Intel Brief

Maritime Cyber Intelligence Brief

16–31 July 2026 · Free preview. The full issue — 23 developments across six sections — ships to subscribers by email.

Two stories in brief

Full analysis, recommended actions, tabletop scenarios, and cited sources in the complete issue.

Ecopetrol disclosed within hours. The data went up anyway.

Colombia’s state oil major was hit on 17 July and said so the same evening — unauthorised access to cloud file stores at around 15 group companies, data tied to roughly 3,300 user accounts downloaded, an attempted ransomware execution blocked before encryption completed. Two days later its technology VP added that files had been copied but neither deleted nor encrypted. On 28–29 July the company confirmed the attackers had published the material anyway, and said it was working with prosecutors and the technology ministry to have it taken down.

Why it matters: Ecopetrol did nearly everything the playbook asks — same-day disclosure, named scope, blocked encryption, criminal referral — and was published regardless, eleven days later. Against a crew whose product is publication rather than downtime, incident response decides whether you keep operating, not whether your files stay private. Fast disclosure buys regulatory standing and credibility. It does not buy leverage.

The US cyber rule most foreign operators are preparing for does not currently bind their ships

33 CFR 101.605(b) says it in one line: the Coast Guard’s cybersecurity subpart “does not apply to any foreign-flagged vessels subject to 33 CFR part 104.” The US terminals those ships call at are fully inside it, working to a 16 July 2027 deadline for a Cybersecurity Officer, an assessment and a submitted plan. A separate rulemaking aimed at foreign-flagged vessels in US waters is expected around November 2026. Meanwhile the Coast Guard clarified on 22 July that an existing physical-security waiver does not carry over to cyber — those entities still owe an assessment first.

Why it matters: the exemption is real, temporary, and widely misread in both directions. Operators are either preparing for a rule that does not yet apply to them, or assuming the gap is permanent when a proposal is already queued. Both readings cost money. The window between now and the proposal is also the only period in which the industry gets to shape what gets proposed.

The full brief also covers

Subscribers only — the complete analysis ships by email.

Section 1 · Incidents & Attacks
🔒 Sixteen days of official silence from the US Navy on a ransomware crew’s sealift claim — and why the silence itself cannot be read either way 🔒 A national maritime regulator lands on a leak site: the directorate that issues certificates and holds vessel records for the world’s largest archipelagic state 🔒 Japan’s cold chain goes down and shows up in restaurant menus before it shows up in disclosures — 140 distribution centres, 1,300+ restaurants downstream 🔒 Leak-site roundup: five more listings across the sea-freight chain, three of them the documentation layer that holds your bills of lading 🔒 An ocean carrier notifies a breach that began eleven months earlier — and what that says about anyone reassured by their own absence from a leak site
Section 2 · Regulations & Standards
🔒 The Netherlands switches on NIS2 with no grace period, two weeks from now, with fines to 2% of worldwide turnover 🔒 The IMO starts drafting a Maritime Cyber Code — voluntary, goal-based, 2028 — while a mandatory cyber amendment for Maritime Single Windows moves quietly toward 2029
Section 3 · Threats — OT/ICS and GNSS/PNT
🔒 A CISA advisory lands squarely on marine loading racks: unauthenticated debug service, root on the controller that decides whether product moves and how much of it is recorded 🔒 Two industrial platforms, one week apart, share a token-validation mistake — and one of them needs no foothold at all 🔒 CISA widens the Iranian PLC advisory to Schneider and Siemens, with logic that leaves the operator’s screen reading normal — and the maritime link that is ours, not CISA’s 🔒 FortiBleed: what the widely repeated maritime numbers actually rest on, and why the date everyone is using is wrong 🔒 The satellite terminal that answers unauthenticated requests with its own identity
Section 4 · Ports & Supply Chain
🔒 Cyber posture migrates into the dashboard fleet managers already watch every day 🔒 A serving argument that US ports need a cyber insurance backstop
Section 5 · People, Training & Governance
🔒 Singapore’s shipboard OT testbed puts a number on its throughput — and a steering-compromise demo that reads as equipment failure 🔒 Research finds crews systematically under-prepared, set against a testbed that has trained thirty-five people 🔒 A correction we owe readers: the 81-million password-spray campaign was neither July nor maritime — and its lesson survives intact 🔒 The world’s largest ship manager reports owners now shopping for cyber capability alongside technical management

Every locked item carries the same depth as the two above: the pattern behind it, the scale of the exposure, the board-level read, the recommended actions, and where one fits, a tabletop you can run with your team. Every claim cited, every unverified claim labelled as one.

Upcoming maritime cyber events — free

Public events on the forward horizon. No subscription required.

Subscribe

Past issues stay free to read in full. From the June 2026 issue, the complete brief is subscriber-only — each new issue still gets a short free summary.

Monthly
€49/mo
 
  • Full semi-monthly reports
  • Cancel anytime
Subscribe
Semi-Annual
€249/6 mo
€41.50/mo · Save 15%
  • Full semi-monthly reports
Subscribe
Best Value
Annual
€399/yr
€33.25/mo · Save 32%
  • Full semi-monthly reports
Subscribe

Also available in GBP, USD, PLN — select your currency at checkout.