TL;DR too long, didn’t read

  • Rakuten Maritime landed its first full-scale shipyard deployment: built with CYTUR, the Korean vendor whose funding round we covered in Issue #18, the platform is now integrated into Hanwha Ocean's vessels from design through operation.

  • Singapore's fusion centre logged a real jump in AIS deception, with a complicated comparison: 122 incidents in the first half of 2026 versus 6 a year earlier, but a January methodology change inflates that ratio.

  • AIS spoofing resumed in the Strait of Hormuz after attacks on three tankers: close to 40 percent of transits are now running dark, continuing a pattern this newsletter has tracked since spring.

The thread through all three: trust in what a ship is telling you, whether that's its onboard systems or its position on a chart, keeps eroding in different ways in different oceans, and the industry's response is still catching up.

Three things that matter this week

Rakuten Maritime lands its first full-scale shipyard deployment, at Hanwha Ocean

Announced 9 July 2026.

Rakuten Symphony has announced the first full commercial deployment of Rakuten Maritime, its vessel-cybersecurity platform, through a full-scale implementation agreement with Hanwha Ocean, a major South Korean shipbuilder. The deal covers the platform across every stage of a vessel's life: design, construction, and operation, using Threat Intelligence and Threat Modeler tools during design, then Scanner, Threat Analysis, and Risk Manager through production and delivery [rakuten-hanwha]. Hanwha Ocean builds roughly 45 commercial and naval vessels a year at its facility in Geoje, so this is not a pilot on a handful of ships.

Rakuten Maritime launched in December 2024, but this is its first deployment at this scale, and the timing is not a coincidence. The platform is built in partnership with CYTUR, the Korean maritime-cybersecurity vendor whose Series A funding round we covered two weeks ago in Issue #18, and which already held cybersecurity contracts across dozens of Rakuten Maritime-connected vessels before this deal. The announcement leans, like CYTUR's own pitch, on the IACS UR E26/E27 cybersecurity framework, which pushes shipbuilders toward exactly this kind of full-lifecycle, built-in-from-design approach rather than compliance bolted on after delivery.

Why this matters for maritime: this is the regulation-to-capital story from two issues ago showing up as an actual production deployment at a top-tier yard, not just a funding round or a pilot. A platform that can point to Hanwha Ocean, from keel to commissioning, is a different sales conversation than one still proving the model.

What to do: if you are a shipowner or shipyard evaluating E26/E27 compliance tooling, ask vendors for a reference deployment at this scale, not just a roadmap; Hanwha Ocean is now a concrete comparison point. If you sell into the sector, expect "full lifecycle, from design" to become the baseline pitch other vendors have to match.

Singapore's fusion centre logs a real jump in AIS deception, with a complicated comparison

Singapore's Information Fusion Centre (IFC) reported 40 cyber-security incidents across its area of responsibility in June 2026 alone, every one of them involving a vessel transmitting false AIS information. Across the first half of 2026, the IFC logged 122 such incidents, against just 6 in the same period of 2025.

That comparison has circulated as a roughly twentyfold increase, and the raw numbers support the arithmetic. But there is a caveat worth stating plainly rather than burying: the IFC changed its incident-reporting methodology in January 2026, moving from a method-centric count to a target-centric one, which mechanically inflates the year-on-year comparison. That does not mean AIS deception in the Indo-Pacific isn't rising; 40 incidents in a single month is a real, reportable figure on its own. It means the "20x" headline is measuring two different rulers, not one continuous trend line, and it should be read that way.

Why this matters for maritime: this is the same AIS-manipulation pattern this newsletter has tracked in the Baltic and the Gulf, showing up with its own regional signature in the South China Sea and the Singapore Strait, among the busiest and most contested shipping lanes anywhere. A fusion centre built specifically to track this kind of thing logging a genuine rise in a single month is worth watching regardless of how the year-on-year figure is framed.

What to do: if you operate through the IFC's area of responsibility, treat AIS position data as one input, not ground truth, and cross-check against radar and visual reporting in the Singapore Strait and South China Sea specifically. If you cite the "20x" figure yourself, cite the methodology change alongside it; readers and regulators will ask.

AIS spoofing resumes in the Strait of Hormuz as tankers come under attack

6-9 July 2026, Strait of Hormuz.

Attacks on three tankers, Al Rekayat, Wedyan, and Cyprus Prosperity, on 6 and 7 July triggered a fresh wave of disruption in the Strait of Hormuz. AIS spoofing activity, tracked by AXSMarine, resumed on 9 July, and close to 40 percent of Hormuz transits are now running with AIS switched off or falsified, well above the roughly 21 percent baseline, according to S&P Global's Commodities at Sea data.

This newsletter isn't going to relitigate the wider Iran-US conflict driving the attacks; that's a story for other outlets. What belongs here is the cyber layer sitting on top of it: ships going dark or spoofing position through one of the world's most congested chokepoints is exactly the kind of AIS-integrity failure this newsletter has tracked through Hormuz since Issue #15, and it's climbing again.

What to do: if you have vessels transiting Hormuz in the coming weeks, assume AIS data from other traffic in the strait is unreliable by default, not just during acute incidents, and brief bridge teams accordingly.

Test your response: briefing the bridge is the easy part. Making the right call mid-transit, when your own AIS picture is the thing lying to you, is the hard part, and it is worth rehearsing before you are doing it for real. Our free Hormuz Haze mini-tabletop runs a crew through exactly that scenario: play it here →.

In case you missed it

  • Greek police recover €4 million from a shipping company's BEC scam: the fraud, reported to the Hellenic Police's Cybercrime Division in August 2025, diverted funds to a bank account in Bulgaria using a spoofed email address and forged payment orders. Coordinated action with banks and Europol froze the money before it could be moved on; recovery and the identification of two foreign suspects were announced 6-7 July, a genuinely rare good-news outcome in a fraud category that usually just disappears.

  • Marine Electricals (India) Ltd discloses a firewall breach: the NSE-listed company (ticker MARINE), a Tier 1 supplier of navigation and integrated platform management systems to Indian shipyards and the Indian Navy, disclosed a "widespread firewall attack" on 7 July. The company says there has been "no material impact" on operations, and that while the risk of data loss "is considered remote," it "cannot be completely ruled out".

Coming up

  • DEF CON Maritime Village — Las Vegas, 6-9 August 2026.

A quick postscript: the Monaco Energy Boat Challenge wrapped on 11 July. Thank you to everyone who came to the GNSS dark-zones panel on Thursday.

Number of the week

  • 1342 — That is the number of Nacos configuration items encrypted in what Sysdig's threat research team is calling the first publicly documented case of "agentic ransomware": an AI agent that ran reconnaissance, exploitation, and encryption, and wrote its own ransom note, without a human directing each step. The agent, nicknamed JadePuffer, got in through a known Langflow flaw, CVE-2025-3248, then pivoted to a separate production server running Nacos, a configuration-service platform, where it tried one exploit, watched it fail, and issued a corrected payload 31 seconds later. The attack happened in late June, Sysdig disclosed it around 2 July, and WaterISAC flagged it for members on 9 July.

    This is not a maritime story on its face. No shipping company or vessel is involved, and Sysdig has not named the victim. But it belongs here for two reasons. First, an autonomous agent collapses the gap between initial access and impact. The dwell time defenders rely on to catch an intrusion shrinks toward zero when a machine, not a person, decides the next move. Second, maritime OT is exactly the environment where that gap used to be forgiving: patch cycles on shipboard systems run in months, not days, thanks to type approval, OEM lock-in, and read-only filesystems (the reasons Special Edition SE03's "Copy Fail" piece walked through back in May). An attacker that compresses exploit-to-impact from days to hours does not care that your patch window is next quarter. Researchers have been warning about this in the abstract for a while, including the autonomous-AI-worm work we flagged in June. This is the first time it has shown up against a live target.

Scuttlebutt

Unconfirmed signals we monitor, including public leak-site postings not yet confirmed by the named company. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.

  • Single-source, leak-site claim: the Safepay ransomware group listed BMI Projects GmbH, a Hamburg-based supplier of cruise-ship, ferry, and yacht interiors (formerly Bez Marine Interiors), on its leak site on 6 July. Worth flagging with a caveat of our own: the company has been under German insolvency administration since early 2025, which raises a real question about whether this is a fresh compromise of an active business or a leak-site posting against a company already winding down.

  • Single-source, leak-site claim: the Chaos ransomware group claimed Grand Isle Shipyard, a US marine construction and offshore-services firm, on 6 July, alleging 1,1 TB of stolen data with a short negotiation deadline. No confirmation from the company as of this writing.

Resource of the week

Singapore Information Fusion Centre — half-yearly and monthly CYBSEC incident reports

The IFC publishes its own incident counts and methodology notes, which is exactly what you need to read past this week's "20x" headline. If you operate anywhere near the Singapore Strait or South China Sea, the primary reports are worth bookmarking directly rather than relying on secondary write-ups.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"This Is How They Tell Me the World Ends" by Nicole Perlroth — a deep dive into the zero-day market and the arms race behind it. Worth revisiting this week: JadePuffer is a reminder that the tools in that market are increasingly not just being bought and sold, but run by something other than a person.