Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…
- Reference: TI-2026-0508-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 4–8 May 2026
- Issued: 8 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents — and by the consolidation of ransomware activity against terminal-operating systems at major hub ports. The operationally most-significant single development inside the reporting window is NCSC's 4 May 2026 blog on the AI-accelerated patch wave, which is materially relevant to a vertical with an established legacy of long-life OT estates and slow patch cadences.
The Q1 2026 Transportation/Logistics victim count on ransomware.live continues to track at the elevated post-2024 baseline, with TheGentlemen and DragonForce both visible in the maritime-aligned subset.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware against terminal-operating systems and shore-side ERP / freight-management platforms will remain the principal material-risk scenario for the vertical, with Qilin, TheGentlemen and DragonForce the most operationally-relevant affiliates over the next reporting cycle. (HIGH confidence)
- It is likely that the convergence of politically-motivated hacktivism with ransomware-as-a-service infrastructure will continue, with hub ports in the United Kingdom, North-West Europe and East Asia the highest-likelihood targets for disruptive activity. (MEDIUM-HIGH confidence)
- It is likely that smart-ship and bridge-systems exposure will become the dominant emerging attack surface over the 6–12 month horizon as fleet-wide IT/OT convergence continues. The 103 per cent year-on-year incident increase reported by CYTUR is the leading indicator. (MEDIUM-HIGH confidence)
- There is a realistic possibility that AI-accelerated vulnerability discovery — flagged by NCSC on 4 May 2026 — will produce at least one nationally-significant maritime exploitation event before the end of Q3 2026. The vertical's combination of legacy patch cadence and high public-facing attack surface makes it disproportionately exposed. (MEDIUM confidence)
- It is likely that supply-chain compromises of maritime software vendors — the pattern that compromised approximately one thousand shipping vessels in the recent ransomware attack on a maritime-software provider — will continue to be the highest-leverage scaling vector for adversaries. (MEDIUM-HIGH confidence)
2. Sector threat landscape
Maritime cyber incidents jumped 103 per cent in 2025 according to the latest CYTUR reporting, with DDoS, ransomware and malware infections remaining the dominant categories. Smart-ship and OT exposure is now an explicit structural concern across the vertical, and the Maritime Transportation System ISAC continues to be the highest-value sector source for non-public indicator and incident sharing.
The April 2026 leak-site picture (Breachsense / ransomware.live) is consistent with the picture published last cycle: 772 total victims claimed across 70 groups, with TheGentlemen now in second place at 82 victims (displacing Akira) and DragonForce in third with 63. The maritime / transportation / logistics subset of these victims is small but growing in both absolute and relative terms; the principal operational-impact scenario remains terminal-operating-system encryption rather than data-extortion against shipping carriers.
Vulnerability exposure at the network edge is the dominant gating factor for the vertical. The Citrix NetScaler ADC / Gateway CVEs from late April, the Ivanti EPMM CVE-2026-6973 (KEV-listed 1 May, FCEB deadline 10 May) and the Palo Alto PAN-OS User-ID portal CVE-2026-0300 (KEV-listed 6 May, FCEB deadline 27 May) collectively define a patch-wave that maritime operators with legacy port and terminal estates are particularly poorly placed to absorb at speed. The MOVEit Automation CVE-2026-4670 active-exploitation reporting matters specifically for any maritime client running automated freight-document or customs-document file transfer.
Geopolitical pressure continues to shape the threat picture. Russian state-aligned hacktivist clusters remain active against UK and NATO-aligned maritime targets; the recent ScarCruft (DPRK-aligned) gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the wider pattern of state-aligned actors using third-party software supply chains as a delivery vector — a pattern of acute concern in maritime, where vessel-management and terminal-operating-system software are tightly concentrated across a small number of vendors.
The IP Insights service currently lists FlokiNET (AS200651) at 110 of 132 known IPs blacklisted with risk 100/critical, and the Tor exit infrastructure (for-privacy.net example 185.220.101.30, 7 active blacklists) continues to surface in cross-tenant scanning telemetry.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Healthcare, financial services, manufacturing, transportation, professional services
- Geographic Focus: Global; sustained UK and EU activity
- Signature TTPs: Initial access via stolen / brute-forced credentials and exposed RDP / VPN; abuse of legitimate remote-management tooling for persistence; double extortion with fast time-to-encrypt
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptor variants; AnyDesk, RustDesk and ScreenConnect for hands-on-keyboard
- Recent Activity: 103 leak-site postings in April 2026 — fourth consecutive month leading the global leak-site rankings; transportation / logistics victims continue to be a non-trivial subset
- Assessed Threat to Vertical: HIGH — sustained operational tempo, mature TTPs, vertical-aligned victimology
- Analytic Confidence: HIGH
TheGentlemen
- Aliases: —
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware
- Sector Targeting: Manufacturing, transportation, logistics, professional services
- Geographic Focus: Global; growing UK and EU activity
- Signature TTPs: Edge-appliance exploitation; stolen-credential initial access; rapid lateral movement; double-extortion
- Tooling / Malware Families: Custom encryptor; LOLBins; abuse of native admin tooling
- Recent Activity: 82 leak-site postings in April 2026 — second-place global ranking; visible in maritime / logistics victim subset
- Assessed Threat to Vertical: HIGH — rising tempo and confirmed sector victimology
- Analytic Confidence: MEDIUM-HIGH
DragonForce
- Aliases: —
- Suspected Origin: Russophone (operator); Western affiliate cluster (Scattered Spider)
- Suspected Sponsor: Organised criminal — RaaS with white-label affiliate model
- Primary Motivation: Financial — ransomware and extortion
- Sector Targeting: Retail, hospitality, financial services, transportation, logistics
- Geographic Focus: Global; high-tempo UK operations
- Signature TTPs: White-label ransomware payload deployed by a range of affiliates; extensive use of native admin tooling and identity-provider compromise
- Tooling / Malware Families: DragonForce ransomware payload; commercial RMM tooling
- Recent Activity: 63 leak-site postings in April 2026 — third-place ranking; payload of choice in the M&S / Co-op campaign and observed against transportation targets
- Assessed Threat to Vertical: MEDIUM-HIGH — affiliate-cluster diversity makes vertical targeting opportunistic but consistently present
- Analytic Confidence: MEDIUM-HIGH
Russian state-aligned hacktivist clusters
- Aliases: NoName057(16), Killnet successors, various
- Suspected Origin: Russia-aligned
- Suspected Sponsor: State-aligned hacktivist; mixed with criminal infrastructure
- Primary Motivation: Disruption — political signalling
- Sector Targeting: Government, financial services, transportation, logistics, energy
- Geographic Focus: UK, EU, NATO-aligned
- Signature TTPs: DDoS against public-facing portals and booking systems; web-defacement; opportunistic compromise
- Tooling / Malware Families: Open-source DDoS tooling; commodity loaders
- Recent Activity: Sustained DDoS activity against UK and EU port and ferry portal infrastructure during the reporting period
- Assessed Threat to Vertical: MEDIUM — disruptive but sub-ransomware in operational impact
- Analytic Confidence: MEDIUM
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1133 | External Remote Services | Citrix NetScaler, Ivanti EPMM and Palo Alto PAN-OS additions to KEV expose maritime edge appliances; legacy OT estates particularly slow to patch. | H |
| Initial Access | T1190 | Exploit Public-Facing Application | MOVEit Automation CVE-2026-4670 and Weaver E-Cology CVE-2026-22679 add unauthenticated RCE surfaces to maritime trust platforms. | H |
| Initial Access | T1199 | Trusted Relationship | Vendor-supply-chain compromise of vessel-management and TOS providers — pattern reinforced by recent maritime-software ransomware impacting ~1,000 vessels. | M |
| Discovery | T1046 | Network Service Scanning | Sustained internet-wide scanning of maritime remote-access surfaces; AS211298 (Constantine Cybersecurity) measurement and AS200651 (FlokiNET) malicious indistinguishable on volumetric metrics alone — disposition relies on intent and content. | M |
| Impact | T1486 | Data Encrypted for Impact | Qilin, TheGentlemen, DragonForce affiliates continue to deploy encryptors against transportation / logistics targets globally. | H |
| Impact | T1499 | Endpoint Denial of Service | Russian state-aligned hacktivist DDoS against UK / EU port and ferry portal infrastructure. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| May 2026 | Multiple maritime / logistics leak-site listings (global) | Qilin, TheGentlemen, DragonForce | Maritime / transportation subset of the 772 April leak-site victims; consistent with Q1 2026 baseline | Ransomware.live; Breachsense |
| May 2026 | Vulnerability patch wave (sector-wide) | Multiple | NCSC 4 May 2026 blog warns AI-accelerated vulnerability discovery is shrinking time-to-weaponisation; Ivanti EPMM, PAN-OS User-ID and Linux kernel CVE additions to CISA KEV directly relevant to maritime estates | NCSC; CISA |
| Recent | Maritime-software vendor — ransomware impacting ~1,000 vessels (carry-forward) | Unattributed (RaaS-aligned) | Demonstrative of the vendor-supply-chain scaling vector; remains the operational reference case for the vertical | Recorded Future / Quorum Cyber |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline 10 May; rotate admin sessions |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch immediately; rotate session keys; review for known-exploit IOCs |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation (< 2025.1.5 / 2025.0.9 / 2024.1.8) | 9.8 | Pending | Yes (low-complexity) | Patch; audit freight-document MFT operator authentication |
| CVE-2026-22679 | Weaver E-Cology | 9.8 | — | Yes | Patch; restrict OA platform to internal networks |
| CVE-2026-31431 | Linux Kernel (resource transfer) | 7.8 | Yes | Yes | Apply distro patches; prioritise terminal-operating-system Linux hosts |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force pattern — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 6 active blacklists |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298) — IP Insights threat 100/critical, 4 active blacklists; observed in cross-tenant scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical, 7 active blacklists |
| ASN | AS200651 | Ongoing | H | FlokiNET — 110/132 known IPs blacklisted; risk 100/critical; bulletproof-style hosting |
| Pattern | DDoS volumetric reflection against port portal / booking systems | Ongoing | M | Russian state-aligned hacktivist tradecraft — community-shared indicator sets via MS-ISAC and CiSP |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Ransomware deployment against terminal-operating systems at hub port | M | H | HIGH |
| Vendor-supply-chain compromise of fleet-management or TOS provider | M | H | HIGH |
| Edge-appliance exploitation chain (Citrix / Ivanti / Palo Alto) leading to OT-adjacent compromise | H | H | CRITICAL |
| DDoS / disruptive activity from state-aligned hacktivist clusters against port / ferry portals | H | M | HIGH |
| AI-assisted phishing of customs and freight-forwarder inboxes leading to BEC and freight diversion | M | M | MEDIUM |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should emphasise edge-appliance exploitation telemetry (Citrix NetScaler, Ivanti EPMM, PAN-OS User-ID portal access correlated against published indicator-of-compromise sets), volumetric DDoS detection on port and ferry portal infrastructure, and freight / customs MFT operator authentication anomaly detection in light of the MOVEit Automation CVE-2026-4670 active-exploitation reporting.
Defend
Patch posture is the single most operationally consequential defensive action. The Ivanti EPMM, PAN-OS, NetScaler, MOVEit Automation, Weaver E-Cology and Linux kernel patch-wave should be circulated immediately to all maritime / logistics clients with edge-appliance exposure. Identity controls — phishing-resistant MFA, hardware-bound assurance for privileged accounts, and helpdesk procedure that does not permit credential-reset on voice authentication alone — are the highest-leverage second priority. ISO/IEC 27001 Annex A controls 5.18, 8.5 and 8.7 are the relevant references; for OT and bridge-systems estates the IMO 2021 cyber risk management resolution and BIMCO Cyber Security Onboard guidelines remain the authoritative regulatory references.
Disrupt
Disruption priorities are concentrated in three areas. First, indicator sharing within the Maritime Transportation System ISAC and CiSP, particularly the Vodafone PT and Reliance Jio source-IP patterns observed in the SSH brute-force telemetry. Second, takedown coordination on phishing infrastructure attributable to AS200651 (FlokiNET). Third, tabletop exercise activity covering the helpdesk social-engineering scenario at port-operations and freight-forwarder scope.
10. Forward outlook
It is highly likely that the AI-driven patch-wave dynamic will continue to dominate the operational picture for the next reporting cycle, with at least one further major edge-appliance or identity-provider CVE expected to enter active exploitation within the 7–14 day horizon. Maritime estates' historical patch latency makes them disproportionately exposed.
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-6973 against a UK port operator or shipping line; identification of a new ransomware affiliate cluster with maritime-specific victimology; or a material increase in DDoS activity against UK-flagged port portals from state-aligned hacktivist clusters.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Preparing for a vulnerability patch wave (4 May 2026 blog) | NCSC | A2 |
| 2 | NCSC Annual Review 2025 – ransomware and nationally significant incidents | NCSC | A1 |
| 3 | UK Cyber Security Breaches Survey 2025/2026 (DSIT) | GOV.UK | A1 |
| 4 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 5 | CISA Alert – Ivanti EPMM CVE-2026-6973 added to KEV (1 May 2026) | CISA | A1 |
| 6 | CISA Alert – Palo Alto PAN-OS CVE-2026-0300 added to KEV (6 May 2026) | CISA | A1 |
| 7 | Breachsense – April 2026 Ransomware Report (772 victims, 70 groups) | Breachsense | B2 |
| 8 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 9 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
| 11 | Industrial Cyber – Maritime cyber incidents jump 103%, CYTUR warns smart ships under fire | Industrial Cyber | B2 |
| 12 | Quorum Cyber – Maritime Organisation Suffers Ransomware Attack (~1,000 vessels) | Quorum Cyber | B2 |
| 13 | Recorded Future – Ransomware attack on maritime software impacts 1,000 ships | Recorded Future | A2 |
| 14 | Ransomware.live – Transportation/Logistics activity index | Ransomware.live | B2 |
| 15 | TXOne Networks – Future Cybersecurity Threats in Ports | TXOne | C2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
Maritime and logistics threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by continued growth in maritime cyber incidents (CYTUR's 103% YoY increase indicator carried forward into Q2 2026), the West Pharmaceutical Services ransomware event affecting shipping and manufacturing logistics, and the persistent operational risk to AIS…
Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…