TL;DR too long, didn’t read

  • FortiBleed put more than 250 maritime, port and energy firms on a credential leak list, and on most of the exposed firewalls nobody had ever renamed the default admin account.

  • CISA confirmed Iranian state-linked actors are reaching into internet-exposed PLCs, the Rockwell, Schneider and Siemens controllers that also run cranes, pumps and lock gates, altering the process while the operator's screen keeps reading normal.

  • CISA flagged satellite terminals used across shipping that answer an unauthenticated request with the terminal's identity and key material.

Three stories, one shape: a firewall, a controller, a satellite terminal, each sitting on the internet where it had no business being. In two of the three, the attacker never needed a password.

Three things that matter this week

Maritime's edge is leaking, and the passwords were never renamed

Cydome's analysis of the FortiBleed credential exposure found more than 250 maritime, port and energy firms in the leaked set. Shipping operators make up about 42 percent of them, offshore contractors about 31 percent, and roughly one in ten are newbuild or ship-repair yards.

Two numbers turn a leak into a breach waiting to happen. Cydome reports that 87 percent of the exposed Fortinet devices still had their management interface reachable from the internet, and 63 percent of the leaked credentials were default admin accounts nobody had renamed.

FortiBleed is not an incident. Not yet: no named victim, no ransom note. It is the step before that. A firewall or VPN fronting a port's terminal operating system, a yard's engineering network, or a fleet's ship-management platform is exactly the foothold ransomware crews and state actors want, and here the front door was standing open with the factory lock still on it. We have been flagging this boundary-device pattern since our first Special Edition. Same story, except this time the credentials are already in someone's hands.

The edge device is the most common way into an OT-adjacent network, and this leak skipped the hard part for the attacker.

What to do: Assume you are on the list until you have checked. Inventory every Fortinet management interface reachable from the internet and take it off the internet. Rotate and rename every default admin account, on the firewall and on everything behind it. If you run a yard, a terminal, or a fleet IT stack on Fortinet gear, treat this as a live credential compromise, not a patch ticket.

The controllers that show the operator a clean screen

On 22 July, CISA and its partner agencies updated advisory AA26-097A with a warning that should stop any port or offshore engineer mid-coffee. Iranian state-affiliated actors, the crew known as CyberAv3ngers and tied to the IRGC, are reaching into internet-exposed programmable logic controllers and manipulating them while the operator's screen keeps showing normal readings.

The update widened the target list beyond Rockwell Automation to Schneider Electric and Siemens: CompactLogix and Micro850, Modicon M340, S7-1200. Those are the same controller families that run cargo cranes, ballast and bunkering pumps, lock gates and offshore process systems.

The technique is the uncomfortable part. These are not exotic zero-days. The actors connect to the PLC over the internet using the vendor's own engineering software (Studio 5000, EcoStruxure Control Expert, TIA Portal), pull down the program logic, alter it, disable the shutdown and alarm interlocks, and leave the human-machine interface reading values that look fine. CISA says affected operators have already taken real operational disruption and direct financial losses, with indicators of compromise dated as recently as this month.

Nothing in the advisory names a ship or a port. It does not have to. The controllers are identical, and the exposure is the one Story 1 just measured: an OT device reachable from the internet. FortiBleed counted 250 maritime firms with the front door open. This is what walks through it.

A manipulated PLC that still reports "normal" is the OT nightmare, because the failure stays invisible until something physical moves the wrong way.

What to do: Take every PLC and its engineering workstation off any internet-reachable path. They belong behind a segmented gateway, never on a routable address. Pull the AA26-097A indicators and hunt for the reusable-code-module changes CISA's update describes. And treat your HMI readings as suspect on any controller that has been internet-facing. A clean screen is no longer proof of a clean process.

The satellite terminal that answers without a password

CISA flagged two vulnerabilities in ST Engineering iDirect's iQ-Series satellite terminals (advisory ICSA-26-183-01, published 2 July), the VSAT gear at the core of shipboard, offshore and defence connectivity. The more serious of the two, CVE-2026-38059, leaves the terminal's management API reachable without authentication, so anyone on the network can pull the device ID and the terminal's private-key identifier: the credential material it uses to authenticate to the satellite network, and enough to impersonate the unit. The second, CVE-2026-38057, is a cross-site request forgery flaw on the reboot endpoint, so one crafted request can bounce the terminal off the link.

A satcom terminal is not a back-office box. It is the pipe between vessel and shore, carrying ECDIS updates, remote monitoring and the crew's traffic. Exposed terminal identity lets an attacker impersonate the unit or interfere with its access. A remote reboot lets them drop the link at a moment of their choosing.

Satellite comms are the least-watched attack surface on most ships, and this one hands over the identity that proves the terminal is who it says it is.

What to do: Find out which VSAT terminals you run and whether their management interface is reachable from the vessel LAN or, worse, from shore. Segment satcom management off the general network, apply the vendor fix, and assume the terminal identity may already be exposed on any unit that has been reachable.

In case you missed it

  • Nichirei's cold chain went down, then came back. Japan's frozen-food and cold-storage giant, with around 140 distribution centres, was hit by a cyberattack on 13 July that disrupted refrigerated logistics nationwide. It announced full recovery on 24 July. The extortion crew RansomHouse has claimed the stolen data; Nichirei has confirmed the attack but not the attacker. Cold chain is maritime's downstream, and reefer boxes, port cold stores and food importers all ride the same links.

  • The Gentlemen v. the US Navy is still a claim. Military Sealift Command has sat on the group's leak site since 17 July, with Ecopetrol added on 19 July, and there is still no confirmation or denial from the Navy. Treat it as an unverified extortion claim until MSC says otherwise, the same discipline we applied to the group's TKMS listing.

  • The SharePoint hole is still open. CISA's remediation deadline for the actively exploited SharePoint deserialization flaw (CVE-2026-58644, unauthenticated remote code execution, CVSS 9.8) passed on 19 July, and responders report continued exploitation of unpatched servers. Plenty of shipping lines and ports keep their document and engineering libraries on SharePoint, and an exposed, unpatched server is an unauthenticated foothold.

  • The compliance surface hardens on two coasts. In Europe, the Netherlands' Cyberbeveiligingswet, its NIS2 implementation, enters into force on 15 August, covering more than 8000 organisations with mandatory NCSC registration and board-level accountability. Ports and logistics are in scope. In the US, the Coast Guard's cyber office clarified on 22 July how the 33 CFR Part 101 Subpart F cyber rules apply to vessels and facilities that already hold physical-security waivers. A waiver on the fence is not a waiver on the network.

  • NATO said it out loud; the Arctic showed what it looks like. On 13 July the North Atlantic Council formally condemned Russia's malicious cyber activity against allies and Ukraine. A week later, open-source analysts tracked two sanctioned heavy-lift carriers, Glory Ocean and Bright Ocean, delivering modules to Russia's Arctic LNG 2 while spoofing their AIS destinations and flying flags of convenience. State-linked maritime deception, running on the navigation data everyone else takes at face value.

Coming up

  • DEF CON 34 and the Maritime Hacking Village — Las Vegas, 6-9 August 2026. The maritime track runs alongside the ICS Village. If you touch shipboard or port OT, it is the one week the people breaking it and the people defending it are in the same room.

Number of the week

  • 81 million — That is how many login attempts one password-spray campaign threw at Microsoft 365 tenants over two weeks, per Huntress. It compromised 78 accounts across 64 organisations, and it worked for one reason: the MFA policies did not cover the legacy authentication path it used. This was cross-sector rather than maritime-specific, but shipping runs its chartering, operations and crewing on Microsoft 365 too. The lesson is not "turn on MFA," because you have. It is "check that MFA covers every way in, including the old ones."

Resource of the week

"Shipyards among firms exposed in FortiBleed credential leak" (Ship & Offshore / Cydome, July 2026) — the breakdown of which maritime sub-sectors landed in the leak and how many devices were still internet-facing. If you want to know whether "250 firms" includes yours, start here.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"The Ransomware Hunting Team" by Renee Dudley and Daniel Golden — the story of the volunteers who quietly broke ransomware for free while the industry looked away. A fitting week for it: FortiBleed is the kind of credential leak that feeds exactly the crews this book is about.

Test your response

This week's edge story has a live drill. Story 1 — a leaked firewall credential is how ransomware gets in — maps to our CMA CGM ransomware mini-gate, a five-minute decision exercise on what you do in the first hour.