TL;DR too long, didn’t read

  • A ransomware group claims it breached the US Navy's Military Sealift Command, with ITAR documents, ESSM cargo manifests, and vessel blueprints allegedly in hand, but neither MSC nor the Navy has confirmed anything, and the same group's own track record suggests most of its claims don't hold up.

  • The European Commission referred Ireland, Spain, France, and the Netherlands to the EU's top court over NIS2, the first cases of their kind, covering four of Europe's largest port states.

  • Singapore's MariOT testbed demonstrated a steering-control compromise on real shipboard hardware that put a vessel on a collision course in a way a bridge team could easily mistake for ordinary equipment failure.

This was the week the leak sites went to sea: three maritime targets showed up on ransomware and extortion listings, and not one of them has been confirmed by the named victim. A listing is not the same thing as a breach.

Three things that matter this week

The Gentlemen claims Military Sealift Command — still nothing from the Navy

Leak-site posting, 17 July.

The ransomware group The Gentlemen posted a listing claiming Military Sealift Command, the US Navy's civilian-crewed sealift and logistics arm, as a victim. The post says the group holds "ITAR documentation, personal data, cargo manifests—including ESSM shipments—vessel blueprints, and both disclosed and undisclosed information," and threatens publication "if you do not get in touch in the near future." The group also claims to have already reached three MSC employees by name, who allegedly dismissed the matter as a joke.

MSC operates roughly 125 civilian-crewed ships and moves Department of Defense cargo worldwide; ESSM refers to the Evolved Sea Sparrow Missile. If the documents are what the group says they are, this would expose a slice of the defense-logistics supply chain that most ransomware claims never touch.

That "if" is doing real work. As of 20 July, the claim has been picked up by multiple trackers (ransomware.live, Breach House, GalaxyWarden, RecentBreaches), but that's the same claim propagating, not confirmation. Neither MSC nor the US Navy has said anything publicly. Some context worth holding onto before taking the listing at face value: The Gentlemen posted around 19 victims in a single day on 16 July, across 13 countries, mostly mid-sized firms, a mass-dump pattern that looks more like volume than precision targeting. The group's own backend was compromised in May, when its internal Rocket.Chat leaked; the resulting analysis (Check Point's "Thus Spoke The Gentlemen," picked up by ransom-isac) found only 66 of the group's 400-plus claimed victims independently confirmed. And this isn't the group's first defense-sector claim: it named TKMS/Atlas Elektronik back in Issue #17, in late June, a claim that remains unconfirmed weeks later. That makes MSC the second naval or defense target this group has claimed in about five weeks, with none of them verified yet.

We're treating this exactly the way we treated TKMS: a claim, not a breach, until someone other than the attacker says otherwise. Both readings stay on the table. If it's real, it's a serious supply-chain exposure. If it's inflated or fabricated, it's a case study in how much noise leak sites generate now.

What to do: if your business sits anywhere in the defense-maritime supply chain, assume you're a target regardless of how this specific claim resolves; that exposure doesn't depend on the Navy confirming this one post. Don't treat a leak-site listing as proof of anything on its own, but do make sure you have an actual procedure for the day your own company's name shows up on one, because that day won't come with a confirmation from the attacker either.

Test your response: the first 24 hours after your company's name shows up on a leak site, or a ransomware note lands in your inbox, is not the time to improvise a response for the first time. It's worth rehearsing before it happens for real. Try our free CMA CGM-inspired ransomware mini-tabletop, a short scenario built around the 2020 attack on CMA CGM, one of the world's largest container carriers: Run the mini-tabletop →

European Commission refers Ireland, Spain, France and the Netherlands to the CJEU over NIS2

Announced 8 July 2026. This one slipped past us in last week's cycle — it deserves coverage even a week late.

The European Commission has referred four member states, Ireland, Spain, France, and the Netherlands, to the Court of Justice of the EU for failing to fully transpose the NIS2 Directive into national law. These are the first NIS2 cases to reach the Court. The Commission is asking for financial sanctions: a lump sum plus daily penalties that continue until each country notifies full transposition.

The timeline runs back nearly two years: the transposition deadline was 17 October 2024, the Commission sent formal notices on 28 November 2024, reasoned opinions went out to 19 lagging states on 7 May 2025, and the four states still short of full transposition were referred to the Court on 8 July.

The maritime angle here isn't subtle. Water transport is an Annex I essential sector under NIS2, and the four states referred include some of Europe's largest port states: the Netherlands (Rotterdam), France (Le Havre and Marseille), Spain (Valencia and Algeciras), and Ireland (Dublin). One detail worth noting: the Dutch parliament's upper house, the Eerste Kamer, passed the Cyberbeveiligingswet, the Netherlands' own NIS2 transposition law, on 7 July — roughly 48 hours before the referral was announced.

What to do: if you operate in any of these four countries, NIS2 obligations are arriving regardless of where national legislation stands, and now with a court case and political attention attached. Don't wait for the domestic law to pass before treating the directive's requirements as real.

Singapore's MariOT shows a cyberattack can look exactly like equipment failure

Digital Ship, 16 July.

MariOT, the Maritime Testbed of Shipboard Operational Technology, was commissioned by Singapore's Maritime and Port Authority and developed by iTrust, the cybersecurity research centre at the Singapore University of Technology and Design. Unlike most maritime-cyber training, MariOT runs on real shipboard hardware, combined with hardware-in-the-loop and simulation, not software alone.

In one demonstration, researchers recreated a cyberattack that compromised a vessel's steering control during a simulated voyage. The compromised steering put the ship on a course toward collision with an anchored vessel, exactly the kind of outcome a bridge team might read as a mechanical fault rather than an attack. "Systems may appear to function normally even when they have been compromised," said Dr Awais Yousaf of iTrust. As Digital Ship's reporting put it: a cyber incident could be mistaken for equipment failure.

MariOT has trained 35 participants, a mix of C-level executives, seafarers, and cybersecurity practitioners, since its inauguration in March 2025, running a three-day programme built around an oil-tanker model. An expansion beyond that single vessel type is planned. Singapore shows up here for the second week running, after the Information Fusion Centre's AIS-deception numbers in Issue #19.

What to do: when you're evaluating maritime cyber training or testing vendors, ask specifically whether their exercises run on real hardware-in-the-loop or purely on software simulation; the two teach different things. And if your crew has never been asked to distinguish a cyberattack from an equipment fault during a drill, that's a gap worth closing before MariOT's steering-compromise scenario shows up somewhere that isn't a testbed.

In case you missed it

  • NCSC UK and 18 partner agencies call out FSB Centre 16 for scanning weak routers across critical infrastructure: the joint advisory, covering 12 countries, describes Centre 16 (also tracked as Berserk Bear or Static Tundra) internet-scanning for poorly configured or default SNMP and Cisco Smart Install setups across communications, defence, energy, and other CNI sectors globally. The UK imposed sanctions alongside the advisory and specifically called out an FSB attack on Poland's energy grid. Boundary devices, routers and other edge gear sitting at network perimeters, are a thread this newsletter keeps returning to, and they're still exactly where attackers are looking.

  • A commercially available chip brings cryptographically secured PNT over Iridium: the new ASIC, 8 by 8 millimetres and under 0.2 grams, delivers timing and location data authenticated through the Iridium satellite network rather than GNSS alone. More than 150 organisations across maritime, drones, aviation, and telecoms have expressed interest since an October 2025 preview, and the first integration, Solace Communications' Vector product, combines it with multi-band GNSS, inertial sensing, LTE, and Iridium SBD into what Solace calls continuous confidence scoring. Read it as one answer the market is offering to the GNSS-jamming problem that has run through these pages since the spring.

Coming up

  • DEF CON 34 — Las Vegas Convention Center, 6-9 August 2026. The Maritime Hacking Village is confirmed to return, in collaboration with the ICS Village.

Number of the week

  • 19 — that's how many victims The Gentlemen posted to their leak site in a single day, on 16 July, spread across 13 countries and mostly mid-sized firms. It's the number worth holding in mind while reading this week's Military Sealift Command claim from the same group: a leak site that can produce 19 new victim postings in 24 hours is optimised for volume, and volume is not the same thing as confirmed breaches. The group's own numbers show the gap between claiming and confirming: after The Gentlemen's internal infrastructure leaked in May, independent analysis of their claimed victim list found only 66 of more than 400 claims independently confirmed. Whatever MSC turns out to be, it's one listing among hundreds, most of which nobody has verified.

Scuttlebutt

Unconfirmed signals we monitor, including public leak-site postings not yet confirmed by the named company. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.

  • Single-source, leak-site claim: the DragonForce ransomware group listed Asian Marine Services PCL (ASIMAR), a Thai shipyard listed on the Stock Exchange of Thailand with more than 35 years in shipbuilding, ship repair, and steel fabrication, on 14 July. FalconFeeds reported the claimed volume at 64.12 GB. No statement from the company as of 20 July. This extends a shipyard thread we keep seeing: Brodosplit and Piriou late last year, Grand Isle Shipyard in Issue #19, and now ASIMAR alongside this week's MSC claim — leak sites are leaning hard into shipbuilding and naval targets right now.

  • Single-source, leak-site claim: the Nova group listed "Dephub," which the posting identifies as Indonesia's Directorate of Shipping and Maritime Affairs, part of the Ministry of Transportation, on 19 July, giving the directorate's Jakarta address. There are no samples, no stated data volume, and no deadline in the listing. It's the thinnest-documented claim of the week; we're flagging it mainly because the target is maritime-specific, not because the evidence is strong.

Resource of the week

Gard, "AIS-assisted collisions: The risks of over-reliance" (14 July)

It's written by a practitioner rather than a vendor — the author has been a seafarer, a VTS supervisor, and a casualty investigator. The piece argues that "over-reliance on AIS may, in some cases, contribute to incidents rather than prevent them." It picks up the AIS-integrity thread from Issue #19 on the navigational side rather than the geopolitical one: AIS can fail or mislead without anyone spoofing anything at all.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"The Cuckoo's Egg" by Cliff Stoll — the original account of hunting an intruder through military and scientific networks, sparked by a 75-cent accounting discrepancy nobody else thought was worth chasing. It fits this week: a claim against a military logistics network is exactly the kind of thing somebody has to go and check for themselves.