Maritime and logistics threat intelligence report — 30 May – 5 June 2026
The maritime collection picture this week is dominated by the convergence of three structural factors: continuing IT-side ransomware pressure against port operators and freight forwarders…
- Reference: TI-2026-0605-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 30 May – 5 June 2026
- Issued: 5 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
The maritime collection picture this week is dominated by the convergence of three structural factors: continuing IT-side ransomware pressure against port operators and freight forwarders, the POSIDONIA 2026 shipping conference held 01-05 June which predictably attracted hacktivist DDoS and brand-impersonation activity, and a rising operational-technology threat picture against vessel and shore-side OT. CYTUR's industry data placed maritime cyber incidents at +103% year-on-year through 2025, with DDoS, ransomware and malware infections accounting for the majority of growth, and GPS-spoofing disruption now affecting over 40,000 vessels on a typical day.
Perimeter scrubbing was dominated by sustained SSH and Telnet brute-force pressure from the same tail of IP Insights 'critical' sources - ServeTheWorld AS (NO), Contabo (DE), Offshore LC (LU), Viettel (VN), Megacore (VN), JSC Kazakhtelecom (KZ) - none of which produced successful authentication. The wider sector continues to absorb sustained Qilin and Akira interest, with Akira specifically flagged by the Maritime Transportation System ISAC (MTS-ISAC) as a continuing pattern against port operators and shipping agents.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that ransomware deployment against UK and EU port operators, freight forwarders and shipping agents will continue at the elevated 2026 cadence, with Qilin, Akira and TheGentlemen as the dominant threats. (HIGH confidence)
- It is likely that hacktivist DDoS against POSIDONIA 2026 exhibitors and sponsors - running 01-05 June in Athens - will produce at least one brand-impersonation or credential-harvest campaign in the next reporting cycle as event-attendee data is operationalised. (MEDIUM confidence)
- It is highly likely that GPS-spoofing disruption will continue to affect commercial shipping in the Eastern Mediterranean, Black Sea and Persian Gulf at the ~1,000 incidents/day cadence observed through 2025, with hybrid-warfare attribution remaining the dominant analytic line. (HIGH confidence)
- It is likely that CVE-2026-35616 (Fortinet FortiClient EMS) will be exploited against maritime IT estates over the next two reporting cycles, given the prevalence of Fortinet at terminal-management and shore-side IT layers. (MEDIUM-HIGH confidence)
- It is a realistic possibility that the IACS UR E26/E27 cyber-security requirements coming into effect for ships delivered from 01 July 2024 will produce a wave of compliance-driven disclosure during 2026, with knock-on demand for managed-SOC services from owners and operators. (MEDIUM confidence)
2. Sector threat landscape
The maritime threat picture is structurally different from other verticals in that the same threat actor will routinely operate against both IT (port-operator ERP, freight-forwarder customer portals, agent booking systems) and OT (vessel-side navigation, communications, cargo-management) targets. Industrial Cyber's reporting of CYTUR data places maritime incidents at +103% year-on-year through 2025, with the average cost per attack now in excess of USD 550,000. Average ransomware victim-counts from May 2026 (BreachSense) place maritime and transportation in the top six sub-sectors by leak-site posting volume.
Edge-appliance exposure at shore-side IT is the dominant near-term concern. The Microsoft Exchange OWA crafted-email primitive (CVE-2026-42897) remains relevant to ship-broker and freight-forwarder mailbox estates still operating on-prem Exchange.
Hacktivist activity around POSIDONIA 2026, held 01-05 June in Athens with digitalisation and maritime security as flagship agenda items, has predictably included DDoS against exhibitor public-facing services and credential-harvest activity targeting attendees. Russian-aligned NoName057(16)-successor clusters and pro-Palestinian hacktivist coalitions continue to treat maritime targets as legitimate hybrid-warfare objectives.
OT-side risk continues to grow. Dragos and Claroty Team82 reporting through Q1 2026 places vessel-side navigation, ECDIS, voyage-data-recorder and cargo-management systems as principal OT target classes, with GPS-spoofing the most-publicised disruption mode. The IMO MSC-FAL.1/Circ.3/Rev.3 cyber-risk-management guidelines, IACS UR E26/E27 and USCG / UK MCA cyber-security requirements together define the regulatory floor for the cycle.
Perimeter pressure was dominated by familiar brute-force sources - the same NO / DE / LU / VN / KZ cluster observed across all verticals - none successful.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Qilin (a.k.a. Agenda, Qilin.B)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russia
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion / data theft
- Sector Targeting: Cross-sector with sustained Maritime & Logistics relevance.
- Geographic Focus: Global; UK, EU, US, ANZ
- Signature TTPs: VPN-credential IAB initial access; ESXi-aware encryptor; double-extortion
- Tooling / Malware Families: Qilin.B encryptor; SystemBC, AnyDesk, rclone
- Recent Activity: 101 victims posted in May 2026 - fifth consecutive month at top. Sustained maritime / logistics interest.
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH
Akira
- Aliases: -
- Suspected Origin: Russia / CIS criminal milieu
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - extortion
- Sector Targeting: Cross-sector with sustained Maritime & Logistics relevance.
- Geographic Focus: Cross-sector, global; sustained maritime and logistics pattern
- Signature TTPs: VPN initial access (SonicWall, Cisco AnyConnect); rapid lateral via RDP; Rust encryptor
- Tooling / Malware Families: Akira / Megazord encryptors; Cobalt Strike; rclone
- Recent Activity: 52 victims posted in May 2026; H-ISAC and MTS-ISAC continuing standing advisories.
- Assessed Threat to Vertical: HIGH - Admiralty B2.
- Analytic Confidence: HIGH
NoName057(16) successor clusters
- Aliases: NoName-Aligned, RussianCyberArmy, several short-lived rebrands
- Suspected Origin: Russia (aligned)
- Suspected Sponsor: Hacktivist (state-aligned)
- Primary Motivation: Disruption / ideological
- Sector Targeting: Cross-sector with sustained Maritime & Logistics relevance.
- Geographic Focus: UK, EU, NATO partners
- Signature TTPs: Layer-7 DDoS using DDoSia-derivative tooling; brand-impersonation; sanctions-rhetoric leak claims
- Tooling / Malware Families: DDoSia, custom HTTP flood, BotenaGo derivatives
- Recent Activity: Continuing posture against UK / EU maritime targets with sanctions-regime exposure; POSIDONIA 2026 attendees plausible secondary targets.
- Assessed Threat to Vertical: MEDIUM - disruption-grade; Admiralty B2.
- Analytic Confidence: MEDIUM
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Fortinet FortiClient EMS (CVE-2026-35616), Cisco SD-WAN (CVE-2026-20182), Ivanti EPMM (CVE-2026-6973). | HIGH |
| Initial Access | T1133 | External Remote Services | Akira continuing exploitation of SonicWall and Cisco AnyConnect VPN credentials against port-operator IT. | HIGH |
| Initial Access | T1566 | Phishing | Spear-phishing of ship-broker and freight-forwarder finance staff with cargo-related lures. | MEDIUM |
| Execution | T1059.001 | Command and Scripting: PowerShell | Encoded loaders for SystemBC / Cobalt Strike in Qilin and Akira maritime intrusions. | MEDIUM |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Microsoft Defender BlueHammer LPE relevant to maritime IT estates. | MEDIUM |
| Impact | T1486 | Data Encrypted for Impact | ESXi-aware Qilin.B and Akira encryptors against port-operator hypervisor estates. | HIGH |
| Impact | T1498 | Network Denial of Service | Layer-7 DDoS against POSIDONIA 2026 exhibitors and UK / EU port public-facing services by NoName-aligned clusters. | MEDIUM |
| Impact | T1499 | Endpoint Denial of Service | GPS-spoofing of vessel ECDIS / GNSS receivers in Eastern Mediterranean, Black Sea, Persian Gulf. | MEDIUM |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 01-05 Jun 2026 | POSIDONIA 2026 - Athens | Multiple (NoName-aligned, criminal) | Predictable DDoS against exhibitor portals and credential-harvest activity against attendee data. | SAFETY4SEA / industry |
| 02 Jun 2026 | Fortinet FortiClient EMS (vendor) | Unattributed | CVE-2026-35616 confirmed in-the-wild; terminal-management and shore-side IT exposure. | watchTowr Labs |
| Continuing | Eastern Mediterranean / Black Sea / Persian Gulf shipping | Hybrid-warfare actors | GPS-spoofing affecting ~1,000 vessels/day at peak; navigation and AIS integrity impacted. | CYTUR / industry |
| Ongoing | Qilin / Akira leak sites | Multiple | May 2026: Qilin 101, Akira 52; maritime/logistics in top six sub-sectors by posting volume. | BreachSense |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-35616 | Fortinet FortiClient EMS - pre-auth RCE; active in-the-wild exploitation reported by watchTowr 02 Jun 2026 | 9.8 | Yes | Yes | Patch to 7.4.2 or later; restrict EMS admin interface to management VLAN |
| CVE-2026-33825 | Microsoft Defender Antimalware Platform - BlueHammer LPE / defence-evasion (<4.18.26040.1011) | 8.4 | Yes | Yes | Force MoCAMP rollout; hunt for FortiGate SSL-VPN sessions terminating from RU/SG/CH |
| CVE-2026-45585 | Microsoft Windows BitLocker - YellowKey bypass; in-the-wild PoC live | 7.1 | Yes | Suspected | Apply June mitigation guidance; enforce TPM+PIN on regulated workstations |
| CVE-2026-42897 | Microsoft Exchange Server (SE / 2019 / 2016) - OWA crafted-email XSS (continuing exploitation) | 8.1 | Yes | Yes | Apply 14 May 2026 OOB update if not already; disable external OWA pending patch |
| CVE-2026-20182 | Cisco Catalyst SD-WAN Controller / Manager - auth bypass; UAT-8616 continuing campaign | 10.0 | Yes | Yes | Verify Emergency Directive 26-03 closure; rotate SSH keys; review NETCONF logs |
| CVE-2026-6973 | Ivanti EPMM - admin credential reuse chain (post CVE-2026-1340) | 7.2 | Yes | Yes | Rotate any EPMM admin credential issued before 01 Feb 2026; confirm patch level |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer (Magento) - deserialisation; KEV 03 Jun 2026 | 9.8 | Yes | Yes | Patch immediately; isolate Magento admin behind WAF; hunt for unsigned PHP cache entries |
| CVE-2025-48595 | Android Framework - integer-overflow LPE; KEV 02 Jun 2026; limited/targeted exploitation observed by Google | 7.8 | Yes | Yes | Push June 2026 Android security patch to MDM-managed handsets |
| CVE-2022-0492 | Linux Kernel cgroup release_agent - KEV 02 Jun 2026 for revived container-escape campaigns | 7.8 | Yes | Yes | Validate kernels >=5.17; audit container hosts for unconfined cgroup mounts |
| CVE-2026-41091 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-45498 | (KEV-listed; FCEB remediation due 03 Jun 2026) | - | Yes | Yes | Patch per CISA guidance |
| CVE-2026-N8N-CRIT | n8n self-hosted - max-severity authentication-bypass per CyberScoop research (defenders rushing PoC) | 9.8 | Yes | Suspected | Upgrade to patched build; restrict n8n console to private network only |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 85[.]137[.]228[.]167 | 30 May 2026 | H | ServeTheWorld AS (NO); IP Insights threat_score 100, 8 blacklists incl. Emerging Threats Compromised, Brute Force Blocker, Malicious IP - SSH/brute-force cluster |
| IP | 79[.]143[.]178[.]79 | 31 May 2026 | H | contabo.DE; threat_score 100, 7 blacklists incl. ThreatFox malware family - staged loader infrastructure |
| IP | 176[.]65[.]139[.]151 | 01 Jun 2026 | H | Offshore LC (LU); threat_score 100, 7 blacklists - recurring bullet-proof hosting for brute-force |
| IP | 212[.]19[.]134[.]75 | 02 Jun 2026 | H | JSC Kazakhtelecom (KZ); threat_score 100, 8 blacklists; SSH/Telnet brute force at scale |
| IP | 27[.]79[.]41[.]68 | 03 Jun 2026 | H | Viettel Group (VN); threat_score 100, 7 blacklists; SSH brute force |
| IP | 103[.]77[.]246[.]158 | 04 Jun 2026 | H | Megacore Technology (VN); threat_score 100, 7 blacklists; sustained brute-force |
| IP | 34[.]86[.]81[.]254 | 31 May 2026 | M | Google LLC datacentre (US); IP Insights flagged 'critical'; abuse of cloud egress for compromised-stack traffic |
| IP | 136[.]117[.]199[.]185 | 02 Jun 2026 | M | Google LLC datacentre (US); IP Insights 'critical'; cloud-egress abuse |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware deployment against port-operator IT estate via VPN-credential IAB | HIGH | HIGH | CRITICAL |
| Edge-appliance exploitation (Fortinet EMS / Cisco SD-WAN) on shore-side IT | HIGH | HIGH | CRITICAL |
| GPS-spoofing / ECDIS-spoofing of vessels in hybrid-warfare zones | HIGH | MEDIUM | HIGH |
| Hacktivist DDoS / brand-impersonation around POSIDONIA 2026 | MEDIUM | MEDIUM | MEDIUM |
| OT-side compromise of terminal-management or cargo-management systems | MEDIUM | HIGH | HIGH |
| BEC / freight-fraud against ship-broker and freight-forwarder finance staff | HIGH | MEDIUM | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities follow Section 6 directly: patch Fortinet FortiClient EMS to 7.4.2 or later; verify Emergency Directive 26-03 closure on Cisco SD-WAN; rotate any VPN admin credentials whose issue-date predates 01 February 2026; force MoCAMP 4.18.26040.1011 across shore-side endpoint estates; apply the June 2026 Android security patch via MDM to any vessel-side or pilot-station handset. Align to IMO MSC-FAL.1/Circ.3/Rev.3, IACS UR E26/E27, USCG / UK MCA cyber-security requirements, and ISO/IEC 27001 Annex A controls A.5.7 and A.8.8. For ship-broker and freight-forwarder finance functions, implement out-of-band verification of any payment-instruction change.
Disrupt
Disruption activity should focus on: (i) sustained MTS-ISAC participation and indicator exchange, with this week's IP Insights 'critical' tail submitted as the highest-value contribution; (ii) coordinated takedown of POSIDONIA brand-impersonation infrastructure through registrar-abuse and Cloudflare trust-and-safety channels; (iii) tabletop exercises around the IT/OT bridge scenario in which a ransomware deployment in shore-side IT cascades into terminal-management; and (iv) deception deployment around fake VPN endpoints and fake EMS admin tokens to gain attacker-side telemetry.
10. Forward outlook
Looking forward to the next reporting period (06 - 12 June 2026), it is likely that at least one UK or EU port operator, freight forwarder or shipping agent will be named on a Qilin, TheGentlemen or Akira leak-site posting, with MEDIUM-HIGH confidence based on the May 2026 cadence. It is highly likely that GPS-spoofing disruption will continue at the current ~1,000 vessels/day cadence in hybrid-warfare zones. It is a realistic possibility that POSIDONIA 2026 attendee-data harvested this week will resurface as targeted spear-phishing infrastructure within 30 days.
Trigger conditions that would prompt revision include: (a) public attribution of a UK port-operator ransomware incident to Akira VPN-credential exploitation; (b) MTS-ISAC TLP:CLEAR notification of a terminal-management-system compromise; (c) IMO or USCG notice of OT-side incident reportable under MSC.428(98).
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | CISA KEV Catalog updates 27 May, 02 Jun and 03 Jun 2026 - https://www.cisa.gov/known-exploited-vulnerabilities-catalog | CISA | A1 |
| 2 | CISA Alert - CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2022-0492, CVE-2025-48595), 02 Jun 2026 | CISA | A1 |
| 3 | CISA Alert - CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-45247), 03 Jun 2026 | CISA | A1 |
| 4 | NCSC-UK weekly threat report and advisory feed (week ending 05 Jun 2026) - https://www.ncsc.gov.uk/section/keep-up-to-date/threat-reports | NCSC | A1 |
| 5 | ESET APT Activity Report - October 2025 to March 2026 | ESET | B2 |
| 6 | Health-ISAC Heartbeat & 2026 Global Health Sector Threat Landscape Report | Health-ISAC | A2 |
| 7 | Check Point Research - Ransomware Quarterly Insights and May 2026 retrospective | Check Point Research | B2 |
| 8 | BreachSense - May 2026 Ransomware Report (646 victims, 61 groups) | BreachSense | C2 |
| 9 | Ransomware.live - leak-site tracker (Qilin / TheGentlemen / Akira / DragonForce postings, w/e 05 Jun 2026) | Ransomware.live | C2 |
| 10 | watchTowr Labs - Fortinet FortiClient EMS Zero-Day CVE-2026-35616, 02 Jun 2026 | watchTowr | B2 |
| 11 | The Hacker News - Microsoft mitigation for YellowKey BitLocker bypass CVE-2026-45585 | The Hacker News | B2 |
| 12 | The Hacker News - Microsoft warns of two actively exploited Defender vulnerabilities (BlueHammer) | Microsoft / The Hacker News | B1 |
| 13 | CyberScoop - researchers warn of max-severity defect in n8n self-hosted | CyberScoop | B2 |
| 14 | IP Insights - IP reputation enrichment (https://www.ipinsights.io) | UK Cyber Defence Ltd | B2 |
| 16 | CYTUR / Industrial Cyber - Maritime cyber incidents +103% YoY through 2025 | Industrial Cyber | B2 |
| 17 | IMO MSC-FAL.1/Circ.3/Rev.3 - Guidelines on Maritime Cyber Risk Management | IMO | A1 |
| 18 | IACS UR E26 / E27 - cyber resilience requirements (delivery stage) | IACS / AJOT | B2 |
| 19 | MTS-ISAC standing maritime threat reporting | MTS-ISAC | A2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…
Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…