SOC status:Duty analyst on shift

UK Cyber Defence
Threat briefing

Maritime and logistics threat intelligence report — 16–22 May 2026

The reporting cycle has been shaped by continued growth in maritime cyber incidents (CYTUR's 103% YoY increase indicator carried forward into Q2 2026), the West Pharmaceutical Services ransomware event affecting shipping and manufacturing logistics, and the persistent operational risk to AIS…

  • Reference: TI-2026-0522-002 (public edition)
  • Sector: Maritime and logistics
  • Reporting period: 16–22 May 2026
  • Issued: 22 May 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst

This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.

1. Executive summary

This report assesses the threat landscape affecting the Maritime & Logistics vertical for the period 16 May 2026 to 22 May 2026. The reporting cycle has been shaped by continued growth in maritime cyber incidents (CYTUR's 103% YoY increase indicator carried forward into Q2 2026), the West Pharmaceutical Services ransomware event affecting shipping and manufacturing logistics, and the persistent operational risk to AIS, GPS and port cargo-handling systems from politically-motivated hacktivism partnered with criminal RaaS infrastructure.

Key Judgements

The following key judgements represent the lead analyst's assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.

  • It is highly likely that maritime cyber incident frequency will sustain the 100%+ YoY growth trajectory through 2026, driven by continued digitisation of port and vessel systems and the operational maturity of cartel-linked RaaS operators against logistics targets. (HIGH confidence)
  • It is likely that at least one major European port or container-terminal operator will publicly disclose a disruptive cyber incident before the end of Q3 2026. (MEDIUM confidence)
  • It is likely that hacktivist groups will continue to exploit RaaS infrastructure on a rented basis to attack ports and logistics platforms linked to geopolitical adversaries; this hybrid model is now a recurring feature of the operational picture. (MEDIUM confidence)
  • There is a realistic possibility that AIS / GPS spoofing incidents observed in 2025 against vessel transit through high-tension waterways will be repeated against UK and EU-flagged vessels during the reporting forward outlook. (MEDIUM confidence)
  • It is highly likely that supply-chain effects from a logistics-sector cyber incident will exceed the originating loss by an order of magnitude across the dependent retail, manufacturing and FMCG clients downstream. (HIGH confidence)

2. Sector threat landscape

Maritime and logistics cyber incident counts have continued the trajectory set in 2025, with industry reporting (SAFETY4SEA, CYTUR, Smart Maritime Network) showing roughly a doubling of incident volumes year on year. DDoS, ransomware and malware infections account for the majority of the activity; AIS and GPS interference, while a smaller portion of the volume, carries disproportionate safety-of-navigation and insurance-claim implications. Everstream Analytics' 2026 logistics outlook flags continued acceleration through the year.

Operationally, the consequential dynamic is the cartel-linked RaaS pivot into the port and logistics target set. DragonForce, Qilin and TheGentlemen affiliates have been opportunistically targeting cargo-handling systems and freight-management platforms in tandem with hacktivist groups that rent RaaS infrastructure on a project basis. This blurs the attribution boundary and complicates the operational response — a politically-motivated incident may carry criminal-cartel tooling that is identical to a pure-financial event.

The West Pharmaceutical Services ransomware event during the reporting period sits at the FS / logistics / manufacturing intersection: shipping, manufacturing and shared-service functions were all disrupted simultaneously, illustrating that the operational impact of a logistics-touching event is rarely confined to one sector. UK shippers and freight forwarders with US supplier dependencies should treat this as a relevant case in their downstream risk modelling.

From a UK-policy perspective, NCSC-UK's Middle East cyber posture guidance continues to be live for any UK-flagged operator transiting affected waterways or with regional port calls; the long-standing Russian state-aligned hacktivist posture against UK firms with sanctions-regime exposure also remains a credible source of disruption-grade DDoS against shipping-agency and port-community websites. The Maritime Transportation System ISAC is the highest-value sector-specific source for UK and US-aligned maritime entities and should be the default subscription for any client in this space.

3. Key threat actors

The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. Profiles below are repeated for each actor; established actors with no fresh activity in the reporting period are referenced briefly in Section 2 without a full profile.

THREAT ACTOR PROFILE — Qilin (logistics affiliate sub-cluster)
AliasesAgenda, Qilin.B
Suspected OriginRussia
Suspected SponsorCriminal (RaaS)
Primary MotivationFinancial — extortion / data theft
Sector FocusLogistics, manufacturing, port operations, freight forwarding
ToolingQilin.B encryptor (ESXi-aware), SystemBC, AnyDesk, Cobalt Strike, rclone
TTP HighlightsIAB-purchased VPN credentials into logistics ERP estates; rapid ESXi-tier encryption; double-extortion with logistics-pricing pressure
Reporting Cycle ActivityContinued leak-site cadence; logistics victims appearing alongside the FS / professional-services majority
ConfidenceHIGH
AdmiraltyB2
ReferenceRefs 1, 2
THREAT ACTOR PROFILE — DragonForce / Scattered Spider affiliate cluster
AliasesUNC3944, Octo Tempest
Suspected OriginEnglish-speaking criminal community
Suspected SponsorCriminal (cartel)
Primary MotivationFinancial extortion
Sector FocusRetail, hospitality, logistics-adjacent outsourcing
ToolingVoice-phishing, MFA fatigue, AnyDesk / ScreenConnect, partner ransomware payload
TTP HighlightsTargeting of outsourced IT helpdesks; M&S / Co-op-style supply-chain entry; rapid pivot to virtualised hosting infrastructure
Reporting Cycle ActivityContinued voice-phishing campaign against UK BPO partners; no UK maritime victim publicly disclosed this week
ConfidenceHIGH
AdmiraltyA2
ReferenceRefs 3, 6
THREAT ACTOR PROFILE — NoName057(16) and aligned hacktivist clusters
AliasesNoName057(16), pro-Russian hacktivist umbrella
Suspected OriginRussia / aligned
Suspected SponsorHacktivist (state-tolerated)
Primary MotivationIdeological / disruption
Sector FocusGovernment, transport, ports, logistics agencies
ToolingDDoS-as-a-Service (DDoSia), defacement, leak-site disclosure
TTP HighlightsCoordinated DDoS against shipping-agency websites and port-community portals; high-volume but generally short-duration; reputational rather than data-loss impact
Reporting Cycle ActivityContinued Russian state-aligned DDoS posture against UK and EU transport infrastructure web presence
ConfidenceMEDIUM
AdmiraltyC2
ReferenceRef 4
THREAT ACTOR PROFILE — Unattributed AIS/GPS interference cluster
Aliases
Suspected OriginState or state-tolerated (mixed)
Suspected SponsorMixed
Primary MotivationDisruption / influence
Sector FocusMaritime navigation, GPS-dependent industries
ToolingGNSS jammers, AIS spoofing infrastructure
TTP HighlightsSelective interference with vessel-position reporting in contested waterways; periodic spoofing events identified via cross-referencing against satellite AIS and TerrestrialAIS feeds
Reporting Cycle ActivityNo publicly-attributed incidents during the reporting period, but the operational risk remains live for vessels transiting affected high-tension waterways
AdmiraltyC3
ReferenceRef 5

4. Tactics, techniques and procedures

The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviour column summarises the activity in operational terms suitable for use in detection engineering and threat hunting.

ATT&CK TacticTechnique IDTechnique NameObserved BehaviourConf.
Initial AccessT1078.004Valid Accounts: CloudIAB-purchased credentials into logistics ERP, freight-management and customer-portal estates.HIGH
Initial AccessT1566.001Spear-phishing AttachmentTargeted phishing against shipping-agent, freight-forwarder and port-operations staff.MEDIUM
Initial AccessT1190Exploit Public-Facing ApplicationExploitation of edge appliances (Citrix NetScaler, Cisco SD-WAN) against maritime IT estates.HIGH
ExecutionT1059.001PowerShellEncoded loaders for SystemBC / Cobalt Strike in Qilin-affiliate operations.MEDIUM
PersistenceT1543.003Create or Modify System Process: Windows ServiceNew attacker-owned services for persistence inside cargo-management application servers.MEDIUM
Lateral MovementT1021.001Remote Services: RDPPivot into ESXi management of containerised cargo systems prior to encryption.HIGH
ImpactT1486Data Encrypted for ImpactESXi-aware ransomware against virtualised TOS (Terminal Operating System) and WMS estates.HIGH
ImpactT1498Network Denial of ServiceDDoS against shipping-agency websites and port-community portals.MEDIUM

5. Notable incidents and campaigns

DateAffected Org / Sub-SectorSuspected AttributionImpact SummaryReference
18 May 2026West Pharmaceutical Services (logistics-adjacent)Unattributed ransomwareDisruption to shipping, manufacturing and shared-service functions; multi-day operational impact.Ref 7
18 May 2026Foxconn (NA operations)Nitrogen ransomwareClaimed 8TB exfiltration; logistics-flow implications for downstream electronics supply chain.Ref 7
Throughout periodMultiple TheGentlemen leak-site victimsTheGentlemen RaaSLogistics and freight-adjacent entities among the 424 named victims.Ref 9
Throughout periodUK and EU shipping-agency web presencePro-Russian hacktivist clustersContinued low-grade DDoS posture; reputational rather than operational impact.Ref 4
Throughout periodMultiple Akira victims (logistics subset)Akira RaaSLogistics and freight included in the 30+ single-day leak posting on 20 May.Ref 10
Reporting periodVarious AIS / GNSS interference events (continuing)UnattributedSelective AIS spoofing in contested waterways; no UK-flagged incident publicly confirmed.Ref 5

6. Vulnerabilities of concern

The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of the affected product in client estates, and the operational exposure of the typical deployment.

CVE IDAffected ProductCVSSKEVActive ExploitationRecommended Action
CVE-2026-20182Cisco Catalyst SD-WAN10.0YesActive ITWPatch immediately; review SSH key and NETCONF activity for indicators of UAT-8616 tradecraft.
CVE-2026-6973Ivanti EPMM7.2YesActive ITWPatch; rotate pre-Feb-2026 admin credentials; assume compromise where unpatched since Jan.
CVE-2026-34926Trend Micro Apex One (on-prem)8.7YesActive ITWApply Trend Micro fix; review Apex One management console exposure.
CVE-2025-34291Langflow8.2YesActive ITWRemove internet exposure of AI-workflow tooling; patch CORS / refresh-token config.
CVE-2026-3055 / CVE-2026-4368Citrix NetScaler ADC / Gateway9.3 / 8.6YesActive ITWApply Citrix-supplied builds and force-rotate session keys.
CVE-2026-41091Microsoft Defender — EoP7.8YesConfirmed exploitationApply May 2026 Patch Tuesday roll-up across the logistics Windows estate.
CVE-2026-31431Linux Kernel7.0YesActive ITWApply distribution-supplied kernel; relevant to Linux-hosted TOS / WMS estates.
Maritime-specificNMEA / AIS / GNSS spoofing exposuren/an/aOperational riskAdopt navigation backup procedures, multi-source position cross-check, IMO MSC.428(98) cyber-risk-management compliance.
OT-adjacentInsecure remote-maintenance VPNs into TOS estatesvariesn/aRecurringTighten remote-maintenance access — phishing-resistant MFA, segmented jump-host, time-bounded vendor access tokens.

7. Indicators of compromise

The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention. Confidence ratings reflect the strength of the underlying corroboration and the lifetime of the indicator type.

TypeIndicatorFirst SeenConf.Notes
IP185.243.78.42Reporting periodMEDIUMBamboozle Web Services FZ-LLC (Dubai); business hosting; egress-deny candidate for logistics estates with no UAE business need.
TacticLogistics ERP credential phish via fake supplier portalReporting periodMEDIUMCommon Qilin-affiliate IAB pattern; deploy URL-filter signatures for supplier-impersonation domains.
TTPDDoS targeting shipping-agency websitesReporting periodMEDIUMContinued NoName057(16) / DDoSia botnet posture; preposition WAF rate-limit and DDoS-edge mitigation ahead of declared targeting windows.
TTPGNSS jamming in transit waterwaysOngoingMEDIUMOperational rather than IT-side indicator; coordinate with vessel master and shore-side ops to capture and report.
Hash (SHA-256)Qilin.B encryptor variant (redacted)Reporting periodMEDIUMDeploy YARA-based detection alongside existing Qilin family ruleset.

8. Sector risk assessment

The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating reflects the product of likelihood and impact over the next reporting cycle.

Threat ScenarioLikelihoodImpactComposite
Ransomware compromise of TOS / WMS via virtualised hypervisorHIGHHIGHCRITICAL
Cargo-management ERP credential theft and double extortionMEDIUM-HIGHHIGHHIGH
Hacktivist DDoS against shipping-agency or port-community web presenceHIGHMEDIUMHIGH
AIS / GPS interference event affecting UK-flagged vesselMEDIUMMEDIUMMEDIUM
Supplier-side compromise propagating into logistics ERPMEDIUMHIGHHIGH

The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment within the next reporting cycle and should be prioritised in line with the risk assessment in Section 8.

Detect

  • Hypervisor / ESXi management-plane logging: alert on any new SSH session to an ESXi host originating outside the documented admin source-range and on any vSphere admin login from a previously-unseen user-agent.
  • Logistics ERP / TOS authentication telemetry: instrument failed-then-success patterns, geo-anomalies and impossible-travel for any admin or operator-class user.
  • Edge-appliance telemetry: alert on Cisco SD-WAN NETCONF writes, SSH key additions and Citrix NetScaler authentication anomalies in line with NCSC and CISA joint guidance.
  • Maritime-specific signals: AIS / GNSS anomaly cross-check against satellite AIS feed for any vessel in active ops; log and triage gaps and position-jumps.

Defend

  • Patch Cisco SD-WAN, Ivanti EPMM, Trend Micro Apex One and Citrix NetScaler before the next reporting cycle; force-rotate any admin credentials in use prior to the patch window.
  • Tighten remote-maintenance vendor access into TOS / WMS estates: phishing-resistant MFA, segmented jump-host with session recording, time-bounded vendor access tokens, and removal of any always-on RDP / VPN tunnels.
  • Segment cargo-handling OT from corporate IT at the network layer; enforce a unidirectional data diode for OT-to-IT telemetry where feasible.
  • Validate the disaster-recovery position for TOS / WMS estates against an explicit ESXi-aware ransomware scenario; verify offline / immutable backups within the next reporting cycle.

Disrupt

  • Subscribe to MTS-ISAC and contribute observed indicators back through the sharing channel.
  • Push indicators in Section 7 into edge / WAF / EDR via the ipinsights.io TAXII 2.1 feed.
  • Tabletop a coordinated hacktivist-DDoS plus simultaneous ransomware-staging scenario before the next reporting cycle; the cartel / hacktivist hybrid model is the right operational test case for 2026.

10. Forward outlook

It is highly likely that maritime cyber incident volumes will continue to grow through 2026, with at least one major European port disruption likely before end of Q3. (HIGH confidence)

It is likely that hacktivist-and-cartel hybrid operations will be the dominant tradecraft model against the vertical for the rest of the year. (MEDIUM confidence)

Trigger conditions warranting forecast revision: a publicly-disclosed ransomware event at a UK port; an AIS/GPS-spoofing incident affecting a UK-flagged vessel under SOLAS regulation; or a major TOS / WMS vendor publicly disclosing exploitation of one of its products.

11. Analytic confidence and source reliability

Analytic confidence ratings used throughout this report express the analyst's assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence from multiple reliable sources with limited ambiguity; MEDIUM indicates partially-corroborated evidence with some logical inference; LOW indicates limited or fragmentary evidence requiring careful onward use. Estimative language follows the conventions of UK intelligence writing — "almost certainly", "highly likely", "likely", "realistic possibility", "unlikely", "highly unlikely" — and is used in preference to numerical probability bands.

Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for the convenience of recipients.

SourceReliabilityInformationCredibility
A — Completely reliableDemonstrated repeated reliability1 — ConfirmedCorroborated by independent sources
B — Usually reliableReliable on most occasions2 — Probably trueLogical, consistent, partially corroborated
C — Fairly reliableSometimes reliable3 — Possibly trueReasonably logical, agrees with some information
D — Not usually reliableLimited prior accuracy4 — DoubtfulPossible but lacks logic or corroboration
E — UnreliableHistory of inaccuracy5 — ImprobableContradicts other reporting
F — Cannot be judgedNo basis for evaluation6 — Cannot be judgedCannot be assessed

12. References

The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System (see Section 11).

Source / TitlePublisherAdmiralty
1Q1 2026 Ransomware RetrospectiveCheck Point ResearchB2
2Ransomware sector reconsolidating (logistics victims)Industrial CyberB2
3DragonForce / Scattered Spider alliance briefingsSophos X-Ops; Acronis TRU; BlackFogA2
4Russian state-aligned hacktivist posture against UK transportNCSC-UK; ENISAA2
5Maritime cyber incidents jump 103%SAFETY4SEA; CYTUR; Smart Maritime NetworkB2
6Scattered Spider expanding web of ransomware attacksBlackFog; SecurityBrief UKB2
7Cyberattacks on Logistics set to double in 2026Supply Chain 24/7; Everstream AnalyticsB2
8Hellenic Shipping News & CSIS — Port Digitisation Systemic RiskCSIS; HSNB2
9TheGentlemen leak-site victim cadenceThe Hacker News; ransomware.liveB2
10Akira ransomware leak cadenceSecurityWeek; The RecordA2
11CISA / NCSC-UK joint advisory on CVE-2026-20182CISA; NCSC-UK; NSA; ACSC; CCCSA1
12Ivanti May 2026 EPMM Security UpdateIvanti; Help Net Security; SocRadarA2
13Maritime Cyber Risk 2026 — operational risk framingChannel 16 / Dryad Global; TXOne NetworksB2
14ipinsights.io enrichment & blocklist dataipinsights.ioB2

About this report

UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.

Share

Written by

PB
Peter Bassill

Founder and Head of Threat Disruption

Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.

WebsiteLinkedIn

Next step

Want this looked at in your own estate?

Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.