Intel Brief

Maritime Cyber Intelligence Brief

1–15 July 2026 · Free preview. The full issue — 13 developments across six sections — ships to subscribers by email.

Two stories in brief

Full analysis, recommended actions, tabletop scenarios, and cited sources in the complete issue.

Hormuz: three tankers hit, threat level Severe — and within 48 hours the AIS spoofing returns

On 7 July three tankers were attacked near the Strait of Hormuz, including the Qatari LNG carrier Al Rekayyat. The same day JMIC — the Combined Maritime Forces’ 47-nation information-sharing body — raised the shipping threat level to Severe. Then the information layer degraded on cue: AXSMarine logged AIS spoofing resuming on 9 July after a two-week lull, AIS-off transits by non-tanker vessels nearly doubled, and Windward assessed around 40% of Hormuz traffic “gone dark” by 10 July, with confirmed daily crossings dropping by a quarter in a single day.

Why it matters: this is the sequence to internalise — kinetic event, threat-level escalation, then immediate manipulation and withdrawal of the traffic picture. Last issue’s lesson now runs in both directions: the absent ship may be present, and the present track may be a fabrication.

TKMS answers the ransomware claim — confirmed intrusion, confined to one subsidiary

Last issue we flagged the TheGentlemen leak-site claim against Thyssenkrupp Marine Systems as unverified. TKMS has now responded: an intrusion did occur, but the company confines it to a North American subsidiary on segmented IT, and says no security-relevant or sensitive military data was compromised — general administrative documents and file lists. That framing sits in tension with the group’s claim of more than 1 TB of naval engineering material, and cannot be independently verified from outside.

Why it matters: “confirmed, but isolated to a segmented subsidiary” is becoming the standard corporate answer to leak-site claims against sensitive targets — and it is unverifiable by design. For the programme’s supply chain, the defensive posture is unchanged until scope is established independently.

The full brief also covers

Subscribers only — the complete analysis ships by email.

Section 1 · Incidents & Attacks
🔒 DragonForce lists ASIMAR — Thailand’s most-awarded shipyard lands on a leak site, with a curious metadata anomaly 🔒 Marine Electricals, Tier-1 electrical and navigation supplier to the Indian Navy, discloses a firewall attack in an exemplary exchange filing 🔒 Leak-site roundup: 1.1 TB claimed from a Gulf of Mexico fabricator — and a Hamburg marine-interiors “victim” that has been in liquidation for a year 🔒 Greek police recover the full €4M from a shipping BEC scam — the counter-playbook working end to end
Section 2 · Regulations & Standards
🔒 USCG’s CTIME 2025 formally lands — and the stat that reframes it: 62% of Coast Guard cyber engagements now touch OT
Section 3 · Threats — OT/ICS and GNSS/PNT
🔒 Singapore’s IFC counts 40 deliberate AIS-deception incidents in June alone — and the methodology caveat that makes headline “surge” numbers honest 🔒 JadePuffer: the first documented agentic-AI ransomware operation — not maritime, but aimed at exactly maritime’s weakness
Section 4 · Ports & Supply Chain
🔒 Rakuten Maritime × Hanwha Ocean — vessel-lifecycle cybersecurity gets its first full-scale commercial deployment at a yard delivering ~45 ships a year 🔒 Iridium’s jam-resistant PNT chip goes commercial — authenticated positioning as a procurable component
Section 5 · People, Training & Governance
🔒 ICS Maritime Barometer: 185 C-suite leaders rank geopolitics and cyber as the top threats to world trade 🔒 Gard: AIS-assisted collisions are now a recurring casualty factor — the over-reliance warning from the insurers

Every locked item carries the same depth as the two above: the pattern, the scale, the board-level read, the actions, and where it fits, a tabletop you can run with your team. Every claim cited.

Upcoming maritime cyber events — free

Public events on the forward horizon. No subscription required.

Subscribe

Past issues stay free to read in full. From the June 2026 issue, the complete brief is subscriber-only — each new issue still gets a short free summary.

Monthly
€49/mo
 
  • Full semi-monthly reports
  • Cancel anytime
Subscribe
Semi-Annual
€249/6 mo
€41.50/mo · Save 15%
  • Full semi-monthly reports
Subscribe
Best Value
Annual
€399/yr
€33.25/mo · Save 32%
  • Full semi-monthly reports
Subscribe

Also available in GBP, USD, PLN — select your currency at checkout.