Maritime and logistics threat intelligence report — 16–22 May 2026
The reporting cycle has been shaped by continued growth in maritime cyber incidents (CYTUR's 103% YoY increase indicator carried forward into Q2 2026), the West Pharmaceutical Services ransomware event affecting shipping and manufacturing logistics, and the persistent operational risk to AIS…
- Reference: TI-2026-0522-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 16–22 May 2026
- Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report assesses the threat landscape affecting the Maritime & Logistics vertical for the period 16 May 2026 to 22 May 2026. The reporting cycle has been shaped by continued growth in maritime cyber incidents (CYTUR's 103% YoY increase indicator carried forward into Q2 2026), the West Pharmaceutical Services ransomware event affecting shipping and manufacturing logistics, and the persistent operational risk to AIS, GPS and port cargo-handling systems from politically-motivated hacktivism partnered with criminal RaaS infrastructure.
Key Judgements
The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that maritime cyber incident frequency will sustain the 100%+ YoY growth trajectory through 2026, driven by continued digitisation of port and vessel systems and the operational maturity of cartel-linked RaaS operators against logistics targets. (HIGH confidence)
- It is likely that at least one major European port or container-terminal operator will publicly disclose a disruptive cyber incident before the end of Q3 2026. (MEDIUM confidence)
- It is likely that hacktivist groups will continue to exploit RaaS infrastructure on a rented basis to attack ports and logistics platforms linked to geopolitical adversaries; this hybrid model is now a recurring feature of the operational picture. (MEDIUM confidence)
- There is a realistic possibility that AIS / GPS spoofing incidents observed in 2025 against vessel transit through high-tension waterways will be repeated against UK and EU-flagged vessels during the reporting forward outlook. (MEDIUM confidence)
- It is highly likely that supply-chain effects from a logistics-sector cyber incident will exceed the originating loss by an order of magnitude across the dependent retail, manufacturing and FMCG clients downstream. (HIGH confidence)
2. Sector threat landscape
Maritime and logistics cyber incident counts have continued the trajectory set in 2025, with industry reporting (SAFETY4SEA, CYTUR, Smart Maritime Network) showing roughly a doubling of incident volumes year on year. DDoS, ransomware and malware infections account for the majority of the activity; AIS and GPS interference, while a smaller portion of the volume, carries disproportionate safety-of-navigation and insurance-claim implications. Everstream Analytics' 2026 logistics outlook flags continued acceleration through the year.
Operationally, the consequential dynamic is the cartel-linked RaaS pivot into the port and logistics target set. DragonForce, Qilin and TheGentlemen affiliates have been opportunistically targeting cargo-handling systems and freight-management platforms in tandem with hacktivist groups that rent RaaS infrastructure on a project basis. This blurs the attribution boundary and complicates the operational response — a politically-motivated incident may carry criminal-cartel tooling that is identical to a pure-financial event.
The West Pharmaceutical Services ransomware event during the reporting period sits at the FS / logistics / manufacturing intersection: shipping, manufacturing and shared-service functions were all disrupted simultaneously, illustrating that the operational impact of a logistics-touching event is rarely confined to one sector. UK shippers and freight forwarders with US supplier dependencies should treat this as a relevant case in their downstream risk modelling.
From a UK-policy perspective, NCSC-UK's Middle East cyber posture guidance continues to be live for any UK-flagged operator transiting affected waterways or with regional port calls; the long-standing Russian state-aligned hacktivist posture against UK firms with sanctions-regime exposure also remains a credible source of disruption-grade DDoS against shipping-agency and port-community websites. The Maritime Transportation System ISAC is the highest-value sector-specific source for UK and US-aligned maritime entities and should be the default subscription for any client in this space.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.
| THREAT ACTOR PROFILE — Qilin (logistics affiliate sub-cluster) | |
|---|---|
| Aliases | Agenda, Qilin.B |
| Suspected Origin | Russia |
| Suspected Sponsor | Criminal (RaaS) |
| Primary Motivation | Financial — extortion / data theft |
| Sector Focus | Logistics, manufacturing, port operations, freight forwarding |
| Tooling | Qilin.B encryptor (ESXi-aware), SystemBC, AnyDesk, Cobalt Strike, rclone |
| TTP Highlights | IAB-purchased VPN credentials into logistics ERP estates; rapid ESXi-tier encryption; double-extortion with logistics-pricing pressure |
| Reporting Cycle Activity | Continued leak-site cadence; logistics victims appearing alongside the FS / professional-services majority |
| Confidence | HIGH |
| Admiralty | B2 |
| Reference | Refs 1, 2 |
| THREAT ACTOR PROFILE — DragonForce / Scattered Spider affiliate cluster | |
|---|---|
| Aliases | UNC3944, Octo Tempest |
| Suspected Origin | English-speaking criminal community |
| Suspected Sponsor | Criminal (cartel) |
| Primary Motivation | Financial extortion |
| Sector Focus | Retail, hospitality, logistics-adjacent outsourcing |
| Tooling | Voice-phishing, MFA fatigue, AnyDesk / ScreenConnect, partner ransomware payload |
| TTP Highlights | Targeting of outsourced IT helpdesks; M&S / Co-op-style supply-chain entry; rapid pivot to virtualised hosting infrastructure |
| Reporting Cycle Activity | Continued voice-phishing campaign against UK BPO partners; no UK maritime victim publicly disclosed this week |
| Confidence | HIGH |
| Admiralty | A2 |
| Reference | Refs 3, 6 |
| THREAT ACTOR PROFILE — NoName057(16) and aligned hacktivist clusters | |
|---|---|
| Aliases | NoName057(16), pro-Russian hacktivist umbrella |
| Suspected Origin | Russia / aligned |
| Suspected Sponsor | Hacktivist (state-tolerated) |
| Primary Motivation | Ideological / disruption |
| Sector Focus | Government, transport, ports, logistics agencies |
| Tooling | DDoS-as-a-Service (DDoSia), defacement, leak-site disclosure |
| TTP Highlights | Coordinated DDoS against shipping-agency websites and port-community portals; high-volume but generally short-duration; reputational rather than data-loss impact |
| Reporting Cycle Activity | Continued Russian state-aligned DDoS posture against UK and EU transport infrastructure web presence |
| Confidence | MEDIUM |
| Admiralty | C2 |
| Reference | Ref 4 |
| THREAT ACTOR PROFILE — Unattributed AIS/GPS interference cluster | |
|---|---|
| Aliases | — |
| Suspected Origin | State or state-tolerated (mixed) |
| Suspected Sponsor | Mixed |
| Primary Motivation | Disruption / influence |
| Sector Focus | Maritime navigation, GPS-dependent industries |
| Tooling | GNSS jammers, AIS spoofing infrastructure |
| TTP Highlights | Selective interference with vessel-position reporting in contested waterways; periodic spoofing events identified via cross-referencing against satellite AIS and TerrestrialAIS feeds |
| Reporting Cycle Activity | No publicly-attributed incidents during the reporting period, but the operational risk remains live for vessels transiting affected high-tension waterways |
| Admiralty | C3 |
| Reference | Ref 5 |
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Conf. |
|---|---|---|---|---|
| Initial Access | T1078.004 | Valid Accounts: Cloud | IAB-purchased credentials into logistics ERP, freight-management and customer-portal estates. | HIGH |
| Initial Access | T1566.001 | Spear-phishing Attachment | Targeted phishing against shipping-agent, freight-forwarder and port-operations staff. | MEDIUM |
| Initial Access | T1190 | Exploit Public-Facing Application | Exploitation of edge appliances (Citrix NetScaler, Cisco SD-WAN) against maritime IT estates. | HIGH |
| Execution | T1059.001 | PowerShell | Encoded loaders for SystemBC / Cobalt Strike in Qilin-affiliate operations. | MEDIUM |
| Persistence | T1543.003 | Create or Modify System Process: Windows Service | New attacker-owned services for persistence inside cargo-management application servers. | MEDIUM |
| Lateral Movement | T1021.001 | Remote Services: RDP | Pivot into ESXi management of containerised cargo systems prior to encryption. | HIGH |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware ransomware against virtualised TOS (Terminal Operating System) and WMS estates. | HIGH |
| Impact | T1498 | Network Denial of Service | DDoS against shipping-agency websites and port-community portals. | MEDIUM |
5. Notable incidents and campaigns
| Date | Affected Org / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 18 May 2026 | West Pharmaceutical Services (logistics-adjacent) | Unattributed ransomware | Disruption to shipping, manufacturing and shared-service functions; multi-day operational impact. | Ref 7 |
| 18 May 2026 | Foxconn (NA operations) | Nitrogen ransomware | Claimed 8TB exfiltration; logistics-flow implications for downstream electronics supply chain. | Ref 7 |
| Throughout period | Multiple TheGentlemen leak-site victims | TheGentlemen RaaS | Logistics and freight-adjacent entities among the 424 named victims. | Ref 9 |
| Throughout period | UK and EU shipping-agency web presence | Pro-Russian hacktivist clusters | Continued low-grade DDoS posture; reputational rather than operational impact. | Ref 4 |
| Throughout period | Multiple Akira victims (logistics subset) | Akira RaaS | Logistics and freight included in the 30+ single-day leak posting on 20 May. | Ref 10 |
| Reporting period | Various AIS / GNSS interference events (continuing) | Unattributed | Selective AIS spoofing in contested waterways; no UK-flagged incident publicly confirmed. | Ref 5 |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.
| CVE ID | Affected Product | CVSS | KEV | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20182 | Cisco Catalyst SD-WAN | 10.0 | Yes | Active ITW | Patch immediately; review SSH key and NETCONF activity for indicators of UAT-8616 tradecraft. |
| CVE-2026-6973 | Ivanti EPMM | 7.2 | Yes | Active ITW | Patch; rotate pre-Feb-2026 admin credentials; assume compromise where unpatched since Jan. |
| CVE-2026-34926 | Trend Micro Apex One (on-prem) | 8.7 | Yes | Active ITW | Apply Trend Micro fix; review Apex One management console exposure. |
| CVE-2025-34291 | Langflow | 8.2 | Yes | Active ITW | Remove internet exposure of AI-workflow tooling; patch CORS / refresh-token config. |
| CVE-2026-3055 / CVE-2026-4368 | Citrix NetScaler ADC / Gateway | 9.3 / 8.6 | Yes | Active ITW | Apply Citrix-supplied builds and force-rotate session keys. |
| CVE-2026-41091 | Microsoft Defender — EoP | 7.8 | Yes | Confirmed exploitation | Apply May 2026 Patch Tuesday roll-up across the logistics Windows estate. |
| CVE-2026-31431 | Linux Kernel | 7.0 | Yes | Active ITW | Apply distribution-supplied kernel; relevant to Linux-hosted TOS / WMS estates. |
| Maritime-specific | NMEA / AIS / GNSS spoofing exposure | n/a | n/a | Operational risk | Adopt navigation backup procedures, multi-source position cross-check, IMO MSC.428(98) cyber-risk-management compliance. |
| OT-adjacent | Insecure remote-maintenance VPNs into TOS estates | varies | n/a | Recurring | Tighten remote-maintenance access — phishing-resistant MFA, segmented jump-host, time-bounded vendor access tokens. |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.
| Type | Indicator | First Seen | Conf. | Notes |
|---|---|---|---|---|
| IP | 185.243.78.42 | Reporting period | MEDIUM | Bamboozle Web Services FZ-LLC (Dubai); business hosting; egress-deny candidate for logistics estates with no UAE business need. |
| Tactic | Logistics ERP credential phish via fake supplier portal | Reporting period | MEDIUM | Common Qilin-affiliate IAB pattern; deploy URL-filter signatures for supplier-impersonation domains. |
| TTP | DDoS targeting shipping-agency websites | Reporting period | MEDIUM | Continued NoName057(16) / DDoSia botnet posture; preposition WAF rate-limit and DDoS-edge mitigation ahead of declared targeting windows. |
| TTP | GNSS jamming in transit waterways | Ongoing | MEDIUM | Operational rather than IT-side indicator; coordinate with vessel master and shore-side ops to capture and report. |
| Hash (SHA-256) | Qilin.B encryptor variant (redacted) | Reporting period | MEDIUM | Deploy YARA-based detection alongside existing Qilin family ruleset. |
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.
| Threat Scenario | Likelihood | Impact | Composite |
|---|---|---|---|
| Ransomware compromise of TOS / WMS via virtualised hypervisor | HIGH | HIGH | CRITICAL |
| Cargo-management ERP credential theft and double extortion | MEDIUM-HIGH | HIGH | HIGH |
| Hacktivist DDoS against shipping-agency or port-community web presence | HIGH | MEDIUM | HIGH |
| AIS / GPS interference event affecting UK-flagged vessel | MEDIUM | MEDIUM | MEDIUM |
| Supplier-side compromise propagating into logistics ERP | MEDIUM | HIGH | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.
Detect
- Hypervisor / ESXi management-plane logging: alert on any new SSH session to an ESXi host originating outside the documented admin source-range and on any vSphere admin login from a previously-unseen user-agent.
- Logistics ERP / TOS authentication telemetry: instrument failed-then-success patterns, geo-anomalies and impossible-travel for any admin or operator-class user.
- Edge-appliance telemetry: alert on Cisco SD-WAN NETCONF writes, SSH key additions and Citrix NetScaler authentication anomalies in line with NCSC and CISA joint guidance.
- Maritime-specific signals: AIS / GNSS anomaly cross-check against satellite AIS feed for any vessel in active ops; log and triage gaps and position-jumps.
Defend
- Patch Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One and Citrix NetScaler before the next reporting cycle; force-rotate any admin credentials in use prior to the patch window.
- Tighten remote-maintenance vendor access into TOS / WMS estates: phishing-resistant MFA, segmented jump-host with session recording, time-bounded vendor access tokens, and removal of any always-on RDP / VPN tunnels.
- Segment cargo-handling OT from corporate IT at the network layer; enforce a unidirectional data diode for OT-to-IT telemetry where feasible.
- Validate the disaster-recovery position for TOS / WMS estates against an explicit ESXi-aware ransomware scenario; verify offline / immutable backups within the next reporting cycle.
Disrupt
- Subscribe to MTS-ISAC and contribute observed indicators back through the sharing channel.
- Push indicators in Section 7 into edge / WAF / EDR via the ipinsights.io TAXII 2.1 feed.
- Tabletop a coordinated hacktivist-DDoS plus simultaneous ransomware-staging scenario before the next reporting cycle; the cartel / hacktivist hybrid model is the right operational test case for 2026.
10. Forward outlook
It is highly likely that maritime cyber incident volumes will continue to grow through 2026, with at least one major European port disruption likely before end of Q3. (HIGH confidence)
It is likely that hacktivist-and-cartel hybrid operations will be the dominant tradecraft model against the vertical for the rest of the year. (MEDIUM confidence)
Trigger conditions warranting forecast revision: a publicly-disclosed ransomware event at a UK port; an AIS/GPS-spoofing incident affecting a UK-flagged vessel under SOLAS regulation; or a major TOS / WMS vendor publicly disclosing exploitation of one of its products.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.
| Source | Reliability | Information | Credibility |
|---|---|---|---|
| A — Completely reliable | Demonstrated repeated reliability | 1 — Confirmed | Corroborated by independent sources |
| B — Usually reliable | Reliable on most occasions | 2 — Probably true | Logical, consistent, partially corroborated |
| C — Fairly reliable | Sometimes reliable | 3 — Possibly true | Reasonably logical, agrees with some information |
| D — Not usually reliable | Limited prior accuracy | 4 — Doubtful | Possible but lacks logic or corroboration |
| E — Unreliable | History of inaccuracy | 5 — Improbable | Contradicts other reporting |
| F — Cannot be judged | No basis for evaluation | 6 — Cannot be judged | Cannot be assessed |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | Q1 2026 Ransomware Retrospective | Check Point Research | B2 |
| 2 | Ransomware sector reconsolidating (logistics victims) | Industrial Cyber | B2 |
| 3 | DragonForce / Scattered Spider alliance briefings | Sophos X-Ops; Acronis TRU; BlackFog | A2 |
| 4 | Russian state-aligned hacktivist posture against UK transport | NCSC-UK; ENISA | A2 |
| 5 | Maritime cyber incidents jump 103% | SAFETY4SEA; CYTUR; Smart Maritime Network | B2 |
| 6 | Scattered Spider expanding web of ransomware attacks | BlackFog; SecurityBrief UK | B2 |
| 7 | Cyberattacks on Logistics set to double in 2026 | Supply Chain 24/7; Everstream Analytics | B2 |
| 8 | Hellenic Shipping News & CSIS — Port Digitisation Systemic Risk | CSIS; HSN | B2 |
| 9 | TheGentlemen leak-site victim cadence | The Hacker News; ransomware.live | B2 |
| 10 | Akira ransomware leak cadence | SecurityWeek; The Record | A2 |
| 11 | CISA / NCSC-UK joint advisory on CVE-2026-20182 | CISA; NCSC-UK; NSA; ACSC; CCCS | A1 |
| 12 | Ivanti May 2026 EPMM Security Update | Ivanti; Help Net Security; SocRadar | A2 |
| 13 | Maritime Cyber Risk 2026 — operational risk framing | Channel 16 / Dryad Global; TXOne Networks | B2 |
| 14 | ipinsights.io enrichment & blocklist data | ipinsights.io | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…
Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…