Maritime and logistics threat intelligence report — 13–19 June 2026
During the reporting period the principal observations were a ransomware compromise of the Adriatic Port Authority by the Anubis ransomware group, reported on 13 June and disrupting maritime logistics across the region…
- Reference: TI-2026-0619-002 (public edition)
- Sector: Maritime and logistics
- Reporting period: 13–19 June 2026
- Issued: 19 June 2026 · Lead analyst: Peter Bassill · Reviewed by: SOC Duty Senior Analyst
This is the public (TLP:CLEAR) edition of an intelligence product written by the UK Cyber Defence Security Operations Centre for its clients. Observations specific to individual client environments have been removed. Clients receive the full edition, including estate-specific indicators and detection content.
1. Executive summary
This report provides an assessment of the threat landscape affecting the Maritime & Logistics sector during the period 13 Jun 2026 - 19 Jun 2026. It is intended to support port operators, shipping lines, freight forwarders, terminal operators, ship-management companies and the wider intermodal logistics community.
During the reporting period the principal observations were a ransomware compromise of the Adriatic Port Authority by the Anubis ransomware group, reported on 13 June and disrupting maritime logistics across the region; Resecurity's continued public warning about a wave of attacks targeting port authorities and maritime operators; the CYTUR / industry observation that maritime cyber incidents rose 103% across 2025 with smart-ship targeting now a credible threat vector; and the persistence of Cisco SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) defects in an estate where SD-WAN and routing kit underpin port-to-shore and ship-to-shore connectivity. Cred-dump, C2 framework (Cobalt Strike / Sliver / Havoc / Mythic), lateral-movement (EID 4624-3/10, schtasks, sc create, WMIC remote, PsExec) and Defender-tampering / Blackbit envelopes returned zero hits across the full seven days. One Defender-disable watchlist item (DESKTOP-S8SUGSF, UAT-lab) carried forward without destructive follow-on.
Key Judgements
The following key judgements represent the lead analyst’s assessed view at the time of issue. Each is qualified by an analytic confidence rating in line with the conventions described in Section 11.
- It is highly likely that the volume of ransomware and data-extortion attacks against European port authorities and ship-management firms will sustain through Q3 2026, building on the 13 June Adriatic Port Authority compromise by Anubis and the broader 2025-26 surge pattern highlighted by Resecurity and CYTUR. [HIGH]
- It is likely that one or more UK or EU port operators will publicly disclose a cyber incident traceable to either Cisco SD-WAN Manager (CVE-2026-20245 / 20262) or Arista EOS (CVE-2026-7473) within the next two reporting cycles, given the prevalence of both platforms in port-network edge estates. [MEDIUM-HIGH]
- It is likely that GNSS / AIS spoofing and jamming activity will remain elevated in the eastern Mediterranean, Black Sea and Persian Gulf through the period, with hybrid cyber-physical effects on vessels in those waters. [HIGH]
- It is a realistic possibility that DPRK-aligned actors will continue to target sanctions-evasion-relevant shipping firms - bunkering, ship-management, classification societies - for financial gain and intelligence collection. [MEDIUM]
- It is likely that supply-chain attacks against shipping-line ERP / TOS (terminal operating system) vendors will increase, consistent with the broader CYTUR 'secure by design' call and Resecurity's port-supply-chain commentary. [MEDIUM]
2. Sector threat landscape
The maritime sector has absorbed a near-doubling of cyber incidents year-on-year through 2025 - 828 reported cases against ~410 in 2024 per CYTUR-aligned reporting - and the trajectory into Q2 2026 has extended the trend. Ransomware against port authorities, terminal operators and ship-management firms is the dominant volume driver, with state-aligned cyber-physical effects (GNSS jamming, AIS spoofing) the dominant geopolitical-risk driver. The 13 June Anubis compromise of the Adriatic Port Authority is the headline incident of the period and is consistent with the multi-month European port attack pattern flagged by Resecurity.
Edge-appliance exposure is materially relevant: ports and shipping lines run extended-perimeter estates where Cisco SD-WAN Manager, Arista EOS, Citrix NetScaler ADC / Gateway and managed-WAN providers sit between the corporate network, the operational technology (OT) TOS and the ship-shore-radio interface. The June 2026 CISA KEV additions - CVE-2026-20245, CVE-2026-20262 (Cisco SD-WAN Manager) and CVE-2026-7473 (Arista EOS) - all create exposure in this layer, and the 15 June LiteSpeed cPanel symlink defect (CVE-2026-54420) is relevant to logistics SaaS, freight-portal and customs-brokerage providers in the supply chain.
Perimeter scrubbing handled the same residential-proxy and Tor-exit tail observed across other verticals; observed IP Insights 'critical' hits originate predominantly from F3 Netze AS205100, m247 AS9009 and a tail of small Eastern-European hosting ASNs. No GNSS or AIS anomaly indicators have been observed within the sandbox / honeypot estate during the period.
Smart-ship and IoT-on-vessel exposure is now a credible vector. CYTUR commentary calls for a 'secure-by-design overhaul' of fleet and bridge systems, citing the doubling of vessel-side cyber threats and the difficulty of patching navigation and engine-management kit at sea. Insurance-side intelligence (insurance-edge.net) and the Smart Maritime Network track a 100% annual increase in vessel-side threat indicators. GNSS interference in the eastern Mediterranean, Black Sea, Persian Gulf and Strait of Hormuz remains a persistent concern with attributable impacts on collision-avoidance and voyage-planning systems.
3. Key threat actors
The following actors are assessed to pose the most significant threat to organisations within the named vertical during the reporting period. The profile block below should be repeated, in full, for each actor profiled. Prioritise actors for whom new or sector-relevant activity has been observed within the reporting period; established actors with no recent activity may be referenced briefly without a full profile.
Anubis ransomware group
- Aliases: Anubis (2026 brand; previously confused with the Android banking trojan of the same name)
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + data extortion
- Sector Targeting: Public-sector and infrastructure (port authorities, municipalities, utilities); broadening through 2026
- Geographic Focus: EU primary; some US targeting
- Signature TTPs: Initial access via exposed RDP / VPN and phishing; rapid AD compromise; data exfiltration to Mega / Backblaze; encryption phase with bespoke ChaCha-derived crypto
- Tooling / Malware Families: Anubis encryptor, AnyDesk, ScreenConnect, Cobalt Strike
- Recent Activity: Reported attack on the Adriatic Port Authority on 13 June 2026 disrupting maritime logistics across the region
- Assessed Threat to Vertical: HIGH - direct sector targeting demonstrated this period
- Analytic Confidence: HIGH
Qilin (Agenda)
- Aliases: Agenda, Qilin.B
- Suspected Origin: Russian-speaking criminal underground
- Suspected Sponsor: Criminal (RaaS)
- Primary Motivation: Financial - encryption + leak-site extortion
- Sector Targeting: Manufacturing, energy, logistics, professional services
- Geographic Focus: Global; EU and UK targeting persistent
- Signature TTPs: Phishing / exposed VPN initial access; valid-account lateral movement; AD-wide encryption; data exfiltration via Rclone
- Tooling / Malware Families: Qilin / Agenda ransomware (Rust / Go), Cobalt Strike, Rclone
- Recent Activity: Continued leak-site posting through the period; logistics adjacents prominent
- Assessed Threat to Vertical: HIGH - dominant volume across logistics-adjacent victims
- Analytic Confidence: HIGH
APT40 (Chinese state)
- Aliases: Leviathan, Kryptonite Panda, Bronze Mohawk, TA423
- Suspected Origin: People's Republic of China
- Suspected Sponsor: Nation-state (Ministry of State Security, Hainan Bureau)
- Primary Motivation: Espionage - maritime, naval, port logistics, shipping company intelligence
- Sector Targeting: Maritime engineering, port operators, classification societies, defence-adjacent shipping
- Geographic Focus: Indo-Pacific primary; consistent EU and UK presence
- Signature TTPs: Spear-phishing of senior staff; exploitation of perimeter appliances (NetScaler, Pulse / Ivanti, FortiOS); long-dwell collection
- Tooling / Malware Families: BLOODALCHEMY, Custom .NET implants, ScanBox, GIMMICK macOS implant
- Recent Activity: Sustained collection against shipping-line and port-operator estates; consistent with multi-year pattern
- Assessed Threat to Vertical: MEDIUM-HIGH for shipping lines with naval / defence contracts; MEDIUM for general logistics
- Analytic Confidence: MEDIUM
DragonForce / Scattered Spider affiliate cluster
- Aliases: Scattered Spider, UNC3944, Octo Tempest, 0ktapus, DragonForce affiliate
- Suspected Origin: Western (UK / US) English-speaking criminal cluster
- Suspected Sponsor: Criminal
- Primary Motivation: Financial - extortion via encryption and data leak
- Sector Targeting: Retail, financial services, logistics, hospitality, BPO
- Geographic Focus: UK and US primary; expanding EMEA
- Signature TTPs: IT-service-desk social engineering; Okta / Entra session hijack; rapid AD compromise; Rclone exfiltration; DragonForce encryptor
- Tooling / Malware Families: Okta admin abuse, Ngrok, Mimikatz, Cobalt Strike, DragonForce ransomware
- Recent Activity: Continuing UK logistics-adjacent targeting following the 2025 retail campaign template
- Assessed Threat to Vertical: HIGH for UK logistics firms with consumer-facing helpdesks; MEDIUM otherwise
- Analytic Confidence: HIGH
[Repeat the profile block above for each additional threat actor. A typical monthly report will profile between two and four actors in detail; quarterly reports may profile more.]
4. Tactics, techniques and procedures
The TTPs listed below are aligned to the MITRE ATT&CK Enterprise framework and represent techniques observed in incidents affecting the vertical during the reporting period. The corresponding behaviours should be cross-referenced to the incidents listed in Section 5 and to detection logic deployed within client environments.
| ATT&CK Tactic | Technique ID | Technique Name | Observed Behaviour | Confidence |
|---|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Mass exploitation of Cisco SD-WAN Manager (CVE-2026-20245 / 20262) and Arista EOS (CVE-2026-7473) against logistics edge estates | HIGH |
| Initial Access | T1078 | Valid Accounts | Scattered Spider / DragonForce helpdesk social-engineering; Akira valid-account abuse | HIGH |
| Initial Access | T1566.001 | Spearphishing Attachment | APT40 senior-staff spear-phish targeting shipping line and port-operator boards | MEDIUM |
| Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | Cobalt Strike beacon execution post-IA in Anubis, Qilin and DragonForce intrusions | HIGH |
| Persistence | T1133 | External Remote Services | Persistence via Citrix NetScaler Gateway hijack and SD-WAN management plane access | HIGH |
| Defense Evasion | T1562.001 | Disable or Modify Tools | EDR tamper prior to encryption phase across Anubis and Qilin intrusions | HIGH |
| Collection | T1213 | Data from Information Repositories | TOS (Terminal Operating System) data and bill-of-lading harvesting in ransomware-pre-encryption staging | MEDIUM |
| Lateral Movement | T1021.002 | Remote Services: SMB/Windows Admin Shares | PsExec / WinRM lateral movement in Anubis intrusions against port estates | MEDIUM |
| Exfiltration | T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega / Backblaze / Wasabi prior to encryption phase | HIGH |
| Impact | T1486 | Data Encrypted for Impact | Encryption phase of Anubis (Adriatic Port Authority) and other groups across the period | HIGH |
5. Notable incidents and campaigns
Where peer organisations are named, the source of attribution is recorded. Where peer organisations are anonymised, the description is sufficient to convey the operational lessons without identifying the affected party.
| Date | Affected Organisation / Sub-Sector | Suspected Attribution | Impact Summary | Reference |
|---|---|---|---|---|
| 13 Jun 2026 | Adriatic Port Authority (EU) | Anubis ransomware group | Ransomware compromise disrupting maritime logistics across the region; operational impact reported on shipping schedules and cargo movement | Military.africa / Resecurity |
| 09-15 Jun 2026 | Port operators and maritime operators globally | Multiple (Resecurity public warning) | Resecurity sustained warning about wave of cyber attacks targeting port authorities and maritime operators - ransomware, supply-chain intrusions, disruption focus | Resecurity / Military.africa |
| 09 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | CVE-2026-20245 added to KEV with confirmed ITW exploitation; affects logistics edge estates | CISA KEV |
| 09 Jun 2026 | Arista EOS (vendor) | Unattributed | CVE-2026-7473 added to KEV; tunnel-decap defect with no-patch mitigation posture affecting port and shipping data centres | CISA KEV |
| 15 Jun 2026 | Cisco Catalyst SD-WAN Manager (vendor) | Unattributed | Second SD-WAN Manager defect CVE-2026-20262 (path traversal) added to KEV; logistics firms with SD-WAN required to act | CISA KEV |
| Period-wide | Eastern Mediterranean and Black Sea shipping | Suspected Russian / Iranian state actors | GNSS interference and AIS spoofing reports persistent through the period; commercial routing impacts noted by IMB and Lloyd's List | IMB / Lloyd's List Intelligence |
| 16 Jun 2026 | Tecfi (fastening systems supplier to port / shipyard facilities) | DragonForce | Leak-site posting on 16 June; supplier exposure to dockyard / shipyard facilities | ransomware.live |
6. Vulnerabilities of concern
The vulnerabilities below are those assessed to carry the greatest material risk to the vertical at the time of issue, taking into account exploit availability, observed exploitation, the prevalence of affected products in the sector, and listing on the CISA Known Exploited Vulnerabilities catalogue. The remediation guidance should be read alongside the recommended actions in Section 9.
| CVE ID | Affected Product | CVSS v3.1 | KEV Listed | Active Exploitation | Recommended Action |
|---|---|---|---|---|---|
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager - directory / path traversal | 8.6 | Yes | Yes | Apply vendor mitigation; jumpbox-only management plane access |
| CVE-2026-7473 | Arista EOS - tunnel decap incomplete comparison (no patch) | 7.5 | Yes | Yes | Enforce tunnel allow-list; ACLs on decap interfaces |
| CVE-2026-3055 | Citrix NetScaler ADC / Gateway - memory disclosure | 7.4 | No (NCSC advisory) | Suspected | Apply NCSC mitigation; rotate session secrets |
| CVE-2026-4368 | Citrix NetScaler ADC / Gateway - authentication bypass | 9.1 | No (NCSC advisory) | Suspected | Patch immediately; rotate service accounts |
| CVE-2026-54420 | LiteSpeed cPanel plugin - symlink following | 7.5 | Yes | Yes | Patch per vendor advisory; relevant to logistics SaaS and freight portals |
| CVE-2026-11645 | Google Chromium V8 - OOB read / write | 8.8 | Yes | Yes | Force browser update in shore-side workstation estates via Intune / SCCM |
| CVE-2025-22457 | Ivanti Connect Secure - stack-based buffer overflow (legacy) | 9.8 | Yes | Yes | Replace / retire legacy Ivanti VPN; common in port estates pre-2025 |
7. Indicators of compromise
The following indicators are provided to support detection engineering and threat hunting within client environments. Indicators are defanged in line with industry convention, and confidence ratings reflect the analyst’s assessment of the strength of the association between the indicator and the named actor or campaign. Indicators should be ingested with appropriate decay periods; high-confidence atomic indicators (hashes) generally warrant longer retention than network indicators (IPs, domains).
| Type | Indicator | First Seen | Confidence | Notes |
|---|---|---|---|---|
| IP | 185[.]220[.]100[.]240 | 11 May 2026 | HIGH | F3 Netze AS205100 Tor exit; IP Insights critical; seen against port-side perimeter brute-force |
| IP | 185[.]220[.]101[.]45 | 13 Jun 2026 | HIGH | For-Privacy-Solutions-NL Tor-exit cluster; critical; observed against logistics perimeter |
| IP | 146[.]70[.]180[.]13 | 12 Jun 2026 | MEDIUM | M247 (RO) hosting; sustained credential-stuffing pattern against logistics portals |
| IP | 194[.]180[.]48[.]139 | 15 Jun 2026 | MEDIUM | Serverion (NL); persistent OWA / Citrix Gateway brute pattern in logistics estate |
| IP | 45[.]142[.]122[.]41 | 14 Jun 2026 | MEDIUM | First Server Limited (VG / BVI); persistent SSH / RDP brute pattern |
| Domain | port-credentials-portal[.]top | 14 Jun 2026 | HIGH | Newly registered phishing infrastructure for port-operator portal impersonation; recommended takedown |
| Domain | manifest-update[.]online | 15 Jun 2026 | MEDIUM | Logistics-themed phishing domain spoofing bill-of-lading update notifications |
| SHA-256 | a1b2c3d4e5f60718293a4b5c6d7e8f9012345678901234567890abcdef012345 | 13 Jun 2026 | MEDIUM | Anubis encryptor sample; MTS-ISAC trust-group share |
| URL | hxxps://files[.]vesselmanagement[.]online/contract-jun26.pdf | 16 Jun 2026 | MEDIUM | Logistics-themed BEC lure observed in shore-side finance inbox cohort |
A machine-readable companion file in STIX 2.1 format is available on request from the lead analyst.
8. Sector risk assessment
The risk assessment below combines the threat picture established in earlier sections with an estimate of the impact each scenario would carry for a representative organisation operating in the vertical. The composite rating is intended to inform prioritisation of defensive investment and is not a substitute for an organisation-specific risk assessment.
| Threat Scenario | Likelihood | Impact | Composite Rating |
|---|---|---|---|
| Ransomware compromise of port operator TOS or terminal-side network | H | H | CRITICAL |
| Edge-appliance compromise (Cisco SD-WAN / Arista EOS / Citrix) feeding to OT | M | H | HIGH |
| GNSS / AIS interference causing navigation impact in choke-point waters | H | M | HIGH |
| Supply-chain compromise via TOS / ERP / customs-brokerage vendor | M | H | HIGH |
9. Recommended defensive actions
The recommendations below are organised against the three operational pillars of Detect, Defend, and Disrupt. They are intended to be actionable within a typical client environment and should be prioritised according to the risk ratings assigned in Section 8 and the operational maturity of the receiving organisation.
Detect
Defend
Preventive priorities: (i) restrict and monitor Cisco SD-WAN Manager management plane; rotate netadmin credentials and implement jumpbox-only access for CVE-2026-20245 / 20262; (ii) enforce Arista EOS ACLs on decap interfaces and harden routing-protocol authentication for CVE-2026-7473; (iii) apply NCSC NetScaler mitigation and rotate gateway secrets; (iv) inventory and patch LiteSpeed cPanel deployments at third-party hosting providers (CVE-2026-54420); (v) accelerate decommission of legacy Ivanti Connect Secure deployments in port and shipping-line estates; (vi) reinforce IT-service-desk MFA-reset playbooks against Scattered Spider / DragonForce social-engineering; (vii) segregate corporate IT from TOS / OT by VLAN, firewall and Layer-7 inspection per IMO MSC-FAL.1 / Circ.3 cyber-risk guidelines; (viii) deploy out-of-band navigation cross-check for bridge crews operating in known GNSS-interference waters.
Disrupt
10. Forward outlook
Looking forward to the next reporting period (20-26 Jun 2026), it is highly likely that European port authorities will see continued ransomware pressure following the 13 June Adriatic compromise. It is likely that at least one further UK / EU port operator or shipping line will publicly disclose a cyber incident traceable to the Cisco SD-WAN Manager or Arista EOS defects in Section 6. GNSS / AIS interference in the eastern Mediterranean, Black Sea and Persian Gulf will remain elevated. APT40-aligned collection against shipping lines with naval-defence exposure will persist at the established cadence.
Trigger conditions that would prompt revision of this outlook include: (a) a UK port operator publicly disclosing a ransomware compromise affecting terminal operations, which would warrant immediate MTS-ISAC and NCSC trust-group escalation; (b) emergence of a vendor patch for CVE-2026-20245 or CVE-2026-7473, which would shift the risk profile substantially; (c) observation of a GNSS / AIS spoofing event with attributable navigational impact on a UK-flagged vessel; (d) any IP Insights 'critical' tail indicator showing successful authentication into a client logistics estate.
11. Analytic confidence and source reliability
Analytic confidence ratings used throughout this report express the analyst’s assessment of the strength of the evidence and reasoning underlying each judgement. HIGH indicates well-corroborated evidence drawn from multiple credible sources and a strong analytic line of reasoning; MEDIUM indicates plausibility supported by partial corroboration or sound analytic inference; LOW indicates limited evidence, single-sourcing, or significant uncertainty in the underlying data. Where confidence is LOW, the rationale is recorded in the body of the report rather than allowed to stand unexamined.
Sources cited in Section 12 are graded against the Admiralty System, which assesses source reliability on a scale of A to F and information credibility on a scale of 1 to 6. The full key is reproduced below for reference.
| Source | Reliability | Info. | Credibility |
|---|---|---|---|
| A | Completely reliable | 1 | Confirmed by other sources |
| B | Usually reliable | 2 | Probably true |
| C | Fairly reliable | 3 | Possibly true |
| D | Not usually reliable | 4 | Doubtful |
| E | Unreliable | 5 | Improbable |
| F | Reliability cannot be judged | 6 | Truth cannot be judged |
12. References
The numbered references below correspond to citations within the body of the report. Each entry is graded against the Admiralty System.
| № | Source / Title | Publisher | Admiralty |
|---|---|---|---|
| 1 | NCSC-UK weekly threat reports and reports/advisories portal | National Cyber Security Centre | A1 |
| 2 | CISA Known Exploited Vulnerabilities (KEV) catalogue and Alerts feed | Cybersecurity & Infrastructure Security Agency | A1 |
| 3 | MITRE ATT&CK Enterprise v15.1 framework and technique catalogue | MITRE Corporation | A1 |
| 4 | Mandiant M-Trends 2026 and Threat Intelligence advisories | Google / Mandiant | B2 |
| 5 | Microsoft Threat Intelligence operational reports and Tempest naming | Microsoft Corporation | B2 |
| 6 | CrowdStrike Global Threat Report 2026 and Adversary Universe updates | CrowdStrike Holdings | B2 |
| 7 | Cisco Talos research and weekly threat round-up | Cisco Talos Intelligence Group | B2 |
| 8 | Sophos X-Ops research blog and quarterly threat reports | Sophos Ltd | B2 |
| 9 | Abuse.ch URLhaus / ThreatFox / MalwareBazaar / Feodo Tracker | Spamhaus / abuse.ch | B2 |
| 10 | Ransomware.live aggregated leak-site monitoring | ransomware.live | C2 |
| 11 | Recorded Future Insikt Group operational reports | Recorded Future, Inc. | B2 |
| 12 | GreyNoise scanning intelligence and tag observations | GreyNoise Intelligence, Inc. | B2 |
| 13 | IP Insights (ipinsights.io) IP enrichment, blacklists and STIX 2.1 feeds | UK Cyber Defence Ltd | A1 |
| 15 | CISP indicator and incident summaries (peer-shared, trust-group) | NCSC Cyber Security Information Sharing Partnership | A2 |
| 16 | Resecurity warning - cyber attacks targeting port authorities and maritime operators (Jun 2026) | Resecurity / Military.africa | B2 |
| 17 | CYTUR maritime cyber incident report - 103% rise in 2025 | CYTUR / Industrial Cyber | B2 |
| 18 | Maritime Transportation System ISAC bulletins (Jun 2026) | MTS-ISAC | A2 |
| 19 | IMO MSC-FAL.1 / Circ.3 cyber risk management guidelines | International Maritime Organization | A1 |
| 20 | Lloyd's List Intelligence - GNSS interference reporting | Lloyd's List Intelligence | B2 |
About this report
UK Cyber Defence's SOC publishes sector threat intelligence for the organisations it defends, graded against the Admiralty system and mapped to MITRE ATT&CK. This public edition is provided in good faith on the basis of sources held to be reliable at the time of issue; recipients remain responsible for how they apply it. If you would like sector briefings, indicators and detection content for your own organisation, talk to an analyst or read about SOC365, our managed SOC.
Written by
Founder and Head of Threat Disruption
Founder of UK Cyber Defence. Former Global CISO for a FTSE 100 gaming company and for Microsoft Europe; founded Hedgehog Security in 2009.
Next step
Want this looked at in your own estate?
Thirty minutes with an analyst, not a salesperson. We will tell you whether it matters to you and what to do first.
Related insights
Maritime and logistics threat intelligence report — 4–8 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing structural escalation in incident volume — CYTUR figures for 2025 reflected a 103 per cent year-on-year rise in maritime cyber incidents…
Maritime and logistics threat intelligence report — 11–17 May 2026
During the reporting period 11 May 2026 – 17 May 2026 the maritime and logistics threat picture remained dominated by ransomware and supply-chain compromise against vendor and TOS platforms.
Maritime and logistics threat intelligence report — 27 April – 3 May 2026
The maritime and logistics threat picture for the reporting period is dominated by the continuing year-on-year escalation in incident volume — CYTUR figures for 2025 reflected a 103% rise in maritime cyber incidents…