Intel Brief

Maritime Cyber Intelligence Brief

1–15 August 2026 · Free preview. The full issue — 21 developments across six sections — ships to subscribers by email.

Two stories in brief

Full analysis, recommended actions, tabletop scenarios, and cited sources in the complete issue.

The paperwork said NDAA-compliant. The firmware called China.

Cameras fitted to 20 K3 Scout uncrewed surface vessels operated by the Royal Marines were sending automated “heartbeat” signals — status pings confirming the device is alive — to an IP address in China. The boats came from Kraken Technology Group under a £12.3m contract. Nobody reported an incident and no attacker tipped anyone off: the finding came out of a routine cyber vulnerability assessment. The Ministry of Defence cut internet connectivity to the cameras and said its investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally. Kraken said the third-party cameras were labelled NDAA-compliant and contained “a small number of components originating from outside the UK”.

Why it matters: an NDAA-compliance label answers one question — whether a component came from a manufacturer named in Section 889 of the 2019 US National Defense Authorization Act. It says nothing about what the firmware does once the box is installed. A camera can clear that list on paper and still beacon out every few seconds. The control that caught this was not a certificate; it was somebody actually testing the equipment they had already bought.

The first marine policy that pays for a course, not a box

Sompo Japan launched cover aimed at economic loss from radio interference with ship navigation systems — paying out when a vessel cannot operate despite suffering no physical damage at all: prevented from entering port, detained, or forced to delay departure after GNSS disruption. It extends the insurer’s existing marine cyber product, which covers hull damage and liability, into pure lost earnings with no collision or grounding involved. The condition of cover is the part worth reading twice: participating seafarers must complete a ClassNK Academy maritime cybersecurity course. No equipment purchase is required.

Why it matters: this is an insurer pricing competence instead of hardware, and it lands in the same fortnight a flag state started subsidising the same skills and a national cyber authority told industry that detecting an incident after it happens is not a control. Three institutions, arriving from three directions, on one conclusion. The open question a buyer should put to the underwriter before signing: whether interference attributed to a state actor — which is most of the interference in the Baltic, Black Sea and Gulf — falls inside the cover or outside it as a war exclusion. No source we found answers that.

The full brief also covers

Subscribers only — the complete analysis ships by email.

Section 1 · Incidents & Attacks
🔒 A US state port authority runs three terminals on manual gates — and then says nothing at all for nine days, a silence we checked twice 🔒 A CMA CGM subsidiary loses eight European warehouses while ocean freight keeps moving — and twelve separate regulatory filings land in under two weeks 🔒 A freight broker confirms an intrusion but not the million files the extortion crew says it holds — and the crew’s method is a phone call, not an exploit 🔒 Seven leak-site listings across the sea-freight chain — a shipbuilding outfitter, a 118-year-old dredging contractor, a port-services fleet — and one where the attacker names the victim’s IT provider too 🔒 The cruise-ship “hack” that the operator’s own statement says was not a hack — and the question no source has answered
Section 2 · Regulations & Standards
🔒 The Netherlands switched NIS2 on with no grace period on the last day of this window — registration, reporting and board liability all at once, fines to 2% of worldwide turnover 🔒 India stands up a dedicated Bureau of Port Security — citing a US port incident by name two days after it happened 🔒 Three compliance clocks at three distances — and the fortnight the US Coast Guard published nothing at all
Section 3 · Threats — OT/ICS and GNSS/PNT
🔒 A backdoor that shipped from the factory in an estimated 100,000 routers — dialling out every 35 seconds, which means your firewall never sees it 🔒 Twenty-two ICS advisories in the window and not one maritime product — plus the four that sit inside a terminal anyway 🔒 An actively exploited firewall flaw with a three-day federal deadline, sitting on the box that keeps your remote staff and contractors connected 🔒 An aviation advisory that describes AIS’s exact problem — with four CVEs and a CVSS score attached to it, which maritime has never had 🔒 Two credible counts of the same exposed controllers came out nearly 3,000 devices apart — and why no outside scan can answer the question for you 🔒 A fortnight with no new dated GNSS incident anywhere we checked — and why that is not the same as quiet
Section 4 · Ports & Supply Chain
🔒 A ransomware crew spends the fortnight publishing engineering drawings and CAD files taken through a design-software flaw — one listing alone runs to 89 GB — and the patch deadline closed seven weeks earlier 🔒 A $4.175bn consolidation of the OT-security tooling market — and why we are not reporting it as closed
Section 5 · People, Training & Governance
🔒 A national cyber authority on AI systems that took unsanctioned actions and behaved deceptively during evaluations: detection after the fact “will not be enough” 🔒 A flag state subsidises OT-literate ship’s staff before it has to mandate them — on a shipboard OT testbed, quarterly 🔒 Where the 103% figure everyone quotes actually comes from — and what its methodology does not cover

Every locked item carries the same depth as the two above: the pattern behind it, the scale of the exposure, the board-level read, the recommended actions, and where one fits, a tabletop you can run with your team. Every claim cited, every unverified claim labelled as one — including the ones we checked and threw out.

Upcoming maritime cyber events — free

Public events on the forward horizon. No subscription required.

Subscribe

Past issues stay free to read in full. From the June 2026 issue, the complete brief is subscriber-only — each new issue still gets a short free summary.

Monthly
€49/mo
 
  • Full semi-monthly reports
  • Cancel anytime
Subscribe
Semi-Annual
€249/6 mo
€41.50/mo · Save 15%
  • Full semi-monthly reports
Subscribe
Best Value
Annual
€399/yr
€33.25/mo · Save 32%
  • Full semi-monthly reports
Subscribe

Also available in GBP, USD, PLN — select your currency at checkout.