SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Maritime and logistics threat intelligence report — 4–8 May 2026

The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…

  • Reference: TI-2026-0508-002 (public edition)
  • Sector: Maritime and logistics
  • Reporting period: 4–8 May 2026
  • Issued: 8 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents — and by the consolidation of ransomware activity against terminal-operating systems at major hub ports. The operationally most-significant single development inside the reporting window is NCSC's 4 May 2026 blog on the AI-accelerated patch wave, which is materially relevant to a vertical with an established legacy of long-life OT estates and slow patch cadences.

The Q1 2026 Transportation/Logistics victim count on ransomware.live continues to track at the elevated post-2024 baseline, with TheGentlemen and DragonForce both visible in the maritime-aligned subset.

Key Judgements

The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  1. It is highly likely that ransomware against terminal-operating systems and shore-side ERP / freight-management platforms will remain the principal material-risk scenario for the vertical, with Qilin, TheGentlemen and DragonForce the most operationally-relevant affiliates over the next reporting cycle. (HIGH confidence)
  2. It is likely that the convergence of politically-motivated hacktivism with ransomware-as-a-service infrastructure will continue, with hub ports in the United Kingdom, North-West Europe and East Asia the highest-likelihood targets for disruptive activity. (MEDIUM-HIGH confidence)
  3. It is likely that smart-ship and bridge-systems exposure will become the dominant emerging attack surface over the 6–12 month horizon as fleet-wide IT/OT convergence continues. The 103 per cent year-on-year incident increase reported by CYTUR is the leading indicator. (MEDIUM-HIGH confidence)
  4. There is a realistic possibility that AI-accelerated vulnerability discovery — flagged by NCSC on 4 May 2026 — will produce at least one nationally-significant maritime exploitation event before the end of Q3 2026. The vertical's combination of legacy patch cadence and high public-facing attack surface makes it disproportionately exposed. (MEDIUM confidence)
  5. It is likely that supply-chain compromises of maritime software vendors — the pattern that compromised approximately one thousand shipping vessels in the recent ransomware attack on a maritime-software provider — will continue to be the highest-leverage scaling vector for adversaries. (MEDIUM-HIGH confidence)

2. Sector threat landscape

Maritime cyber incidents jumped 103 per cent in 2025 according to the latest CYTUR reporting, with DDoS, ransomware and malware infections remaining the dominant categories. Smart-ship and OT exposure is now an explicit structural concern across the vertical, and the Maritime Transportation System ISAC continues to be the highest-value sector source for non-public indicator and incident sharing.

The April 2026 leak-site picture (Breachsense / ransomware.live) is consistent with the picture published last cycle: 772 total victims claimed across 70 groups, with TheGentlemen now in second place at 82 victims (displacing Akira) and DragonForce in third with 63. The maritime / transportation / logistics subset of these victims is small but growing in both absolute and relative terms; the principal operational-impact scenario remains terminal-operating-system encryption rather than data-extortion against shipping carriers.

Vulnerability exposure at the network edge is the dominant gating factor for the vertical. The Citrix NetScaler ADC / Gateway CVEs from late April, the Ivanti EPMM CVE-2026-6973 (KEV-listed 1 May, FCEB deadline 10 May) and the Palo Alto PAN-OS User-ID portal CVE-2026-0300 (KEV-listed 6 May, FCEB deadline 27 May) collectively define a patch-wave that maritime operators with legacy port and terminal estates are particularly poorly placed to absorb at speed. The MOVEit Automation CVE-2026-4670 active-exploitation reporting matters specifically for any maritime client running automated freight-document or customs-document file transfer.

Geopolitical pressure continues to shape the threat picture. Russian state-aligned hacktivist clusters remain active against UK and NATO-aligned maritime targets; the recent ScarCruft (DPRK-aligned) gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the wider pattern of state-aligned actors using third-party software supply chains as a delivery vector — a pattern of acute concern in maritime, where vessel-management and terminal-operating-system software are tightly concentrated across a small number of vendors.

The IP Insights service currently lists FlokiNET (AS200651) at 110 of 132 known IPs blacklisted with risk 100/critical, and the Tor exit infrastructure (for-privacy.net example 185.220.101.30, 7 active blacklists) continues to surface in cross-tenant scanning telemetry.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.

Qilin

  • Aliases: Agenda, Qilin.B
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal — RaaS
  • Primary Motivation: Financial — ransomware and data extortion
  • Sector Targeting: Healthcare, financial services, manufacturing, transportation, professional services
  • Geographic Focus: Global; sustained UK and EU activity
  • Signature TTPs: Initial access via stolen / brute-forced credentials and exposed RDP / VPN; abuse of legitimate remote-management tooling for persistence; double extortion with fast time-to-encrypt
  • Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptor variants; AnyDesk, RustDesk and ScreenConnect for hands-on-keyboard
  • Recent Activity: 103 leak-site postings in April 2026 — fourth consecutive month leading the global leak-site rankings; transportation / logistics victims continue to be a non-trivial subset
  • Assessed Threat to Vertical: HIGH — sustained operational tempo, mature TTPs, vertical-aligned victimology
  • Analytic Confidence: HIGH

TheGentlemen

  • Aliases:
  • Suspected Origin: Russophone
  • Suspected Sponsor: Organised criminal — RaaS
  • Primary Motivation: Financial — ransomware
  • Sector Targeting: Manufacturing, transportation, logistics, professional services
  • Geographic Focus: Global; growing UK and EU activity
  • Signature TTPs: Edge-appliance exploitation; stolen-credential initial access; rapid lateral movement; double-extortion
  • Tooling / Malware Families: Custom encryptor; LOLBins; abuse of native admin tooling
  • Recent Activity: 82 leak-site postings in April 2026 — second-place global ranking; visible in maritime / logistics victim subset
  • Assessed Threat to Vertical: HIGH — rising tempo and confirmed sector victimology
  • Analytic Confidence: MEDIUM-HIGH

DragonForce

  • Aliases:
  • Suspected Origin: Russophone (operator); Western affiliate cluster (Scattered Spider)
  • Suspected Sponsor: Organised criminal — RaaS with white-label affiliate model
  • Primary Motivation: Financial — ransomware and extortion
  • Sector Targeting: Retail, hospitality, financial services, transportation, logistics
  • Geographic Focus: Global; high-tempo UK operations
  • Signature TTPs: White-label ransomware payload deployed by a range of affiliates; extensive use of native admin tooling and identity-provider compromise
  • Tooling / Malware Families: DragonForce ransomware payload; commercial RMM tooling
  • Recent Activity: 63 leak-site postings in April 2026 — third-place ranking; payload of choice in the M&S / Co-op campaign and observed against transportation targets
  • Assessed Threat to Vertical: MEDIUM-HIGH — affiliate-cluster diversity makes vertical targeting opportunistic but consistently present
  • Analytic Confidence: MEDIUM-HIGH

Russian state-aligned hacktivist clusters

  • Aliases: NoName057(16), Killnet successors, various
  • Suspected Origin: Russia-aligned
  • Suspected Sponsor: State-aligned hacktivist; mixed with criminal infrastructure
  • Primary Motivation: Disruption — political signalling
  • Sector Targeting: Government, financial services, transportation, logistics, energy
  • Geographic Focus: UK, EU, NATO-aligned
  • Signature TTPs: DDoS against public-facing portals and booking systems; web-defacement; opportunistic compromise
  • Tooling / Malware Families: Open-source DDoS tooling; commodity loaders
  • Recent Activity: Sustained DDoS activity against UK and EU port and ferry portal infrastructure during the reporting period
  • Assessed Threat to Vertical: MEDIUM — disruptive but sub-ransomware in operational impact
  • Analytic Confidence: MEDIUM

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1133External Remote ServicesCitrix NetScaler, Ivanti EPMM and Palo Alto PAN-OS additions to KEV expose maritime edge appliances; legacy OT estates particularly slow to patch.H
Initial AccessT1190Exploit Public-Facing ApplicationMOVEit Automation CVE-2026-4670 and Weaver E-Cology CVE-2026-22679 add unauthenticated RCE surfaces to maritime trust platforms.H
Initial AccessT1199Trusted RelationshipVendor-supply-chain compromise of vessel-management and TOS providers — pattern reinforced by recent maritime-software ransomware impacting ~1,000 vessels.M
DiscoveryT1046Network Service ScanningSustained internet-wide scanning of maritime remote-access surfaces; AS211298 (Constantine Cybersecurity) measurement and AS200651 (FlokiNET) malicious indistinguishable on volumetric metrics alone — disposition relies on intent and content.M
ImpactT1486Data Encrypted for ImpactQilin, TheGentlemen, DragonForce affiliates continue to deploy encryptors against transportation / logistics targets globally.H
ImpactT1499Endpoint Denial of ServiceRussian state-aligned hacktivist DDoS against UK / EU port and ferry portal infrastructure.M

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
May 2026Multiple maritime / logistics leak-site listings (global)Qilin, TheGentlemen, DragonForceMaritime / transportation subset of the 772 April leak-site victims; consistent with Q1 2026 baselineRansomware.live; Breachsense
May 2026Vulnerability patch wave (sector-wide)MultipleNCSC 4 May 2026 blog warns AI-accelerated vulnerability discovery is shrinking time-to-weaponisation; Ivanti EPMM, PAN-OS User-ID and Linux kernel CVE additions to CISA KEV directly relevant to maritime estatesNCSC; CISA
RecentMaritime-software vendor — ransomware impacting ~1,000 vessels (carry-forward)Unattributed (RaaS-aligned)Demonstrative of the vendor-supply-chain scaling vector; remains the operational reference case for the verticalRecorded Future / Quorum Cyber

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM)8.8Yes (1 May)YesPatch immediately; FCEB deadline 10 May; rotate admin sessions
CVE-2026-0300Palo Alto Networks PAN-OS User-ID Portal9.8Yes (6 May)YesPatch immediately; FCEB deadline 27 May; restrict portal exposure
CVE-2026-3055Citrix NetScaler ADC / Gateway9.3YesYesPatch immediately; rotate session keys; review for known-exploit IOCs
CVE-2026-4368Citrix NetScaler ADC / Gateway8.8YesYesPatch; audit Gateway session logs
CVE-2026-4670Progress MOVEit Automation (< 2025.1.5 / 2025.0.9 / 2024.1.8)9.8PendingYes (low-complexity)Patch; audit freight-document MFT operator authentication
CVE-2026-22679Weaver E-Cology9.8YesPatch; restrict OA platform to internal networks
CVE-2026-31431Linux Kernel (resource transfer)7.8YesYesApply distro patches; prioritise terminal-operating-system Linux hosts

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.

TypeIndicatorFirst SeenConf.Notes
IPv4136[.]232[.]11[.]1020 Apr 2026HSSH brute-force pattern — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 6 active blacklists
IPv487[.]236[.]176[.]4502 May 2026MConstantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298) — IP Insights threat 100/critical, 4 active blacklists; observed in cross-tenant scanning
IPv4185[.]220[.]101[.]3003 May 2026MTor exit (for-privacy.net) — IP Insights threat 100/critical, 7 active blacklists
ASNAS200651OngoingHFlokiNET — 110/132 known IPs blacklisted; risk 100/critical; bulletproof-style hosting
PatternDDoS volumetric reflection against port portal / booking systemsOngoingMRussian state-aligned hacktivist tradecraft — community-shared indicator sets via MS-ISAC and CiSP

A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.

Threat ScenarioLikelihoodImpactComposite
Ransomware deployment against terminal-operating systems at hub portMHHIGH
Vendor-supply-chain compromise of fleet-management or TOS providerMHHIGH
Edge-appliance exploitation chain (Citrix / Ivanti / Palo Alto) leading to OT-adjacent compromiseHHCRITICAL
DDoS / disruptive activity from state-aligned hacktivist clusters against port / ferry portalsHMHIGH
AI-assisted phishing of customs and freight-forwarder inboxes leading to BEC and freight diversionMMMEDIUM

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.

Detect

Detection priorities for the next reporting cycle should emphasise edge-appliance exploitation telemetry (Citrix NetScaler, Ivanti EPMM, PAN-OS User-ID portal access correlated against published indicator-of-compromise sets), volumetric DDoS detection on port and ferry portal infrastructure, and freight / customs MFT operator authentication anomaly detection in light of the MOVEit Automation CVE-2026-4670 active-exploitation reporting.

Defend

Patch posture is the single most operationally consequential defensive action. The Ivanti EPMM, PAN-OS, NetScaler, MOVEit Automation, Weaver E-Cology and Linux kernel patch-wave should be circulated immediately to all maritime / logistics clients with edge-appliance exposure. Identity controls — phishing-resistant MFA, hardware-bound assurance for privileged accounts, and helpdesk procedure that does not permit credential-reset on voice authentication alone — are the highest-leverage second priority. ISO/IEC 27001 Annex A controls 5.18, 8.5 and 8.7 are the relevant references; for OT and bridge-systems estates the IMO 2021 cyber risk management resolution and BIMCO Cyber Security Onboard guidelines remain the authoritative regulatory references.

Disrupt

Disruption priorities are concentrated in three areas. First, indicator sharing within the Maritime Transportation System ISAC and CiSP, particularly the Vodafone PT and Reliance Jio source-IP patterns observed in the SSH brute-force telemetry. Second, takedown coordination on phishing infrastructure attributable to AS200651 (FlokiNET). Third, tabletop exercise activity covering the helpdesk social-engineering scenario at port-operations and freight-forwarder scope.

10. Forward outlook

It is highly likely that the AI-driven patch-wave dynamic will continue to dominate the operational picture for the next reporting cycle, with at least one further major edge-appliance or identity-provider CVE expected to enter active exploitation within the 7–14 day horizon. Maritime estates' historical patch latency makes them disproportionately exposed.

Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 against a UK port operator or shipping line; identification of a new ransomware affiliate cluster with maritime-specific victimology; or a material increase in DDoS activity against UK-flagged port portals from state-aligned hacktivist clusters.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.

SourceReliabilityInfo.Credibility
ACompletely reliable1Confirmed by other sources
BUsually reliable2Probably true
CFairly reliable3Possibly true
DNot usually reliable4Doubtful
EUnreliable5Improbable
FReliability cannot be judged6Truth cannot be judged

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.

Source / TitlePublisherAdmiralty
1NCSC – Preparing for a vulnerability patch wave (4 May 2026 blog)NCSCA2
2NCSC Annual Review 2025 – ransomware and nationally significant incidentsNCSCA1
3UK Cyber Security Breaches Survey 2025/2026 (DSIT)GOV.UKA1
4CISA Known Exploited Vulnerabilities Catalogue (rolling)CISAA1
5CISA Alert – Ivanti EPMM CVE-2026-6973 added to KEV (1 May 2026)CISAA1
6CISA Alert – Palo Alto PAN-OS CVE-2026-0300 added to KEV (6 May 2026)CISAA1
7Breachsense – April 2026 Ransomware Report (772 victims, 70 groups)BreachsenseB2
8Ransomware.live – sector and group leak-site indexRansomware.liveB2
9IP Insights – IP reputation and blocklist enrichment serviceUK Cyber DefenceA1
11Industrial Cyber – Maritime cyber incidents jump 103%, CYTUR warns smart ships under fireIndustrial CyberB2
12Quorum Cyber – Maritime Organisation Suffers Ransomware Attack (~1,000 vessels)Quorum CyberB2
13Recorded Future – Ransomware attack on maritime software impacts 1,000 shipsRecorded FutureA2
14Ransomware.live – Transportation/Logistics activity indexRansomware.liveB2
15TXOne Networks – Future Cybersecurity Threats in PortsTXOneC2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.