Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
- Reference: TI-2026-0517-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 11–17 May 2026
- Issued: 17 May 2026 · Lead analyst: Peter Bassill · Analysts: EmilyAI; Peter Bassill
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms. The week's standout operational item is the addition of CVE-2026-20182 (Cisco Catalyst SD-WAN Controller authentication bypass) to the CISA KEV catalogue on 14 May, paired with CISA Emergency Directive 26-03 and its hunt-and-hardening supplemental direction — Cisco SD-WAN is a common WAN choice for multi-site port operators, freight forwarders and logistics back-office estates. Maritime cyber incidents increased 103 percent year-on-year per CYTUR / SAFETY4SEA reporting carried into the reporting period; DDoS, ransomware and malware infections continue to drive the majority of reported attacks. Container-handling and TOS-dependent terminal operations remain the highest-impact attack surface, with December 2025's major-terminal-operator ransomware incident still operating as the operational reference case for the vertical.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware against TOS (terminal operating system) and vessel-management platforms — Qilin, TheGentlemen, DragonForce affiliates — will continue to drive the majority of material risk to the vertical over the next reporting cycle. Q1 2026 leak-site volume (2,122 victims, 91 active DLS, Check Point Research) confirms continued consolidation rather than easing of tempo (HIGH confidence).
- It is likely that CISA Emergency Directive 26-03 (Cisco Catalyst SD-WAN, CVE-2026-20182) will produce at least one publicly-disclosed multi-site port or logistics operator exploitation event within the next two reporting cycles. Cisco SD-WAN is widely deployed in multi-terminal and 3PL multi-warehouse estates (HIGH confidence).
- It is likely that vendor-supply-chain compromise of TOS, vessel-management and freight-management software will produce at least one further nationally-significant maritime / logistics incident within the cycle. The carry-forward ~1,000-vessel maritime-software vendor ransomware incident remains the structural reference case for the vertical (HIGH confidence).
- There is a realistic possibility of disruption activity against UK / EU port portal infrastructure attributable to Russian state-aligned hacktivism, particularly tied to high-profile geopolitical developments. NCSC's Middle East cyber-posture guidance remains live and applies to UK-flagged shipping operating in regional waters (MEDIUM confidence).
- It is highly likely that mass internet scanning of maritime remote-access surfaces will continue at current tempo (AS211298 Constantine Cybersecurity / INTERNET-MEASUREMENT prominent in current IP Insights enrichment), driving pre-attack reconnaissance for both opportunistic and targeted operators (HIGH confidence).
2. Sector threat landscape
Maritime and logistics organisations continued to absorb a disproportionate share of opportunistic and supply-chain cyber activity directed at the global shipping network. Reporting during the period carries forward the headline statistic that maritime cyber incidents rose 103 percent year-on-year, with DDoS, ransomware and malware infections collectively accounting for the majority of attacks (CYTUR / SAFETY4SEA, refreshed reporting). Large-scale hub-port ransomware incidents at Rotterdam-scale and Los Angeles / Long Beach-scale terminals remain the standing structural reference cases for the vertical, with the December 2025 major-terminal-operator incident continuing to drive sector tabletop exercise content.
Edge-appliance exposure for the vertical centres this week on Cisco Catalyst SD-WAN (CVE-2026-20182, KEV 14 May, CISA ED 26-03). Multi-terminal port operators and 3PL multi-warehouse estates frequently rely on Cisco SD-WAN to connect back-office to terminal-operations LANs; an authentication-bypass on the controller plane is therefore directly load-bearing on the vertical's WAN trust model. The Ivanti EPMM CVE-2026-6973 FCEB deadline of 10 May has passed and active exploitation continues globally; maritime estates running EPMM for mobile and ruggedised-device fleet management are an exposure point. Citrix NetScaler ADC / Gateway CVEs (CVE-2026-3055 / CVE-2026-4368), Palo Alto PAN-OS User-ID Portal CVE-2026-0300 and Progress MOVEit Automation CVE-2026-4670 remain on the same active-exploitation footing — many port-community-system and customs-document-exchange systems route through MOVEit-class managed file-transfer infrastructure.
Geopolitical pressure continues to shape the threat picture. Russian state-aligned hacktivist clusters remain active against UK and NATO-aligned maritime targets; the recent ScarCruft (DPRK-aligned) gaming-platform supply-chain compromise reported by ESET on 5 May 2026 is illustrative of the wider pattern of state-aligned actors using third-party software supply chains as a delivery vector — a pattern of acute concern in maritime, where vessel-management and terminal-operating-system software are tightly concentrated across a small number of vendors.
The IP Insights service currently lists FlokiNET (AS200651) at 110 of 132 known IPs blacklisted with risk 100/critical, and the Tor exit infrastructure (for-privacy.net example 185.220.101.30, 7 active blacklists) continues to surface in cross-tenant scanning telemetry.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period.
Threat Actor Profile — Qilin
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware and data extortion
- Sector Targeting: Transportation, logistics, manufacturing, healthcare, professional services
- Geographic Focus: Global; sustained UK and EU activity
- Signature TTPs: Initial access via stolen / brute-forced credentials and exposed RDP / VPN and edge-appliance exploitation; abuse of legitimate remote-management tooling; double-extortion model
- Tooling / Malware Families: Qilin / Agenda Rust- and Go-based encryptor variants; AnyDesk, RustDesk and ScreenConnect
- Recent Activity: 338 leak-site postings in Q1 2026 (Check Point Research) — third consecutive quarter as global leader; transportation / logistics victimology continues into May 2026
- Assessed Threat to Vertical: HIGH — sustained operational tempo, vertical-aligned victimology
- Analytic Confidence: HIGH
Threat Actor Profile — TheGentlemen
- Aliases: —
- Suspected Origin: Russophone
- Suspected Sponsor: Organised criminal — RaaS
- Primary Motivation: Financial — ransomware
- Sector Targeting: Manufacturing, logistics, transportation, professional services
- Geographic Focus: Global; growing UK and EU activity
- Signature TTPs: Initial access via stolen credentials and edge-appliance exploitation; rapid lateral movement; double-extortion model
- Tooling / Malware Families: Custom encryptor; commodity LOLBins
- Recent Activity: Top-five Q1 2026 ranking (Check Point Research) — among the four operations responsible for 41 percent of all Q1 leak-site postings (with Qilin, Akira, LockBit)
- Assessed Threat to Vertical: HIGH — rising tempo and logistics-sector victimology
- Analytic Confidence: MEDIUM-HIGH
Threat Actor Profile — DragonForce affiliate cluster
- Aliases: Various Scattered-Spider-aligned affiliates
- Suspected Origin: Mixed (Western affiliates, Russophone tooling)
- Suspected Sponsor: Organised criminal — affiliate of multiple RaaS
- Primary Motivation: Financial — ransomware, data extortion
- Sector Targeting: Retail, logistics, financial services, hospitality
- Geographic Focus: Global; high-tempo UK and North American operations
- Signature TTPs: Helpdesk social engineering; MFA fatigue; identity-provider abuse; living-off-the-land
- Tooling / Malware Families: DragonForce ransomware payload; commercial RMM tooling
- Recent Activity: M&S / Co-op campaign (Category 2 cyber hurricane); replicable affiliate playbook against UK retail-logistics and BPO operations
- Assessed Threat to Vertical: HIGH — proven UK-victimology with social-engineering vector poorly mitigated in logistics estates
- Analytic Confidence: HIGH
Threat Actor Profile — Russian state-aligned hacktivist clusters (NoName057, KillNet successors)
- Aliases: Various
- Suspected Origin: Russophone
- Suspected Sponsor: State-aligned — non-state-controlled
- Primary Motivation: Disruptive — ideological
- Sector Targeting: Transport infrastructure, government, financial services
- Geographic Focus: Europe, UK, Ukraine, NATO allies
- Signature TTPs: DDoS against public-facing portals; defacement; data-leak claims
- Tooling / Malware Families: DDoSia and successor botnet-style tooling; commodity stresser services
- Recent Activity: Continued tempo against UK / EU transport portals tied to geopolitical news cycles
- Assessed Threat to Vertical: MEDIUM — disruption-oriented, low strategic depth
- Analytic Confidence: MEDIUM
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Cisco Catalyst SD-WAN CVE-2026-20182 (KEV 14 May, ED 26-03) and Ivanti EPMM CVE-2026-6973 (active exploitation, FCEB deadline passed) place authentication-bypass and pre-auth RCE on maritime / logistics edge surfaces. | H |
| Initial Access | T1133 | External Remote Services | Citrix NetScaler, Ivanti EPMM and Palo Alto PAN-OS additions to KEV expose maritime edge appliances; legacy OT estates particularly exposed. | H |
| Initial Access | T1199 | Trusted Relationship | Vendor-supply-chain compromise of vessel-management and TOS providers — pattern reinforced by recent maritime-software ransomware incident. | H |
| Discovery | T1046 | Network Service Scanning | Sustained internet-wide scanning of maritime remote-access surfaces; AS211298 (Constantine Cybersecurity) and AS200651 (FlokiNET) prominent — both currently scored 100/critical by IP Insights. | M |
| Impact | T1486 | Data Encrypted for Impact | Qilin, TheGentlemen, DragonForce affiliates continue to deploy encryptors against transportation / logistics targets globally; Q1 2026 leak-site total 2,122 victims (Check Point Research). | H |
| Impact | T1499 | Endpoint Denial of Service | Russian state-aligned hacktivist DDoS against UK / EU port and ferry portal infrastructure tied to news cycles. | M |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 14 May 2026 | Cisco Catalyst SD-WAN exploitation surface (sector-wide) | Multiple — CISA ED 26-03 | CVE-2026-20182 authentication-bypass added to KEV; ED 26-03 and supplemental hunt-and-hardening direction issued; multi-terminal port operators and 3PL multi-warehouse estates with Cisco SD-WAN immediately exposed | CISA; NCSC |
| May 2026 | Maritime / logistics leak-site listings (global) | Qilin, TheGentlemen, DragonForce | Maritime / transportation subset of Q1 2026 leak-site total (2,122 victims, 91 active DLS, Check Point Research); consistent with the 103 percent YoY incident growth in CYTUR / SAFETY4SEA reporting | Check Point Research; CYTUR / SAFETY4SEA |
| Carry-forward | Maritime-software vendor — ransomware impacting ~1,000 vessels | Unattributed (RaaS-aligned) | Demonstrative of the vendor-supply-chain scaling vector; remains the operational reference case for the vertical | Recorded Future / Quorum Cyber |
| Carry-forward | Major terminal-operator ransomware (Dec 2025) | Unattributed (RaaS-aligned) | Container-handling and TOS impact; reference case for vertical tabletop exercises | Vendor reporting; press |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller (authentication bypass) | 9.8 | Yes (14 May) | Yes | Patch immediately; align with CISA ED 26-03 / Supplemental Direction; hunt for compromise; FCEB hardening guidance applies |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) | 8.8 | Yes (1 May) | Yes | Patch immediately; FCEB deadline now passed (10 May); rotate admin sessions; review MDM admin auth logs |
| CVE-2026-0300 | Palo Alto Networks PAN-OS User-ID Portal | 9.8 | Yes (6 May) | Yes | Patch immediately; FCEB deadline 27 May; restrict portal exposure |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway | 9.3 | Yes | Yes | Patch; rotate session keys; hunt for indicators |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 8.8 | Yes | Yes | Patch; audit Gateway session logs |
| CVE-2026-4670 | Progress MOVEit Automation (< 2025.1.5 / 2025.0.9 / 2024.1.8) | 9.8 | Yes | Yes (low-complexity) | Patch; audit MFT operator and admin authentication |
| CVE-2026-8043 | Ivanti Xtraction (external control of file name, RCE) | 9.6 | — | Pending | Patch; restrict reporting console exposure |
| CVE-2026-44277 | Fortinet FortiAuthenticator (improper access control) | 9.1 | — | Pending | Patch; restrict management plane exposure |
| CVE-2026-26083 | Fortinet FortiSandbox (missing authorisation, RCE) | 9.1 | — | Pending | Patch; restrict sandbox API exposure |
| CVE-2026-34260 | SAP S/4HANA Enterprise Search for ABAP | 9.6 | — | Pending | Patch; restrict access to enterprise search endpoints |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the analyst's assessment of the strength of the association between the indicator and the named actor or campaign. The IP Insights enrichment service (https://ipinsights.io) provides the underlying threat-score and blocklist coverage.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IPv4 | 136[.]232[.]11[.]10 | 20 Apr 2026 | H | SSH brute-force pattern — Reliance Jio IN (AS55836); IP Insights threat 100/critical, 7 active blacklists; carry-forward IOC |
| IPv4 | 87[.]236[.]176[.]45 | 02 May 2026 | M | Constantine Cybersecurity Ltd / INTERNET-MEASUREMENT (AS211298) — IP Insights threat 100/critical; mass scanning |
| IPv4 | 185[.]220[.]101[.]30 | 03 May 2026 | M | Tor exit (for-privacy.net) — IP Insights threat 100/critical |
| ASN | AS200651 | Ongoing | H | FlokiNET — 112/134 known IPs blacklisted; risk 100/critical; risk breakdown low 19 / med 3 / high 31 / critical 81; bulletproof hosting |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Cisco Catalyst SD-WAN exploitation chain (CVE-2026-20182, ED 26-03) against multi-terminal / multi-warehouse estates | H | H | CRITICAL |
| Vendor-supply-chain compromise of TOS, vessel-management or freight-management platform leading to multi-customer impact | M | H | HIGH |
| Ransomware deployment against container-handling, TOS or vessel-management systems | H | H | CRITICAL |
| DDoS / disruptive activity from Russian state-aligned hacktivist clusters against UK / EU port portals | M | M | MEDIUM |
| BEC and freight-payment fraud targeting freight forwarders, carriers and customs brokers | H | M | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Detection priorities for the next reporting cycle should focus on four concurrent threads. First, Cisco Catalyst SD-WAN Controller telemetry: ensure vManage, vSmart and vBond control-plane authentication, configuration changes, and template-push events are being centrally ingested across all terminal sites and 3PL warehouses; apply the CISA ED 26-03 supplemental hunt hypotheses retrospectively across sixty days. Second, edge-appliance exploitation telemetry on Citrix NetScaler, Ivanti EPMM and Palo Alto PAN-OS — sustained admin-plane coverage from prior cycles. Third, TOS and vessel-management platform authentication, configuration and operator-action telemetry — particularly for any platform reachable from the customer-portal or partner-portal surface. Fourth, sustained internet-wide scanning of maritime remote-access surfaces from AS211298 (Constantine Cybersecurity / INTERNET-MEASUREMENT) and AS200651 (FlokiNET) — both currently scored 100/critical by IP Insights.
Defend
Patch posture is the single most operationally consequential defensive action for the next reporting cycle. The combination of CVE-2026-20182 (Cisco SD-WAN, ED 26-03), CVE-2026-6973 (Ivanti EPMM, FCEB deadline passed), CVE-2026-0300 (PAN-OS), CVE-2026-3055 / CVE-2026-4368 (NetScaler) and CVE-2026-4670 (MOVEit Automation) is the prioritised patching set. Treat all WAN-controller and identity-broker patches as out-of-cycle. Segment TOS, vessel-management and freight-management platforms from corporate networks and from customer-portal surfaces. For OT-adjacent equipment (terminal automation, crane PLCs, gate-pass kiosks) follow Dragos / Claroty Team82 / Nozomi Labs sector-specific guidance.
Disrupt
Disruption priorities for the next reporting cycle are concentrated in three areas. First, indicator sharing within the Maritime Transportation System ISAC and CiSP CNI Trust Group, using IP Insights enrichment to support prompt indicator submission. Second, takedown coordination on phishing infrastructure spoofing freight-forwarder, carrier and customs-broker brands — these are persistent BEC vectors. Third, vendor-supply-chain indicator exchange with MTS-ISAC peers around TOS, vessel-management and freight-management platform vulnerabilities and observed exploitation tradecraft.
10. Forward outlook
It is highly likely that ransomware against TOS, vessel-management and freight-management platforms will continue at current tempo. It is likely that CISA ED 26-03 (Cisco SD-WAN) will produce at least one publicly-disclosed multi-site port or logistics operator exploitation event within the next two reporting cycles. It is likely that supply-chain compromise of a maritime-software vendor — with cascading impact across vessels or terminals — will produce at least one nationally-significant incident within the cycle. There is a realistic possibility of disruption activity against UK / EU port portal infrastructure attributable to Russian state-aligned hacktivism, particularly during high-profile geopolitical developments.
Trigger conditions warranting forecast revision: confirmed exploitation of CVE-2026-20182 against a UK port or logistics operator (raises the vertical-risk to CRITICAL); identification of a new ransomware affiliate cluster with maritime-specific victimology (raises the operational tempo forecast); novel TOS or vessel-management platform CVE published with active exploitation evidence; coordinated DDoS campaign against EU / UK port portals attributable to a known hacktivist cluster.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC – Reports & Advisories (rolling) | NCSC | A1 |
| 2 | NCSC – Cisco Catalyst SD-WAN advisory and ED 26-03 alignment (May 2026) | NCSC / CISA | A1 |
| 3 | NCSC – Citrix NetScaler ADC / Gateway CVE-2026-3055 / CVE-2026-4368 | NCSC | A1 |
| 4 | NCSC – F5 BIG-IP Access Policy Manager unauthenticated RCE advisory | NCSC | A1 |
| 5 | NCSC – Middle East cyber posture review guidance | NCSC | A1 |
| 6 | CISA Known Exploited Vulnerabilities Catalogue (rolling) | CISA | A1 |
| 7 | CISA Alert – CVE-2026-20182 Cisco Catalyst SD-WAN Controller added to KEV (14 May 2026) | CISA | A1 |
| 8 | CISA Emergency Directive 26-03 – Mitigate Cisco SD-WAN Vulnerabilities | CISA | A1 |
| 9 | CISA Alert – Ivanti EPMM CVE-2026-6973 active exploitation | CISA | A1 |
| 10 | Check Point Research – State of Ransomware Q1 2026 | Check Point Research | B2 |
| 11 | Breachsense – April / Q1 2026 ransomware tracking | Breachsense | B2 |
| 12 | Ransomware.live – sector and group leak-site index | Ransomware.live | B2 |
| 13 | IP Insights – IP reputation and blocklist enrichment service | UK Cyber Defence | A1 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…
Maritime and logistics threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by continued growth in maritime cyber incidents (CYTUR's 103% YoY increase indicator carried forward into Q2 2026), the West Pharmaceutical Services ransomware event affecting shipping and manufacturing logistics, and the persistent operational risk to AIS…
Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…