Intel Brief

Maritime Cyber Intelligence Brief

16–31 August 2026 · Free preview. The full issue — 22 developments across six sections — ships to subscribers by email.

Two stories in brief

Full analysis, recommended actions, tabletop scenarios, and cited sources in the complete issue.

Brazil’s submarine yard went dark on 9 August. The record of it arrived on the 22nd, from the people who did it.

Itaguaí Construções Navais — the yard responsible for Brazil’s submarine development programme, PROSUB, building conventional boats for the Brazilian Navy and working on the nuclear-propelled project — identified a ransomware attack at around 23:00 on Sunday 9 August. Data in the IT environment was encrypted: mail servers, systems, files, databases. The company shut the environment down immediately to stop the malware spreading, and brought in specialist firms for a full scan, root-cause investigation, server rebuild and restoration from backup.

Then nothing. The website stayed offline. The company did not respond to the one regional journalist who asked, and has never said publicly whether this was encryption only or whether data was also accessed, copied or transferred. Thirteen days later, on 22 August, the LockBit5 leak site listed the yard’s domain. As of 1 September the company has still issued no statement of its own.

Why it matters: for twenty-two days, the only account of what happened at a state-owned naval shipbuilder came from a regional newspaper the company declined to speak to. The second account came from the attacker. That gap is a supply-chain problem before it is a communications one. Subcontractors, equipment suppliers and classification surveyors downstream cannot assess their own exposure without knowing whether design data or credential material left the network, and the absence of a data-theft denial is not the same as a denial. Anyone sharing a portal, a transfer account or an engineering-collaboration platform with the yard is currently working from a picture written by the people who attacked it.

The exploit was written by a machine, and dressed up as your monitoring software

On 19 August the NSA, CISA, the FBI, the Department of Energy and the Environmental Protection Agency jointly published advisory AA26-231A. Threat actors are conducting reconnaissance and capability development against Siemens PLC installations “using AI-generated exploitation scripts disguised as legitimate monitoring tools.” The method is spelled out: open-source automation libraries — snap7 — combined with AI-assisted scripting to build custom tools that mimic legitimate OT monitoring software, giving read and write access to controller memory, configuration and ladder logic over S7comm on TCP port 102. Targets are found through Censys and ZoomEye. Affected: S7-200, S7-300, S7-400, S7-1200 and S7-1500, including F-series safety controllers.

The agencies say why the AI part matters instead of leaving it as colour: it “dramatically reduc[es] the technical expertise and time required to develop working ICS exploitation scripts and malicious tools.”

Why it matters: the advisory tells a maritime reader two things at once, and both are true. The six sectors named as most targeted do not include transportation — and the advisory’s own opening line says the targeting “is broader than Siemens PLCs” and that all PLC owners should apply the mitigations. S7 controllers run ship-to-shore and yard cranes, lock gates, bunkering and loading skids, ballast treatment and ro-ro ramp hydraulics, and the advisory’s specific warning about third-party integrators with remote access is squarely a port problem: most terminal PLC estates are maintained by an OEM or integrator, and the asset owner frequently does not know which remote paths exist. The vulnerability has not changed. What has changed is how many people can now build a working, disguised tool against it.

The full brief also covers

Subscribers only — the complete analysis ships by email.

Section 1 · Incidents & Attacks
🔒 An eleven-terminal port operator is publicly tied to a ransomware claim by one piece of evidence — a domain name the attacker typed into a field on its own leak site 🔒 The attacker wrote the victim’s company history, got the founding year wrong by twelve years and the town wrong — and threat-intel blogs, breach aggregators and our own source corpus all repeated it before anyone checked 🔒 One marine inspection company, two different ransomware groups, sixteen days apart — and a published unlock timetable aimed at the victim’s clock 🔒 470 GB claimed against the largest independent oil storage terminal in the Mediterranean, then thirteen days of nothing at all 🔒 A maritime procurement marketplace gets listed — and why that dataset is worth more for fraud than for resale 🔒 An extortion crew publishes an essay: “Seven Vulnerabilities of a Canadian Freight Broker. PROLOGUE.” Plus the four listings we checked and threw out, and why a maritime-sounding name is not a maritime nexus
Section 2 · Regulations & Standards
🔒 The IMO published steadily through the fortnight and published nothing on cyber — we read every item and list what it did publish instead 🔒 Why the US Coast Guard section of this issue is labelled a gap in our verification rather than a finding 🔒 Two EU directives that most operators run as separate workstreams, and the reason a regulator will read them as one obligation 🔒 An owner buys multi-path connectivity and files it as compliance evidence — the reframing worth borrowing
Section 3 · Threats — OT/ICS and GNSS/PNT
🔒 A bridge transponder that will take anyone’s word for which vessel it is — CVSS 9.1, all versions, and the vendor stopped making it in 2020, so the patch will never exist 🔒 Seventeen ICS advisories in the window and exactly one maritime — the first in months, and what broke the streak 🔒 Two vendors, one advisory batch, the same day: one issued a fix, the other confirmed there would never be one. The difference was decided at procurement, years earlier 🔒 Two national warnings in one week about the machines at your network edge — and the device class that appears in neither your IT asset register nor your OT one 🔒 A second consecutive fortnight with no dated GNSS incident — and why that is a property of the reporting, not the interference
Section 4 · Ports & Supply Chain
🔒 A satellite operator doubles a constellation to detect exactly the lie that a discontinued transponder makes cheap to tell — and why the defensive side of that exchange always costs more 🔒 Connectivity, IT and cybersecurity bought as one contract across 160 ships — the upside, and the concentration risk that belongs in the contract 🔒 Twenty-six named practitioners from the Cyprus and Greece clusters, one 4 million euro wire transfer, and the numbers in that report you have already read somewhere else
Section 5 · People, Training & Governance
🔒 An owner reports zero incidents for the year — and publishes the testing behind it, including penetration tests onboard, not just ashore. The sentence that separates evidence from wording 🔒 A maritime capture-the-flag whose attack path runs port 5G to power grid to ship OT, built with countermeasures aimed specifically at competitors using AI agents 🔒 A class society argues the future is not a choice between people and technology — and two items in this issue prove the point better than the argument does 🔒 Seafarer morale falls to 6.87 from 7.18, with connectivity listed among fundamental necessities — and why that is a network security finding, not a welfare one

Every locked item carries the same depth as the two above: the pattern behind it, the scale of the exposure, the board-level read, the recommended actions, and where one fits, a tabletop you can run with your team. Every claim cited, every unverified claim labelled as one — including the ones we checked and threw out.

Upcoming maritime cyber events — free

Public events on the forward horizon. No subscription required.

Subscribe

Past issues stay free to read in full. From the June 2026 issue, the complete brief is subscriber-only — each new issue still gets a short free summary.

Monthly
€49/mo
 
  • Full semi-monthly reports
  • Cancel anytime
Subscribe
Semi-Annual
€249/6 mo
€41.50/mo · Save 15%
  • Full semi-monthly reports
Subscribe
Best Value
Annual
€399/yr
€33.25/mo · Save 32%
  • Full semi-monthly reports
Subscribe

Also available in GBP, USD, PLN — select your currency at checkout.