TL;DR — too long, didn’t read
Sixty American-flagged ships carry 90 percent of the cargo that sustains U.S. military operations — and the satellite links connecting them to shore were demonstrated wide open in 2020, with no one measuring since.
CISA warned water utilities about attackers entering through cellular modems nobody documented — installed by operators, vendors and integrators, and the same pattern sits on ships and terminals right now.
A Coast Guard essay contest winner argues Washington should reinsure port cyber catastrophes — because private policies exclude exactly the state-backed attacks the sector actually faces.
The thread through all three: none of them is a technology problem. The encryption exists, the modems can be found, the risk can be priced. What is missing in every case is somebody going back to check.
Three things that matter this week
Sixty ships, 90 percent of the cargo, and a five-year-old measurement
The satellite links that sustain American power projection were shown wide open in 2020. Nobody has measured them since.
In March 2025, General Randall Reed, who commands U.S. Transportation Command, told the Senate Armed Services Committee that maritime vessels depend on connectivity to survive in a contested environment. Writing in the July issue of Proceedings, Dr Winnifred Warren takes that statement and asks the obvious follow-up question: is that connectivity actually secure?
The answer, uncomfortably, is that nobody knows.
The Maritime Security Program consists of 60 commercial, American-flagged vessels crewed by American mariners. Between them they carry 90 percent of the cargo needed to project and sustain U.S. military operations. In a Pacific crisis they are the backbone of contested logistics. They also rely on very small aperture terminal satellite systems, and in 2020 James Pavur and colleagues at Oxford showed what that means in practice.
Their equipment cost under 400 dollars, bought off the shelf from satellite television suppliers. With it they intercepted 1,3 terabytes of live maritime VSAT traffic across more than 10 million square miles of ocean. More than 60 percent of the networks they observed transmitted unencrypted by default. The haul included navigation data, cargo manifests, crew correspondence, passport details, over 130 000 unencrypted email sessions and at least 4 million AIS messages.
Then it gets worse, because the link is not just a window. It is a door. The researchers demonstrated man-in-the-middle attacks against ships at sea, and found ECDIS chart updates arriving over unencrypted ftp and http. An adversary able to alter chart data can put a navigator into water they believe is clear.
This stopped being theoretical last year, and not on a warship. In March 2025 a group calling itself Lab Dookhtegan reached into 116 Iranian oil tankers and disabled their communications through VSAT, with what analysts described as full control and elevated credentials across the ships' networks. The laboratory finding became an operational fact on more than a hundred commercial hulls.
The NSA told VSAT operators to encrypt down to and including the outermost vendor-proprietary transmission protocol. That was 2022. Most suppliers still ship with encryption off by default, and the 2020 study remains the only empirical baseline anyone has. Warren's point lands hard: contested logistics in the Pacific is being planned on a measurement that is now six years old.
What to do: Ask your satellite provider one written question — is link-layer encryption enabled on our terminals, yes or no — and keep the answer. Do not accept "our network is secure" as a response, because the Oxford work showed that phrase coexisting with plaintext on the wire. If the answer is no, note that link-layer encryption runs in the modem below the TCP stack and is invisible to crew, whereas the VPN alternative your provider may offer instead can cost up to 70 percent of your throughput. Separately, check how your ECDIS receives chart updates; if the answer is ftp or email, you have inherited a 2020 problem in 2026.
The modems nobody put on the drawing
On 30 July, CISA urged water and wastewater utilities to protect operational technology against activity aimed at their programmable logic controllers. Read the alert as a maritime operator and the detail that should stop you is not the sector. It is how the attackers got in.
They used internet-exposed PLCs, changed passwords to lock operators out of their own equipment, and altered device IP addresses to cut controllers off. But the entry route CISA singles out is undocumented cellular modems — installed by operators, by vendors, and by integrators. Hardware that is physically present, network-connected, and absent from the diagram the security team is working from.
The consequences were not abstract. Utilities issued boil water notices and fell back to sustained manual operation.
One line in the alert deserves reading twice: the targeting covered water entities of all sizes, including those with mature security programmes. Maturity did not help, because a mature programme secures the estate it knows about.
Why this matters for maritime is that this is our exact failure mode, dressed in someone else's uniform. Every engine manufacturer, cargo system supplier and crane vendor wants remote diagnostics. Many install the connectivity themselves, during construction or a yard period, and the owner learns about it years later or never. In April this year a joint advisory documented Iranian-affiliated actors reaching PLCs across American critical infrastructure through vendors' own engineering software. That was AA26-097A, and we covered it in issue 21. Same controllers, same suppliers, different sector, three months apart.
What to do: Run an inventory that assumes the diagram is wrong. Walk the spaces rather than reading the drawings, and look for cellular antennas and modems on switchboards, cranes, engine control rooms and cargo systems. For each one you find, establish who fitted it, who can reach it, and whether anyone would notice if the password changed. Then apply the four CISA mitigations, which cost nothing: take PLCs off the public internet, replace default passwords, allowlist the engineering machines permitted to connect, and hold a known-clean controller image somewhere your integrator cannot reach.
The insurance argument arrives in the Naval Institute
Steven M. Levy took second prize in the Coast Guard essay contest with a piece in the August Proceedings arguing that American ports need a federal cyber insurance backstop. Whatever you make of the policy, the reasoning is the most useful thing I have read this year for anyone who has to fund maritime cyber work.
His starting point is that insurance is where preparedness, recovery and incentives meet. A port hit hard needs money quickly, for responders, workarounds and keeping cargo moving. Insurers have shaped maritime behaviour through premium pricing for centuries; ships sailing pirate waters paid more.
The problem is what the market now excludes. In August 2022 Lloyd's issued market bulletin Y5381 pushing syndicates towards robust wording excluding state-backed cyber attacks. The Government Accountability Office had already warned in 2022 that private cyber insurance may not cover catastrophic losses to critical infrastructure. As of February 2026, Treasury and CISA agreed with that finding but had not acted on it.
So the sector faces adversaries it cannot insure against. Levy cites Volt Typhoon prepositioning in American infrastructure, and the April 2026 advisory on Iranian-affiliated actors in PLCs — the same document behind Story 2. He also quotes an analysis finding hacktivists targeting Israeli-linked vessels through AIS data, Russian groups going after European ports supporting Ukraine, and Chinese state actors compromising classification societies.
His proposal borrows from the Terrorism Risk Insurance Act: insurers keep writing policies and absorbing routine losses, government backstops systemic events. The clever part is the condition. Federal reinsurance would be available only for policies whose terms do not distinguish between state and non-state attacks — killing the incentive to write exclusion-heavy cover that turns into a dispute precisely when a port needs cash.
The part that matters outside American waters is the second half of his argument. A mature insurance market needs verified evidence of risk mitigation, which means independent annual review rather than self-assessment. He nominates maritime as the first sector to try it, on the grounds that it is systemically important, actively targeted, and has fewer networks than healthcare. Whether or not Congress ever moves, underwriters are heading towards demanding audited evidence, and self-assessment is what they are moving away from.
What to do: Pull your cyber policy and find the state-backed attack exclusion, because it is almost certainly there. Then ask your broker the question the wording avoids: who decides attribution, on what evidence, and how long may they take. Attribution routinely runs to weeks or months, and a policy that pays only after it is settled is not recovery funding. If you are trying to get cyber work funded, stop leading with threat and start leading with this — it is an argument for the finance director, in their language, and it survives contact with a board in a way that a threat briefing does not.
In case you missed it
The Coast Guard rule is past its easy deadline: MTSA cybersecurity training was due 12 January 2026. The harder part is next — designating a cybersecurity officer and submitting the cybersecurity plan for approval, due 16 July 2027. Writing in Signal, AFCEA frames the rule as a culture shift rather than a checklist, which is a fair reading of a regulation that makes baseline training universal rather than confining it to IT.
Italy is following the same path: the Ministry of Infrastructure and Transport issued an updated navigation safety circular in December 2025, strengthening cyber risk expectations for national vessels, ship management companies and port facility operators. It comes into force in November 2026, and echoes the themes of the American rule closely enough that operators working both sides of the Atlantic can plan once.
The numbers behind the rulemaking: maritime cyber incidents rose 103 percent in 2025 against 2024, and in the Coast Guard's own 2024 review, 70 percent of breached organisations reported significant or very significant operational disruption.
Coming up
DEF CON 34, Maritime Security Village — Las Vegas, 6–9 August. The maritime village is where ship and port systems get taken apart in public, which is worth watching given Story 1.
DNV Maritime Cybersecurity Summit — Hamburg, 1 September, immediately before SMM Hamburg on 1–4 September.
10th NMIOTC Conference on Cyber Security in the Maritime Domain — Chania, Crete, 23–24 September.
Number of the week
6 years — that is how long it has been since anyone published a measurement of encryption on maritime VSAT networks. The 2020 Oxford study is still the only empirical baseline, and it found more than 60 percent transmitting in the clear. Every plan built since rests on the assumption that somebody fixed it.
Scuttlebutt
Unconfirmed signals from open-source and regional channels we monitor. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.
Single-source: A leak site listed L3Harris, the aerospace and defence supplier, as a victim in the last days of July. We are flagging it only because defence electronics sits upstream of naval and sealift communications, which is the subject of Story 1. Nothing is confirmed, the company has said nothing publicly, and leak-site listings are frequently wrong or recycled. Treat as a claim.
Single-source: The same class of channels listed CEN and CENELEC, the European standardisation bodies, at the start of August. Relevance here is indirect but real: these organisations draft standards the sector builds against. Again a claim, unconfirmed, and worth nothing more than watching.
Resource of the week
"A Tale of Sea and Sky: On the Security of Maritime VSAT Communications" by James Pavur, Daniel Moser, Martin Strohmeier, Vincent Lenders and Ivan Martinovic (IEEE Symposium on Security and Privacy, 2020)
This is the paper underneath Story 1, and it is worth reading rather than taking second hand. The method is documented well enough that you can explain to a superintendent, without hand-waving, how 400 dollars of consumer equipment produced a live feed of shipping movements. It is also short on drama, which makes the findings harder to dismiss.
Want more depth?
Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.
Read of the week
"The Cuckoo's Egg" by Cliff Stoll — an astronomer notices a 75-cent accounting error, refuses to write it off, and pulls on the thread until it reaches a foreign intelligence service. Nearly forty years old and still the sharpest account I know of the habit this issue is about: going back to check the thing everyone assumed was fine.
