.8.21 (network services) are direct levers. Identity-controls hardening to mitigate Scattered-Spider-style helpdesk social engineering is recommended for any customer with outsourced shore-side IT support. Smart-ship secure-by-design recommendations from CYTUR 2026 should be assessed against the customer's fleet-modernisation programme.

Disrupt

Disruption priorities are sustained sharing of the IP Insights blocklist (812,641 entries) into customer perimeter-block lists; coordination with the Maritime Transportation System ISAC where customers are members; tabletop exercise against the terminal-operating-system ransomware scenario for any customer with material port or terminal exposure; and rehearsal of the manifest-and-customs document fall-back procedure for a multi-day TOS outage.

10. Forward outlook

It is highly likely that ransomware will remain the principal material-risk scenario for the vertical over the next reporting cycle, with TOS and freight-management platforms the highest-impact target class. (HIGH confidence; 30-day horizon)

It is likely that Citrix NetScaler exploitation will affect at least one UK maritime / logistics edge appliance within the next two reporting cycles. (MEDIUM-HIGH confidence; 60-day horizon)

There is a realistic possibility that a UK port or terminal operator will see a Scattered-Spider-style helpdesk-compromise within the next six reporting cycles. (MEDIUM confidence; 180-day horizon)

Russian-aligned hacktivist DDoS is highly likely to continue at low operational tempo against UK transport / port portals; impact is expected to remain disruption-grade rather than data-impact. (HIGH confidence; 30-day horizon)

Trigger conditions that would prompt revision of this forecast: confirmed compromise of a UK port TOS; in-the-wild exploitation of a previously-quiet maritime SaaS platform along the Cl0p pattern; an at-sea OT incident with confirmed disruption impact.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC — Threat reportsNCSC.GOV.UKA1
2CISA KEV — April / May 2026 additionsCISAA1
3CYTUR — Maritime cyber incidents jumped 103% in 2025CYTUR via SAFETY4SEAB2
4Channel 16 / Dryad Global — Maritime Cyber Risk in 2026Dryad GlobalB2
5Ransomware.live — Transportation / Logistics trackerransomware.liveB2
6April 2026 Ransomware Report — 772 victims, 70 groupsBreachSenseB2
7Marks & Spencer / Co-op — Scattered Spider / DragonForce reportingComputer Weekly / SecurityAffairsB2
8IP Insights — IP / ASN / CIDR threat intelligence APIipinsights.ioA1

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.