TL;DR — too long, didn’t read
ENISA named the group: Mustang Panda ran espionage campaigns against maritime organisations in the EU throughout 2025, often through USB media. The "seven member states" the coverage repeated has no source in the report; the "four" thirty-six pages later does.
The Philippines named the ship: Jia Hai Ke 7's AIS put her off Papua New Guinea hours after she left Xiamen. The Coast Guard found her holding station near the cable corridors off Batanes.
The FBI named neither, and said the most useful thing: attackers inside an industrial integrator's network searched for "customers" and "SCADA". The fact sheet asks whether you could run without your integrator.
The thread: after three issues about silence, public bodies spoke this week, and each named something different. None of them named everything, which is why the details matter.
Panama: what happened, and one correction
Last issue gave you the time of our Thursday session at the Universidad Marítima Internacional de Panamá (UMIP): 08:40 to 10:10. That is not what happened. The conference programme changed in the final days, and we had two slots of twenty minutes instead of one ninety-minute session. We used them to set up Friday rather than to squeeze Friday into them.
Friday ran as planned, 09:30 to 15:30. Around fifty people worked in five teams (traffic control, cybersecurity, lock automation, pilotage and executive management) through a fictional incident at the Panama Canal. Each team held part of the picture and none could resolve the situation alone, so what the day really tested was whether information travelled between the tables in time. Colleagues from UMIP and MTCC Latin America facilitated at the tables with us; fifty people is more than two facilitators can hold.
Read this as a report from the people who ran it, not as an independent review. The most useful outside view came from one participant, a technology executive in Panama's port sector, who wrote afterwards that nobody in the room had a complete view of what was happening, and that you had to listen, compare information, coordinate and decide. That is the design, described from the other side of the table.
Three things that matter this week
ENISA named the group, and the number everyone quoted is the one without a source
On 22 September ENISA, the EU's cybersecurity agency, published its annual Threat Landscape, covering incidents recorded between 1 January and 31 December 2025. In the section on transport it says: "Maritime-related organisations were primarily targeted by China-nexus Mustang Panda, with continuous campaigns impacting at least seven EU MSs." That sentence, and the word seven, led the coverage.
Thirty-six pages later, in the chapter on state-linked actors, the same report says Mustang Panda "was notably seen targeting maritime entities in at least four EU MSs". That sentence carries footnotes, to the French national cybersecurity agency and the Belgian Centre for Cybersecurity. The sentence with seven carries none. The report does not reconcile the two figures, and both may be true: four documented by two national agencies, seven from wider reporting. But only one of them shows where it came from, and it is not the one in the headlines.
The rest is solid and worth more than the count. The purpose, in ENISA's words, was "cyberespionage and strategic intelligence collection". The ways in were spear phishing, compromised USB devices and DLL side-loading, with a toolset that includes DOPLUGS, a Korplug loader and customised PlugX. Elsewhere the report puts it plainly: Mustang Panda "primarily focused their cyberespionage activities against the maritime industry, targeting several EU MSs maritime related entities throughout 2025, notably through the use of compromised USB media." It names no country and no company.
One more distinction, because some coverage blurred it. ENISA does not say it "attributed" these campaigns. It says the organisations were "targeted by" the group and that the group was "seen targeting" them. In the same report the word attributed is kept for governments' formal statements, such as Czechia's attribution of a campaign against its foreign ministry to APT31. That is a named group tracked by analysts, not a state putting its name to an accusation, and the difference matters when this ends up in a board paper.
Why this matters for maritime: the threat described here is quiet collection rather than disruption, and one of its doors is the oldest one on a ship. ENISA also places maritime transport, with rail, in the "risk zone" of its NIS360 assessment, "notably due to their reliance on heterogenous systems and their strategic importance in the global supply chain".
What to do: Find out this week who can plug removable media into which systems on board and ashore, and how chart and software updates actually arrive on the bridge. If the answer includes a USB stick handed over by an agent, a surveyor or a service engineer, write down what checks it before it touches ECDIS or the engine control room, and who signs for it.
Test your response: Your national authority under NIS2 reads the same report and asks what you have done about espionage through removable media. You have a policy document, and a chief engineer who updates the engine monitoring software from a vendor's USB stick twice a year. What do you show them, and what do you change first? NIS2 Nightmare: The Audit That Turned Into a Crisis →
A research ship sailed from China to Papua New Guinea in a day, and the Coast Guard flew out to look
On Monday 28 September the Philippine Coast Guard challenged the Chinese research vessel Jia Hai Ke 7 about 38 nautical miles north-west of Itbayat, in the Batanes islands, inside the Philippine exclusive economic zone. A PCG aircraft called her several times over the radio, asked her to state her intentions and to stop any unauthorised activity, and got no answer.
What drew attention was her AIS track. According to Rear Admiral Jay Tarriela, the PCG spokesperson for the West Philippine Sea, the ship reported departing Xiamen at 00:59 on 21 September. By 20:10 the same day she was transmitting a position off Bindari, Papua New Guinea, more than 2,000 nautical miles away. By 06:55 on Monday she was transmitting from north-west of Itbayat, where a maritime domain awareness flight found her. "The PCG assesses this as deliberate AIS spoofing to conceal the vessel's true movements from Philippine authorities," Tarriela said. Other reports of the same statement put it more cautiously, as possible deliberate spoofing.
The location matters more than the ship. In Tarriela's words, "the waters off Batanes and the Luzon Strait host critical submarine cable corridors linking the Philippines to Northeast Asia and the wider Indo-Pacific", and a seabed survey vessel hiding its position while holding station there raises concerns about undersea communications. The PCG has raised the possibility of survey work relevant to cables; it has not publicly established that she was doing it. The Chinese Embassy in Manila, according to a Manila Bulletin headline, says the vessel was operating lawfully.
Two details matter beyond the politics. The anomaly was checked with a Canadian-provided Dark Vessel Detection system, which compares what ships broadcast with what can be observed. And in the same week a Copenhagen company, Worldwide AIS Network, said its receiver in Varna had picked up 27 position reports from four tankers in the Black Sea. They placed all four on the same one-kilometre circle in central Lima, more than 12,000 kilometres away. Why this matters for maritime: AIS is a self-declared signal. It becomes evidence only when somebody checks it against something the ship does not control.
What to do: Ask whoever reads AIS in your operation (vessel traffic services, terminal planning, fleet operations) what happens to a position report that is physically impossible. Is it flagged, silently dropped, or plotted as if it were true? If the answer is "plotted", your picture of who is near your cables, pipelines or berths is only as good as the least honest transponder in range.
Test your response: Your traffic picture shows a survey vessel holding station over the approach to a cable landing. Her AIS says she is two thousand miles away. Nobody on your team has the authority to send anyone out to look. Who do you call, and what do you record before the track disappears? Ghost Ships of the Black Sea: When GPS Lies →
The FBI named neither the attacker nor the victim, and still said the most useful thing this week
On 23 September the FBI and CISA published a four-page fact sheet, Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators. It opens with a case. Between March and April 2025, according to FBI technical analysis, "malicious foreign cyber actors" gained access to the network of a US industrial automation company that provided system integration, engineering consulting and SCADA programming to industrial customers, "including power utilities and transportation entities". Once inside, they searched for terms including "customers" and "SCADA", and created nine .zip files of roughly 800 files, "including customer SCADA information, ICS device details, and other schematics", for presumed exfiltration.
The fact sheet does not name the company, the customers or the attackers. It does not mention ports or ships either. It does not need to. Why this matters for maritime: the people who install and maintain lock control systems, crane automation, terminal operating systems and much of what runs below the bridge are integrators, and many of them keep a remote way in for support. An attacker who reaches the integrator reaches the drawings, and sometimes the door.
The document asks four questions that every operator should be able to answer without a meeting. What organisational data does the integrator store or have access to? Where is that data stored? Does the integrator have remote access for operational support? And the last one: "Can the organization operate independently if the integrator is compromised?"
Its recommendations are plain. Put cybersecurity into the contract, including remote access capabilities, the integrator's own security programme, change and patch management, and a list of the personnel authorised to access your systems. "Monitor and log remote access." Make integrators come in through routes you can see, and "use on-demand remote access if possible, so operators have to proactively allow remote access". Ask for an inventory of every piece of hardware and software the integrator supplied, with documentation of how it connects to your infrastructure. And practise manual operations, accounting for where the third parties sit in your recovery.
What to do: Take the four questions to whoever owns your OT contracts this week, and start with the third. For each integrator that supports your cranes, locks, terminal systems or vessel automation, write down how they connect, who can switch that connection on, and where the log of it lives. If the honest answer is "they have a permanent VPN and we have never looked at it", you have found your first contract clause.
Test your response: A flag State inspector asks you to show how your automation vendor reaches the ship's systems from ashore, and who on board knows when they do. Your chief engineer believes the connection is only opened on request. Your IT manager believes it is always on. Who is right, and how would you prove it before the inspector leaves? MSC.428 Inspection: When the Flag State Finds Your Secrets →
Still quiet: the names we have been following
TEC Container, named on a leak site on 26 August, and Globalport Terminals, named on 27 August, are now at five weeks without a public word. AMPTC, named on 1 September, is at four. Nothing from any of them, and nothing new about them beyond trackers repeating the original claims.
Tanjung Pelepas resumed operations on 15 September and has still not said what the incident was. The group that listed the port claimed around 200 GB of data on 11 September; as far as we can see, nothing has been published.
Inland and Offshore Contractors in Trinidad and Tobago, listed by Qilin on 18 September, has said nothing either.
On the two US boardings from last issue: the second vessel is still unnamed, and US authorities have not attributed either incident to anyone. Vivit Africa LNG was near Algeciras on 24 September according to AIS tracking, and the cause of her systems failure has still not been published. A Foundation for Defense of Democracies brief on 23 September used both cases to argue that Congress should require the Coast Guard to set out how its maritime cybersecurity office will be resourced, which is the question the House committee's bill from last issue asks the GAO to answer.
In case you missed it
Honeywell's 2026 OT Cybersecurity Benchmark Report, released on 22 September, says 87% of maritime respondents had a significant OT cybersecurity incident in the previous twelve months. It is a vendor survey of more than 600 leaders across several sectors. The coverage we have seen gives neither the size of the maritime sample nor what counts as "significant", so treat the headline with the care we gave last week's 120 million. The more useful figure is further down: 88% of all respondents called their OT programmes mature, and 21% said they had a complete inventory of their OT assets.
NorthStandard, the P&I club, has agreed a partnership giving its members a 15% discount on PntGuard, a system from SGM Technology that authenticates a ship's position independently of GNSS using the Iridium PNT satellite service. It is a commercial arrangement and we have not tested the product.
Coming up
Maritim Cyber Security, Ålesund, and ShipIT, Athens, both today, 29 September.
4th EMSA Maritime Cybersecurity Conference, Lisbon, 8 October. The European Maritime Safety Agency's own cyber conference, a fortnight after ENISA's report named a China-linked group targeting shipping.
Forum Gospodarki Morskiej (Maritime Economy Forum), Gdynia, 9 October. The 25th edition, with a cyber track.
IMO / Cyber-SHIP Lab Symposium on Maritime Cyber Security, London, 11–12 November, at IMO headquarters.
Full calendar, with cyber tracks flagged: https://mc3.maritime-ogmios.tech
Number of the week
104 knots — the average speed implied by the AIS track of Jia Hai Ke 7 on 21 September: more than 2,000 nautical miles from Xiamen to a position off Papua New Guinea between 00:59 and 20:10, as the Philippine Coast Guard described it. A large container ship at full speed makes 20 to 25. Nobody needed a forensic tool to see that the track was false; they needed somebody to look, and an aircraft to go and confirm it.
Scuttlebutt
Unconfirmed signals from open-source and regional channels we monitor. Confidence is flagged on each item. Treat these as early warning, not fact, until confirmed.
ASYAD Group, listed by the Spirals group on 23 September. The description on the listing is corporate boilerplate (the group is "Oman's global integrated logistics provider"), so, as usual, we looked at the domain instead: www.asyad.com, which resolves to the same server as asyad.om, the group's Omani site. Asyad is Oman's state-owned logistics group, and its businesses include a shipping company and interests in the country's main ports. That is the maritime nexus, and it is the only part of the listing the attackers did not write.
Everything else is the attackers' claim: no stated data volume, no statement from the company, no coverage we could find.
Resource of the week
ENISA Threat Landscape 2026 (ENISA, 22 September 2026)
A hundred pages, and most of it is not about ships. Read two pages side by side: page 30, where maritime appears in the transport section with seven member states, and page 66, where the same group appears with four member states and footnotes to two national agencies. It is a small lesson in reading any threat report: follow the number back to its source before you repeat it.
Want more depth?
Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.
Read of the week
"The Art of Cyberwarfare: An Investigator's Guide to Espionage, Ransomware, and Organized Cybercrime", by Jon DiMaggio, 2022.
A working method for reading adversary operations rather than a history of them: how investigators get from scattered evidence to a named group, and how much confidence each step deserves.
Relevant this week because three public bodies each named something, and none of them named everything. Knowing what an attribution rests on is the difference between reading "China-linked" as a finding and reading it as a headline.
