Full analysis, recommended actions, tabletop scenarios, and cited sources in the complete issue.
GNSS · HIGH
Hormuz: three tankers hit, threat level Severe — and within 48 hours the AIS spoofing returns
On 7 July three tankers were attacked near the Strait of Hormuz, including the Qatari LNG carrier Al Rekayyat. The same day JMIC — the Combined Maritime Forces’ 47-nation information-sharing body — raised the shipping threat level to Severe. Then the information layer degraded on cue: AXSMarine logged AIS spoofing resuming on 9 July after a two-week lull, AIS-off transits by non-tanker vessels nearly doubled, and Windward assessed around 40% of Hormuz traffic “gone dark” by 10 July, with confirmed daily crossings dropping by a quarter in a single day.
Why it matters: this is the sequence to internalise — kinetic event, threat-level escalation, then immediate manipulation and withdrawal of the traffic picture. Last issue’s lesson now runs in both directions: the absent ship may be present, and the present track may be a fabrication.
INCIDENT · HIGH
TKMS answers the ransomware claim — confirmed intrusion, confined to one subsidiary
Last issue we flagged the TheGentlemen leak-site claim against Thyssenkrupp Marine Systems as unverified. TKMS has now responded: an intrusion did occur, but the company confines it to a North American subsidiary on segmented IT, and says no security-relevant or sensitive military data was compromised — general administrative documents and file lists. That framing sits in tension with the group’s claim of more than 1 TB of naval engineering material, and cannot be independently verified from outside.
Why it matters: “confirmed, but isolated to a segmented subsidiary” is becoming the standard corporate answer to leak-site claims against sensitive targets — and it is unverifiable by design. For the programme’s supply chain, the defensive posture is unchanged until scope is established independently.