TL;DR — too long, didn’t read

  • The US Coast Guard has stopped writing maritime cyber rules and started building the machine that enforces them: a dedicated policy office, and three days later a qualification insignia, which is how an institution signals that it expects to be doing this for a long time.

  • Two maritime organisations were named on leak sites in five days, and we cannot find a word from either: a tanker owner and the national ports authority of the Philippines. This is the fourth issue running in which the sector's answer to being named publicly is silence.

  • A Norwegian car carrier operator signed a five-year contract to fit its fleet with an independent source of position: the technology is the ordinary part; the notable part is that GNSS interference got through an approval process as a budget line.

The thread through all three: an institution, an operator and two victims each had a chance this week to put something on the record, and only two of them took it.

Two and a half weeks out: Panama

On 25 September I am running a cyber incident exercise at the Universidad Marítima Internacional de Panamá, with MTCC Latin America, as part of World Maritime Day. Five teams, one incident, six decisions. I flagged my commercial interest in this two issues ago and I will keep flagging it while it is on the calendar.

One honest note about expectations, because it belongs in a newsletter that asks other people to be candid. I asked people who know the region whether there is real appetite there for this kind of work. The answer I got back was that it is early: the topics are not yet widely understood across the sector, and institutions tend to handle them inside their own technical structures rather than together. So we are going there to listen and to measure, not to sell anything, and I would rather learn that in September than keep guessing from Poland.

Whatever that room teaches us, I will write it up here, including the parts that do not flatter us.

Three things that matter this week

The United States built an office for this

US Coast Guard announcement, 1 September 2026. Reported by SecurityWeek, ExecutiveGov and others the same week.

On 1 September the Coast Guard established the Office of Maritime Cybersecurity Policy, CG-MCP, sitting under the Director of Inspections and Compliance. In the service's own framing it is the central authority for policy on the cyber safety and security of the Marine Transportation System, and the primary liaison with industry and with other agencies. Its listed jobs run from domestic policy to contributing to international standards to directing a coordinated compliance and enforcement strategy. That last word is the one to notice.

Three days later the same service introduced a Cyberspace Qualification Insignia, a wearable mark for people who have completed the cyber qualification track.

Either one on its own is a press release. Together they say something more specific. An office placed under Inspections and Compliance is where enforcement policy gets written, not where research gets done, and an insignia is how a uniformed service tells its own people that a specialism has become something you train into, wear, and get promoted for.

This matters well beyond American jurisdiction, because the rule those people will be enforcing is already in force. Title 33 of the Code of Federal Regulations, section 101.650, took effect on 16 July 2025. It binds US-flagged vessels and US port facilities, and two of its requirements are unusually specific:

❝

Multifactor authentication must be implemented on password-protected IT and remotely accessible OT systems.

❝

Monitor and document all third-party remote connections to detect cyber incidents.

The second of those is unusual. Plenty of frameworks tell you to control vendor access; this one tells you to keep the receipts, and it does so in the language of a requirement. The compliance clock is already running: personnel training was due by 12 January 2026, and the Cybersecurity Assessment is due by 16 July 2027 and annually after that.

Line the sequence up and it covers fourteen months: the rule takes effect, an office appears to enforce it, and a career path appears to staff the office. Nobody builds in that order while still deciding whether to bother.

What to do: If any part of your operation touches a US port facility or a US-flagged hull, find out who owns 33 CFR 101.650 inside your organisation, and specifically who is responsible for the record of third-party remote connections. If the honest answer is that nobody is producing that record, that is the finding, and it is cheaper to discover now than during an inspection by somebody wearing a new insignia. If you are outside US jurisdiction entirely, read the text anyway: it is the most concrete public statement anyone has made about what supervising vendor access is supposed to look like.

Test your response: an inspector asks for the log of every third-party remote connection into your OT in the last ninety days. How long does it take, and how much of it is reconstructed from memory? USCG Cyber Drill: The Final Rule Reality Check →

Two named in five days, and nobody is saying anything

Leak-site listings, 1 and 5 September 2026. Verified against the victim-domain field, not the headline.

On 1 September a group calling itself Krybit listed the Arab Maritime Petroleum Transport Company, victim domain amptc.net. AMPTC is a tanker owner set up in 1972 as a joint Arab venture, and it operates product and LPG carriers. On 5 September the Qilin group listed the Philippine Ports Authority, victim domain www.ppa.com.ph, the state agency that operates and regulates the country's public ports.

Both of those identifications come from the domain recorded against the listing rather than from the name in the post, which is a distinction worth keeping. Attackers get names wrong, and similarly named companies exist in every jurisdiction. The domain is the part that decides who is actually being claimed.

What we can say: two organisations at the centre of maritime trade in two different regions were publicly claimed within five days. What we cannot say: whether either claim is true. Qilin published no description of its victim at all. AMPTC's website is up and running normally with nothing on it about an incident. We have found no statement from either organisation and no coverage in the maritime trade press we monitor.

That absence is why this is a story and not a line in Scuttlebutt. It is the fourth issue in a row in which the pattern is identical: a maritime name appears, the sector says nothing, and the only public account of what happened is the one written by the people claiming to have done it. Over the twelve weeks to 4 September we counted seventeen maritime organisations named across ransomware leak sites, out of 2,821 victims listed in total. Not one of those seventeen listings was accompanied by a public statement from the organisation named.

The reasons for silence are usually good ones taken individually. Lawyers advise it. Insurers advise it. An unconfirmed claim answered publicly can turn a bluff into a headline. The aggregate is harder to defend. An entire sector has handed the first draft of its own incident history to criminals. Everyone downstream reads that draft, including the people deciding whether to call at your terminal next month, because nothing else exists.

What to do: Decide now, in writing, what you will say if your organisation's name appears on a leak site tomorrow and you do not yet know whether it is true. The decision you want to avoid is the one made at 22:00 by whoever is awake. Then ask the same question outward: if a terminal you use, or an agency that clears your cargo, is named this week, what is your process? Most companies have no answer and default to waiting. Waiting is a decision too, and it is the one you will have to explain afterwards.

Test your response: a supplier you depend on is named on a leak site. They say nothing for a week. What do you change in the meantime? CMA CGM: Ransomware in the Container Kingdom →

Somebody put a duration and a budget on GPS interference

Höegh Autoliners announcement, 1 September 2026, confirmed on the company's own news page. Reported alongside a supplier announcement, and read here with that in mind.

Höegh Autoliners has signed a five-year contract with the Norwegian company SGM Technology to fit its fleet with PntGuard, described as providing an independent source of position when satellite navigation is disrupted and alerting the bridge when interference is detected. Trade coverage puts the fleet at 38 vessels with future newbuildings included; the company's own announcement says the entire fleet without giving a number. The waters named in the coverage are the Baltic, the Black Sea, the Red Sea, the Arabian Sea, the Persian Gulf and the eastern Mediterranean.

Two caveats first. It reached us as a customer-win announcement, which is a marketing artifact, and both parties benefit from you concluding that everyone needs one. And we have no visibility into why Höegh bought it: not the business case, not the price, not whether a customer asked for it. So we are not going to tell you what the company believes about the future, because they have not said, and it is not ours to invent.

What is on the record is narrower than a trend, and more useful. Somebody attached a duration and a budget line to GNSS interference.

That is unusual here. Most of the industry handles jamming and spoofing the way it handles weather: you report it, you work around it, you write it up afterwards, and nobody is ever asked what it costs. Getting a multi-year fleet-wide contract through an approval process is a different kind of activity. It requires somebody to describe the problem in terms a finance function will accept, and to defend that description against everything else competing for the same money. Their reasoning might have been about permanence, or insurance, or a customer asking, or plain prudence. We do not know, and we are not going to pretend otherwise. What we can see is that it got through.

For everyone else, forget whether to buy the same thing. Ask instead whether your own organisation could describe this risk in those terms if it had to, or whether GNSS interference currently sits in your reporting as an operational annoyance with no owner, no number and no line in any budget.

What to do: You do not need to buy anything this quarter to act on this. Ask your masters on the routes above what they currently do when the position looks wrong, and write the answers down. If the procedure is "cross-check with radar and visual", that is a real procedure, and it deserves to be trained and timed instead of assumed. If the answer varies by master, you have found the actual gap, and it is a cheaper one to close than the equipment.

Test your response: the position on the display and the position by radar have disagreed for twenty minutes in a busy strait. Who decides which one the ship is navigating on, and how is that decision recorded? Hormuz Haze: The Tanker That Couldn't See, Couldn't Stop, Couldn't Call →

In case you missed it

  • The US and the Philippines widened their maritime agenda, with the coast guard adding a cyber component. Reported on 6 September, one day after the Philippine Ports Authority was named on a leak site. The two are unrelated as far as anybody has said, and the coincidence of timing is worth noticing only because it is the kind of thing that gets connected later by people who were not paying attention at the time.

  • Inmarsat published three years of distress-call data, and within a day one number in it was already being misquoted. Inmarsat Maritime launched a Maritime Safety Data Hub on 1 September, built with the analysts at SeaFocus on three years of GMDSS data plus 106 975 maritime safety broadcasts transmitted during 2025. Weather accounted for 84.6% of urgent messages, storms for three quarters of the weather hazards. Further down: container ships were the fifth-highest vessel type by number of distress calls, at 54, and were also subject to GPS spoofing. By the next morning that had become a headline reading "Container ships made 54 GMDSS distress calls in 2025 amid rising GPS spoofing". The 54 is real and checkable. The word "amid" is not: Inmarsat reported two findings side by side, and one hop of republishing turned them into cause and effect.

  • COSCO and the concealed-equipment allegations. US officials accused the Chinese shipping group of carrying equipment to gather military intelligence; COSCO denied it on 5 September. We are not covering it, because this newsletter stays out of state-versus-state disputes, and saying so is more honest than quietly omitting the biggest maritime story of the week.

Coming up

  • ION GNSS+, Orlando, 14–18 September. The navigation community's own conference. Not a maritime event, which is exactly the reason to watch it: the jamming and spoofing work presented here reaches shipping about a year later. Given this week's third story, it is the most relevant week on the calendar.

  • 10th NMIOTC Conference on Cyber Security in Maritime, Chania, 23–24 September, and CS4CA Europe, London, the same two days. Still an unfortunate clash if you were considering both.

  • World Maritime Day, Panama, 24–25 September. As above. The Thursday is the World Maritime Day programme; the exercise runs on the Friday, 09:30 to 15:30, and registration goes through UMIP.

  • Maritim Cyber Security, Ålesund, 29 September and ShipIT, Athens, the same day. Both dedicated maritime cyber events, both single-day, at opposite ends of Europe.

Full calendar, with cyber tracks flagged: https://mc3.maritime-ogmios.tech

Number of the week

  • 5 years — the length of the contract Höegh Autoliners signed for independent positioning across its fleet. We have run a lot of jamming stories, and almost all of them described an event that happened on a particular day. This is the first one we have covered that describes a procurement decision with a term attached to it. We are not going to guess what that says about the next five years, because that is the company's business and they have not told us. The part worth borrowing is narrower: somebody found a way to describe this problem that a finance function accepted. Anyone who has tried and failed to get it funded knows how hard that is.

Scuttlebutt

Unconfirmed signals from open-source and regional channels we monitor. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.

One item, at low confidence, and the caveat matters more than the item.

  • ST Engineering was listed on a leak site on 7 September by a group calling itself Metaencryptor. The Singapore group is large and does build and repair ships, which is why it is here at all. But the attacker's own description of the victim lists aerospace, smart city, defence and public security, and does not mention marine. So the maritime nexus is ours, not theirs, and it may not survive contact with the facts. No statement from the company, no second source, nothing published yet. We will settle it next week either way.

Nothing flagged in #26 remains open. Both items we carried last week were settled and taken off the board in that issue.

Resource of the week

The victim-domain field on leak-site trackers

A small habit that saves you from a bad week. When a ransomware group names a victim, the name in the post is frequently wrong, abbreviated, or shared with an unrelated company on another continent. Public leak-site trackers record the domain associated with the listing separately from the name, and that field is the one to read. This week it is what let us say that the Philippine listing points at www.ppa.com.ph, the state ports agency, rather than at some similarly named private firm.

If you take one thing from this: before you forward an alert saying that a named company has been breached, open the listing and look at the domain. It takes fifteen seconds, and it is the difference between a warning and a rumour with your name on it.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"The Dark Art and Science of GPS Spoofing" (2nd edition, 2025) by Gareth Morgan Thomas — a book-length treatment of the subject underneath this week's third story: how spoofing actually works, why states do it, and documented cases including the Black Sea incidents. If your reading of the Höegh contract is that somebody made a large bet about the next five years, this is the material they were betting on. It is on our list under Satellite & Navigation Security, alongside three others on the same shelf.