Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…
- Reference: TI-2026-0504-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 27 April – 3 May 2026
- Issued: 4 May 2026 · Lead analyst: P. Bassill (SOC Lead) · Reviewed by: SOC Reviewing Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents — and by the consolidation of ransomware activity against terminal-operating systems at major hub ports. DDoS, ransomware and malware infections remain the dominant categories. Smart-ship and OT exposure remains a structural concern.
Key Judgements
1. It is highly likely that ransomware against terminal-operating systems and shore-side ERP / freight-management platforms will remain the principal material-risk scenario for the vertical, with Qilin, Akira and DragonForce the most operationally-relevant affiliates. (HIGH confidence)
2. It is likely that the convergence of politically-motivated hacktivism with ransomware-as-a-service infrastructure will continue, with hub ports in the United Kingdom, North-West Europe and East Asia the highest-likelihood targets for disruptive activity. (MEDIUM-HIGH confidence)
3. It is likely that smart-ship and bridge-systems exposure will continue to be exploited for reconnaissance and credential harvesting, although the absolute volume of confirmed at-sea incidents remains low relative to shore-side systems. (MEDIUM confidence)
4. There is a realistic possibility that Citrix NetScaler CVE-2026-3055 / 4368 exploitation will affect maritime-sector edge appliances within the next reporting cycle; emergency-patch posture is warranted. (MEDIUM confidence)
2. Sector threat landscape
The maritime and logistics vertical absorbed a 103 per cent year-on-year rise in cyber incidents into 2025 according to CYTUR figures, with DDoS, ransomware and malware infections accounting for the dominant share of activity. The trajectory has not flattened in 2026: ransomware continues to consolidate, and large-scale infections at major hub ports across Europe and North America during the past twelve months have demonstrated the operational risk of terminal-operating-system compromise. Rotterdam, Los Angeles and Busan have all featured as prominent targets in recent reporting.
Inland and shore-side targets — freight-forwarding, customs-broking, warehouse-management — continue to be victim-targeted by the same ransomware affiliates that dominate the wider corporate-victim leak-site profile. The Transportation / Logistics tracker on Ransomware.live recorded sustained activity through the reporting period across Qilin, Akira, LockBit, DragonForce and ShinyHunters posts.
Operational-technology exposure remains a structural concern. CYTUR's 2026 reporting calls for a secure-by-design overhaul of smart-ship architectures, citing repeated reconnaissance against bridge systems, ECDIS and engine-management telemetry. Although the at-sea incident count remains substantially lower than shore-side, the criticality of any successful at-sea compromise is materially higher.
Geopolitically, the reporting period continues to carry elevated risk for maritime operators with Black Sea or Eastern Mediterranean exposure. NCSC has reiterated guidance for UK organisations to review their cyber security posture in light of evolving Middle East events, and Russian state-aligned hacktivist activity remains a credible disruption vector — albeit one whose operational impact is materially below that of ransomware.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
| THREAT ACTOR PROFILE — Qilin | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal — RaaS |
| Primary Motivation | Financial — ransomware and data extortion |
| Sector Targeting | Logistics, manufacturing, healthcare, financial services |
| Geographic Focus | Global; sustained activity against UK / EU / North American logistics operators |
| Signature TTPs | Initial access via stolen credentials and exposed RDP/VPN; rapid double extortion |
| Tooling / Malware Families | Qilin/Agenda Rust- and Go-based encryptors; AnyDesk, RustDesk, ScreenConnect |
| Recent Activity | Leading position in April 2026 — 103 leak-site postings; logistics victims include freight-forwarders and 3PL operators |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — DragonForce | |
|---|---|
| Aliases | DragonForce Malaysia (historical) / current ransomware brand |
| Suspected Origin | Mixed — RaaS with Western affiliates |
| Suspected Sponsor | Organised criminal |
| Primary Motivation | Financial — ransomware |
| Sector Targeting | Retail, hospitality, logistics, financial services |
| Geographic Focus | Global; high-tempo UK operations during 2025–2026 |
| Signature TTPs | Helpdesk social engineering (Scattered-Spider-style affiliate use); commercial RMM abuse; rapid time-to-encrypt |
| Tooling / Malware Families | DragonForce encryptor; ScreenConnect; living-off-the-land |
| Recent Activity | Co-deployed in the M&S / Co-op campaigns; continues to move up the ransomware leaderboard |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — Akira | |
|---|---|
| Aliases | Storm-1567 |
| Suspected Origin | Russophone |
| Suspected Sponsor | Organised criminal — RaaS |
| Primary Motivation | Financial — ransomware |
| Sector Targeting | Manufacturing, logistics, professional services |
| Geographic Focus | Global; significant UK and European presence |
| Signature TTPs | Initial access via VPN credential abuse and exposed remote services; double extortion |
| Tooling / Malware Families | Akira / Megazord encryptor; Cobalt Strike; AnyDesk |
| Recent Activity | 48 leak-site postings in April 2026; logistics victims include road-freight and warehousing operators |
| Assessed Threat to Vertical | HIGH |
| Analytic Confidence | HIGH |
| THREAT ACTOR PROFILE — Russian state-aligned hacktivist clusters (NoName057(16) / KillNet-adjacent) | |
|---|---|
| Aliases | Various |
| Suspected Origin | Russia |
| Suspected Sponsor | State-aligned |
| Primary Motivation | Disruption — political signalling |
| Sector Targeting | Government, transport, ports, critical national infrastructure |
| Geographic Focus | United Kingdom, Western Europe, NATO members |
| Signature TTPs | Volumetric DDoS; defacement; opportunistic data leak |
| Tooling / Malware Families | Booter/stresser services; commodity DDoS infrastructure |
| Recent Activity | NCSC alert 19 Jan 2026; sustained low-grade DDoS targeting UK transport and public-sector portals |
| Assessed Threat to Vertical | MEDIUM — disruption-grade rather than data-impact |
| Analytic Confidence | MEDIUM |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Citrix NetScaler CVE-2026-3055 / 4368 expected to be weaponised against maritime edge appliances during the next reporting cycle. | M |
| Initial Access | T1078 | Valid Accounts | Stolen / brute-forced VPN and RDP credentials remain the dominant initial-access vector for ransomware affiliates targeting the vertical. | H |
| Initial Access | T1566 | Phishing | Freight-and-customs themed lures continue to be used against shipping-line and 3PL inboxes. | H |
| Execution | T1059.001 | PowerShell | PowerShell -ExecutionPolicy Bypass remains the most prolific in-network execution signature in shore-side estates. | H |
| Impact | T1486 | Data Encrypted for Impact | Qilin / Akira / DragonForce encryptors continue to deploy against shore-side ERP and freight-management platforms. | H |
| Impact | T1498 | Network Denial of Service | Russian state-aligned hacktivist DDoS against UK transport and port portals continues at low operational tempo. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| Apr 2026 | Multiple logistics leak-site listings (global) | Qilin, Akira, DragonForce, ShinyHunters | 772 victims claimed across 70 groups in April; logistics subset includes 3PL operators and freight-forwarders | Ransomware leak-site tracking |
| 2025 — carry-forward | Hub ports (Rotterdam, LA, Busan and others) | Mixed ransomware / hacktivist | Terminal-operating-system disruption; container-handling stoppage exemplars cited in CYTUR 2025/2026 reporting | CYTUR / SAFETY4SEA / industrialcyber.co |
| 2025–2026 | Smart-ship reconnaissance — multi-victim | Mixed; CYTUR-flagged | No confirmed disruption-impact at sea but sustained reconnaissance against bridge / ECDIS / engine-management exposure | CYTUR |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-31431 | Linux Kernel (resource transfer) | 7.8 | Yes | Yes | Apply distro patches; prioritise Internet-facing & multi-tenant hosts |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys; review for known-exploit IOCs |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-41940 | WebPros cPanel / WP Squared / WHM | 9.8 | No | Suspected | Patch; audit panel admin auth events |
| CVE-2026-20122 | Cisco Catalyst SD-WAN Manager | 8.8 | Yes | Yes | Patch immediately; restrict admin plane to mgmt VLAN |
| CVE-2026-20128 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Rotate SD-WAN passwords; patch |
| CVE-2026-20133 | Cisco Catalyst SD-WAN Manager | 7.5 | Yes | Yes | Patch; review information disclosure logs |
| CVE-2025-2749 | Kentico Xperience | 9.0 | Yes | Yes | Patch; audit upload paths |
| CVE-2025-32975 | Quest KACE SMA | 8.8 | Yes | Suspected | Patch; restrict KACE management UI |
| CVE-2025-48700 | Synacor Zimbra Collaboration | 6.1 | Yes | Yes | Patch; restrict webmail to authenticated users |
| CVE-2024-27199 | JetBrains TeamCity | 7.3 | Yes | Yes | Patch; rotate CI secrets |
7. Indicators of compromise
Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. IP Insights reputation feed currently lists 812,641 distinct IPv4 addresses across active blocklists (snapshot 04 May 2026 08:15 UTC). AS200651 (FlokiNET) currently lists 110 of 131 known IPs as blacklisted (risk score 100/critical); the AS continues to host bulletproof-style infrastructure observed in the reporting period across phishing, RAT C2, and brute-force activity.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force; IP Insights threat 100/critical, 6 active blacklists; Reliance Jio IN |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd (GB) — IP Insights threat 100/critical, 6 blacklists |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical, 7 blacklists |
| ASN | AS200651 | 04 May 2026 | H | FlokiNET — 110/131 known IPs blacklisted; risk 100/critical; bulletproof-style hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment against terminal-operating-system / freight-management | M | H | CRITICAL |
| Edge-appliance compromise via Citrix NetScaler / Cisco SD-WAN CVEs | M | H | HIGH |
| Helpdesk social engineering of shore-side IT support (Scattered-Spider pattern) | M | H | HIGH |
| Hacktivist DDoS against port and transport public portals | H | L | MEDIUM |
| Smart-ship / OT reconnaissance leading to confidentiality compromise | M | M | MEDIUM |
| Customs / freight-themed phishing leading to credential theft | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle are: extension of edge-appliance hunting to cover Citrix NetScaler CVE-2026-3055 / 4368 indicators as soon as Sigma rules are released; tuning of perimeter-DDoS rule thresholds for low-grade Russian-aligned hacktivist activity (volumetric but predictable in source-AS pattern); deployment of detection content for terminal-operating-system anomalous behaviour (off-hours administrative actions on TOS hosts) where customer telemetry permits; and continued promotion of the IP Insights blocklist into customer perimeter-block lists, with particular attention to AS200651 (FlokiNET) and similar bulletproof-style hosting.
Defend
Patching priorities are dominated by Citrix NetScaler ADC / Gateway and the Linux kernel CVE-2026-31431. Network segmentation between corporate IT and shore-side OT networks remains the highest-impact structural control; ISO/IEC 27001 Annex A controls A.8.20 (network segregation) and A.8.21 (network services) are direct levers. Identity-controls hardening to mitigate Scattered-Spider-style helpdesk social engineering is recommended for any customer with outsourced shore-side IT support. Smart-ship secure-by-design recommendations from CYTUR 2026 should be assessed against the customer's fleet-modernisation programme.
Disrupt
Disruption priorities are sustained sharing of the IP Insights blocklist (812,641 entries) into customer perimeter-block lists; coordination with the Maritime Transportation System ISAC where customers are members; tabletop exercise against the terminal-operating-system ransomware scenario for any customer with material port or terminal exposure; and rehearsal of the manifest-and-customs document fall-back procedure for a multi-day TOS outage.
10. Forward outlook
It is highly likely that ransomware will remain the principal material-risk scenario for the vertical over the next reporting cycle, with TOS and freight-management platforms the highest-impact target class. (HIGH confidence; 30-day horizon)
It is likely that Citrix NetScaler exploitation will affect at least one UK maritime / logistics edge appliance within the next two reporting cycles. (MEDIUM-HIGH confidence; 60-day horizon)
There is a realistic possibility that a UK port or terminal operator will see a Scattered-Spider-style helpdesk-compromise within the next six reporting cycles. (MEDIUM confidence; 180-day horizon)
Russian-aligned hacktivist DDoS is highly likely to continue at low operational tempo against UK transport / port portals; impact is expected to remain disruption-grade rather than data-impact. (HIGH confidence; 30-day horizon)
Trigger conditions that would prompt revision of this forecast: confirmed compromise of a UK port TOS; in-the-wild exploitation of a previously-quiet maritime SaaS platform along the Cl0p pattern; an at-sea OT incident with confirmed disruption impact.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC — Threat reports | NCSC.GOV.UK | A1 |
| 2 | CISA KEV — April / May 2026 additions | CISA | A1 |
| 3 | CYTUR — Maritime cyber incidents jumped 103% in 2025 | CYTUR via SAFETY4SEA | B2 |
| 4 | Channel 16 / Dryad Global — Maritime Cyber Risk in 2026 | Dryad Global | B2 |
| 5 | Ransomware.live — Transportation / Logistics tracker | ransomware.live | B2 |
| 6 | April 2026 Ransomware Report — 772 victims, 70 groups | BreachSense | B2 |
| 7 | Marks & Spencer / Co-op — Scattered Spider / DragonForce reporting | Computer Weekly / SecurityAffairs | B2 |
| 8 | IP Insights — IP / ASN / CIDR threat intelligence API | ipinsights.io | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
Maritime and logistics threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by continued growth in maritime cyber incidents (CYTUR's 103% YoY increase indicator carried forward into Q2 2026), the West Pharmaceutical Services ransomware event affecting shipping and manufacturing logistics, and the persistent operational risk to AIS…
Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…