TL;DR — too long, didn’t read

One of the world's largest transhipment hubs was hit, stopped itself, and had confirmed it publicly before the attackers got round to announcing it. Four other maritime names from the last three weeks have still said nothing at all. And a satellite terminal that is often the only link a vessel has turns out to need no stolen credential to take over, because the account an attacker would use ships from the factory.

Panama, a correction, and how to actually get in

Two weeks ago this newsletter said that registration for the Friday exercise at the Universidad Marítima Internacional de Panamá "is opening on their side now". That was what we understood at the time. It has not opened. There is still no registration link and no public announcement of the event, ten days out.

What is true: the exercise runs on Friday 25 September, 09:30 to 15:30, at UMIP in Panama City, it is a full day, it needs no technical background, and places are limited by the size of the room, not by a form. Attendance is arranged by UMIP, not by us, and the honest instruction is the unglamorous one: if you are in the region and this is your work, write to the university and ask. We will say so here the moment anything changes.

We are telling you this in an issue about who puts things on the record and when. It would be a poor issue to write while quietly leaving our own sentence from a fortnight ago standing.

Three things that matter this week

The port spoke before the attackers did

At 23:34 local time on Tuesday 9 September, the Port of Tanjung Pelepas detected a cybersecurity incident in its terminal operating systems. What happened next is the part worth your attention: PTP isolated the affected systems as a precaution and suspended container terminal operations. A phased restart began the following day.

This is not a small port. PTP moved more than 14 million TEU in 2025. The wider Johor complex, which includes PTP and Johor Port's terminal at Pasir Gudang, handled a record 15.1 million. It is a principal node in the Gemini Cooperation network operated by Maersk and Hapag-Lloyd, and PTP itself is a joint venture between AP Møller Maersk and the Malaysian group MMC.

On Thursday 11 September the incident became public, and it became public from the people it happened to. Lloyd's List reported PTP's own confirmation at 10:15 UTC. By 11:26 UTC a Maersk spokesperson had gone on the record with The Loadstar: the affected systems were restored, operations were progressively resuming, some vessels might see delays.

At 15:54 UTC the same day, a group calling itself Direwolf posted PTP to its leak site, claiming 200 gigabytes. That claim is the attackers' and nobody has verified it.

Five hours and thirty-nine minutes separate the two. For four issues running, this newsletter has been reporting the reverse sequence: a name appears on a leak site, and the organisation says nothing, for weeks. Here the organisation had already spoken, and the leak-site entry arrived into a story that was public.

It is worth being precise about why. PTP did not choose candour over silence in the abstract. It stopped a terminal that moves close to forty thousand TEU on an average day, inside a network whose partners have customers expecting boxes. A halted quay cannot be kept quiet, and a carrier with a berthing schedule will say something whether the terminal does or not. The decision that made the disclosure inevitable was the decision to stop.

What to do: Ask who in your organisation is allowed to stop the operation, and whether that person needs anybody's permission at 23:34. Then ask the second, harder question: if they did stop it, who tells your customers, and how long after. At PTP those two answers were close enough together that the attackers were overtaken by them. Most organisations have a plausible answer to the first and no answer at all to the second, and discover it in the hour when both are needed.

Test your response: your terminal operating system is encrypted overnight and the quay is stopped by your own decision. The first carrier calls at 06:00 asking what to tell its customers. What do you say, who approved it, and is it written down anywhere?
Port of San Diego: When Ransomware Meets the Harbor →

Four names, three weeks, nothing said

The contrast is the story. We have been watching four maritime organisations named on leak sites since late August, and this week we checked all four again.

TEC Container was named on 26 August. Globalport Terminals on 27 August. Three weeks. Nothing from either, no coverage in the trade press, no change to their public sites.

AMPTC was named on 1 September. Two weeks. Nothing.

The Philippine Ports Authority, a state port administration identified through the victim-domain field as www.ppa.com.ph, was named on 5 September. Nine days. Nothing.

Put beside Story 1, this stops being a story about candour and becomes a story about visibility. None of these four organisations had a quay stop in a way that a shipping line would have to explain to its own customers. PTP did. The variable that predicts disclosure here is not the severity of the breach, and it is not the culture of the organisation. It is whether anything visible stopped moving.

That is an uncomfortable finding, because it means the public record of maritime cyber incidents is shaped by operational visibility instead of materiality. The incidents that interrupt a berth get written down. The ones that take an administration's back office, or a container equipment supplier's network, do not. Those are precisely the ones that sit upstream of everybody else.

What to do: Make a list of the third parties whose failure would not be visible to you: the agency that clears your cargo, the supplier that maintains your equipment, the firm that holds your drawings. For each, write down how you would find out. If the honest answer for most of them is "we would read about it", you have found the shape of your own blind spot, and it matches the shape of this week's silence.

Test your response: an audit asks you to demonstrate that you would know within seven days if a critical supplier had been breached. What do you show them?
NIS2 Nightmare: The Audit That Turned Into a Crisis →

The account that ships from the factory

On 10 September CISA published Update A to advisory ICSA-26-183-01, covering ST Engineering iDirect iQ-Series terminals. Four vulnerabilities, highest CVSS v3 8.8, affecting Evolution iQ-Series, 3315-Series and 9-Series terminals at version 4.5.2.1 and below. The classes are unglamorous and familiar: missing authentication for a critical function, cross-site request forgery, missing authorisation, exposure of sensitive system information.

The following day, the National Vulnerability Database published the detail on one of them, CVE-2026-38056, and the detail is the reason this is a story and not a line in a bulletin.

The device is the iQ200, a rackmount satellite modem. NVD's own description places it "across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites". And then it explains what an attacker needs:

❝

"the device ships from the factory with a pre-configured low-privilege local user account… This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced."

This is not a default password somebody forgot to change. It is an account the manufacturer put there deliberately, for field technicians who need shell access, and it is the first rung of a ladder that ends in full control of the box through which a vessel talks to the world.

One thing we are not going to do. A group calling itself Metaencryptor listed ST Engineering on its leak site on 7 September, and we flagged it here last week at low confidence because the maritime connection was our inference, and the listing itself said nothing about ships. This week's advisory settles the maritime question: the company's terminals sit on ships and rigs, and a regulator has said so. It settles nothing whatsoever about the ransomware claim, and the two things are unrelated as far as anybody has shown. We are reporting them in the same story because they concern the same company in the same week, and for no other reason.

What to do: Find out which satellite terminals you actually have, at what firmware, and who can reach their management interface. On most vessels this is a question nobody owns: the box was installed by the connectivity provider, it is maintained remotely by them, and the operator has no inventory line for it. If the terminal is your only link, its compromise is not a connectivity problem, it is a complete loss of the vessel's ability to tell you anything.

Test your response: a flag-state inspector asks who has administrative access to the satellite terminal on your vessel and when its firmware was last updated. How long before you can answer, and does the answer come from a record or from a phone call to the supplier?
MSC.428 Inspection: When the Flag State Finds Your Secrets →

In case you missed it

  • The US House Transportation and Infrastructure Committee announced a mark-up of bills to strengthen maritime transportation cybersecurity (11 September). Read alongside last week's story about the Coast Guard standing up an Office of Maritime Cybersecurity Policy, the sequence over fourteen months now runs: rule in force, office created, career path defined, legislation drafted.

    The Coast Guard's digital mariner credentialing platform is set to go live (11 September), a reminder that the same organisation writing your cyber rules is also digitising the documents that put people on ships.

Coming up

  • 24–25 September, Panama City. World Maritime Day at UMIP, and the full-day exercise the following day. See the note at the top of this issue about how to attend.

Full calendar, with cyber tracks flagged: https://mc3.maritime-ogmios.tech

Number of the week

  • 5 hours 39 minutes — the gap between the Port of Tanjung Pelepas confirming its incident publicly and the attackers publishing it. For four issues this newsletter has measured that gap in weeks, in the other direction.

Scuttlebutt

Unconfirmed signals from open-source and regional channels we monitor. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.

Last week's item is settled, and it is in Story 3 above. ST Engineering's maritime relevance is now established by a CISA advisory, not by our guesswork, which is the outcome we said we wanted. The ransomware listing itself remains unremarked by the company and unverified by anybody.

No new item this week. One leak-site listing in the window (Akira, 9 September) carries a name we could not tie to maritime operations with any confidence, and an entry we cannot stand behind is worth less than an empty section.

Resource of the week

The description field on an NVD entry

Most people read a vendor advisory or a CVSS score and stop. The advisory for this week's iDirect vulnerabilities tells you the severity. It does not tell you that the affected device is often the only communications link a vessel has, or that the account an attacker needs comes pre-installed. Both of those sentences are in the NVD description, written by whoever submitted the CVE.

It is free, it is thirty seconds, and on operational technology it is regularly the only place where somebody has written down what the box actually does for a living.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"Ransomware and Cyber Extortion: Response and Prevention", by Sherri Davidoff, Matt Durrin and Karen Sprenger, 2022.

The practitioner reference on the whole lifecycle: initial access, dwell time, exfiltration before encryption, negotiation, payment mechanics, recovery. It is one of very few books that gives the negotiation itself a method of its own, instead of treating it as a moral question.

Relevant this week for the unfashionable chapters: what you say, to whom, and when. Both halves of this issue, the port that spoke in hours and the four that have not spoken in weeks, are decisions this book has a framework for.