TL;DR — too long, didn’t read

  • A tanker's propulsion, according to people without names: Bloomberg reports that FBI and Coast Guard investigators found evidence that hackers accessed the propulsion system of VL Prosperity. The officials who said so asked not to be identified, and the agencies themselves added nothing on the record.

  • The spoofing was in the data five months early: a Georgia Tech study of AIS from more than 367 000 vessels found the interference pattern at the MSC Antonia grounding site in January 2025. She ran aground there in May.

  • Four maritime names on leak sites in five days: a ship supplier, an equipment maker, a Jones Act carrier and a Brazilian marine services firm. Each listing proves less than it seems to, and the useful question is what your suppliers hold about your ships.

The thread: the loudest claim of the week had no name on it, and the strongest evidence had been sitting in data that nobody looked at in time.

Three things that matter this week

Hackers reached a tanker's propulsion system, say officials who would not be named

On 2 October Bloomberg reported that FBI and US Coast Guard investigators had found evidence that hackers accessed the propulsion system of an oil supertanker as she approached the Texas coast this summer. The ship is VL Prosperity, the crude carrier boarded on 21 August, which led issue #29. According to the report, outsiders gained "temporary access" to the digital system, and "it wasn't immediately clear how long the hackers had access and what they could've controlled aboard the ship with it." Officials are still examining how the breach happened and who was responsible.

Look at who is speaking. The claim comes from "U.S. officials familiar with the matter", who asked not to be identified because they were not authorised to discuss it. The Coast Guard declined to comment. The FBI repeated the statement the two agencies had already released. The boardings were carried out "following indications that the networks of both vessels were compromised", and "currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts." So the record says networks were compromised and nothing was disrupted. The propulsion system is mentioned only by people who would not give their names.

That is not a reason to dismiss it. In September Rear Admiral Amy Grable, commander of Coast Guard Cyber Command, told CBS on the record that the boarding teams "did find malicious cyber activity". The same interview named the worry: "those IT systems being connected to other systems on the ship that control propulsion, navigation and other systems that are critical to the safety of that vessel." In August, Iranian state media had claimed that the ship's propulsion was reached. The new report moves that claim from an Iranian broadcaster to anonymous US officials. It has not yet moved it onto the record.

It also leaves open what "the propulsion system" means. It could be the engine control system itself, the monitoring network around it, or a remote maintenance connection to either. Those are three different findings with different consequences, and the report's own word is "accessed", not "controlled". DNV's head of cyber security, Svante Einarsson, told Bloomberg that most vessels can fall back on other systems that let the crew keep operating.

Why this matters for maritime: the harder question is how anyone on board would have known. Kaleb Rood worked as an equipment operator at the Georgia Ports Authority in Savannah and trained as a ship-to-shore crane operator, before moving into IT risk. Last week Kaleb described the view from the cab to us:

❝

"Despite that hands-on control, visibility into the underlying network architecture or remote access pathways is zero. If something went wrong, an operator would feel physical anomalies right away, like control lag or erratic positioning. However, because micro-glitches happen all the time, the immediate assumption on the terminal is always a faulty sensor or mechanical bug, not a cyber event. That gap between physical operational noise and cyber awareness is where the real risk sits."

A crane cab is not an engine control room, but the gap is the same one.

What to do: For each ship, ask your technical superintendent and the engine maker's service partner three things: which remote connections reach the propulsion control or engine monitoring systems, who can open them, and where the record of the last session is kept. Then ask the chief engineer how an unexplained change in engine behaviour gets logged. If "fault" is the only category available, add one question to the procedure: was anyone connected at the time?

Test your response: Your tanker is two days out from a US port. The Coast Guard asks for advance notice of her arrival, because she is on a list of ships with suspected cyber exposure. Nobody on board has noticed anything unusual. What do you tell them, and what do you check before she arrives? USCG Cyber Drill: The Final Rule Reality Check →

The spoofing at the MSC Antonia grounding site was in the data five months earlier

On 29 September researchers at the Georgia Institute of Technology published a preprint, She Spoofed Sea Ships by the Sea Shore, which they describe as the first large-scale measurement study of maritime GPS spoofing. They took AIS data from more than 367 000 vessels, collected between late November 2024 and early February 2025, and looked for physically implausible movement that appears in several ships at the same time and place, rather than in one ship alone. The result was 17 936 anomaly episodes across 2663 vessels, and 31 persistent hotspots, "at least 22 of which show strong evidence of GPS spoofing". Many of them match documented incidents. Others, the authors say, are spoofing regions nobody had reported before.

The finding that matters most concerns MSC Antonia, the container ship that ran aground in the Red Sea in May 2025, in an incident widely attributed to suspected GNSS spoofing. Near Port Sudan, in January 2025, the researchers found false tracks matching the ones MSC Antonia recorded before she ran aground. The tracks "follow the exact same latitude, to the fifth decimal point, as those recorded from the MSC Antonia prior to its grounding, suggesting repeated or continued operation of the same interference source five months apart." In their words, the activity "was ongoing months before the incident, which has not been previously documented."

The authors are careful about the limits, and so should we be. AIS reports the position a ship's receiver calculated, not the signal it received, so they "cannot localize transmitters, attribute interference to specific actors". Their counts are "a lower bound". There is no onboard ground truth, and their explanations of who was behind each zone are offered as hypotheses. Only two clusters, in the Gulf of Mexico and the Baltic near Copenhagen, could be reproduced on public US and Danish AIS data. The main feed is commercial satellite AIS from Spire, and the paper has not yet been peer-reviewed. It does not establish what caused the grounding, and nor do we.

Why this matters for maritime: none of this needed a new sensor. The pattern was already in the data before the ship arrived, and it stayed in the same place for months.

What to do: Before your next transit of the Red Sea, the Gulf of Oman or the Arabian Gulf, ask whether the passage plan uses any record of where interference has happened before: UKMTO's weekly overview, your own fleet's AIS history, the hotspots in this paper. Then check whether the bridge team has been told which stretch to expect it on, and what they cross-check against when it starts. Interference that has stayed at the same latitude for five months is not a surprise. It is a known hazard, and it belongs in the passage plan like one.

Test your response: Your tanker is entering a stretch where interference has been reported every week this year. The GNSS position starts drifting from the radar picture. The officer of the watch joined the ship two months ago. What does the passage plan say to do, and who gets the first call? HORMUZ HAZE: The Tanker That Couldn't See, Couldn't Stop, Couldn't Call →

Four maritime names on leak sites in five days, and what a listing proves

Between 29 September and 3 October, four companies with a clear maritime business appeared on ransomware leak sites, according to the ransomware.live tracker:

  • Seven Seas Group, a supplier of ship stores, spare parts and technical equipment, listed by Spirals on 3 October (domain on the listing: sevenseasgroup.com).

  • Wesmar (Western Marine Electronics), a US maker of thrusters, fin stabilisers and fishing sonar, listed by Akira on 1 October.

  • Trailer Bridge, a carrier running ocean freight between Jacksonville, San Juan and Santo Domingo, listed by Brain Cipher on 29 September (domain: trailerbridge.com).

  • Camorim Serviços Marítimos, a Brazilian marine services company, listed by LockBit5 on 29 September (domain: camorim.com.br).

None of them has said anything, and we found no coverage beyond trackers repeating the listings. All four are the attackers' claims until the companies confirm them.

Each listing proves less than it seems to. The domain field is the strongest evidence of identity on the page, and it is still typed by the attacker. Wesmar's listing has no domain at all, so the identification rests on the name. Akira says it "will upload 66gb of corporate data soon", and lists employee passports and driving licences, financials, client information and NDAs. That is the group's description of what it holds, and nobody has verified it. The tracker's own description of Trailer Bridge is marked "[AI generated]" and puts the headquarters in Jacksonville, while the company's website gives its corporate headquarters as Frankfurt. It is a small error, and it is the reason we never quote those descriptions as fact.

Why this matters for maritime: two of the four are not ship operators. They supply ships. A supplier of ship stores may know where your vessels will call and when. An equipment maker holds drawings and service records, and sometimes a remote way into what it installed. Last week's FBI fact sheet asked what your integrator holds about you. The same question applies to everyone who supplies the ship.

What to do: Pick the three suppliers who know the most about your fleet: schedules, crew lists, drawings, service logins. Ask each of them what they hold about your ships, how they would tell you if they were breached, and how quickly. If the contract does not answer the last two, that is the clause to add when it comes up for renewal.

Test your response: Your company's name appears on a leak site on a Tuesday morning, before your IT team has seen anything wrong. A customer forwards you the screenshot and asks whether their cargo data is safe. What do you tell them, and when? CMA CGM: Ransomware in the Container Kingdom →

Still quiet: the names we have been following

TEC Container, named on a leak site on 26 August, and Globalport Terminals, named on 27 August, are now at almost six weeks without a public word. AMPTC, named on 1 September, is at five. Nothing from Inland and Offshore Contractors in Trinidad and Tobago, and Tanjung Pelepas has still not said what its September incident was; as far as we can see, the group that claimed it has published nothing.

The cause of the Vivit Africa LNG systems failure has still not been published. The second vessel boarded in the US in August has still not been named by any authority. And on 1 October the Philippine Coast Guard said it had shadowed Jia Hai Ke 7, the research vessel with the impossible AIS track from last issue, until she left the Philippine exclusive economic zone.

In case you missed it

  • Wärtsilä FOS-Onboard, the onboard part of the company's Fleet Optimisation Solution, was the subject of a CISA advisory on 15 September (ICSA-26-258-02): two critical vulnerabilities involving a hard-coded cryptographic key, which could let an attacker deliver an unauthorised update. CISA updated the advisory on 24 September with a link to the fixed version. It is one of the few advisories this year about a product built for ships, and we did not cover it here at the time. If FOS runs on your fleet, ask Wärtsilä which version you have. Disclosure: the vulnerabilities were reported by Cydome, and Ogmios has a business relationship with Cydome.

  • Marlink and NORMA Cyber, the Nordic maritime cyber centre, launched a combined service on 29 September: NORMA's operations centre monitors and does the first assessment, and Marlink investigates and contains incidents on board. Höegh Autoliners is deploying it across its whole fleet. It is a commercial announcement and we have not tested it. The interesting part is the split: the people who watch the fleet are not the people who go in and fix it.

  • A new MR tanker, the 50 000 dwt Zhi Neng Yun Fan, was delivered in Dalian with compliance with IACS UR E26 among its stated features and a China Classification Society cyber notation. E26 and E27 are mandatory for ships contracted from 1 July 2024, so the news is not the compliance. It is that a shipyard now lists it as a selling point.

Coming up

  • IEEE MetroSea, Šibenik, 5–7 October, with a special session on cybersecurity for the maritime sector.

  • Shipping UK, London, today, 6 October.

  • Cyber Security for Future Maritime Systems, Bristol, 7 October. A one-day IMarEST conference.

  • 4th EMSA Maritime Cybersecurity Conference, Lisbon, 8 October.

  • Forum Gospodarki Morskiej (Maritime Economy Forum), Gdynia, 9 October. The 25th edition, with a cyber track.

  • Uncrewed Naval Systems, Tróia, 13–14 October, including a talk on resilient navigation when GNSS is denied.

  • Digital Ship Summit, Athens, 15 October.

  • IMO / Cyber-SHIP Lab Symposium on Maritime Cyber Security, London, 11–12 November.

Full calendar, with cyber tracks flagged: https://mc3.maritime-ogmios.tech

Number of the week

  • 35347 — anomalous AIS positions UKMTO observed in its Voluntary Reporting Area in the seven days to 2 October. In the same seven days, ships sent UKMTO eight reports of GNSS interference. UKMTO notes that report density "reflects reporting volume, vessel traffic, and AIS visibility, not the absolute level of GNSS interference." Put the two numbers next to Story 2: the data sees far more than the ships report.

Published

The IET's Digital Transformation in Maritime Transportation and Logistics came out officially on 1 October. As disclosed in issue #29, I wrote chapter 14, "Maritime security and cybersecurity", so read this as a notice, not a recommendation.

Resource of the week

UKMTO VRA Weekly Overview (UK Maritime Trade Operations, published weekly; latest edition for the week ending 2 October 2026)

Four pages, free, every week: transit statistics, incidents, and a page on GNSS interference that sets vessel reports against anomalous AIS positions. If your ships transit the Red Sea, the Gulf of Oman or the Arabian Gulf, this is the cheapest input your passage planning can have.

Want more depth?

Maritime Cyber Intelligence Brief covers what the weekly cannot: full incident timelines, regulatory analysis, GNSS threat data, and OT advisory breakdowns. The latest issue is a free preview.

Read of the week

"Countering Cyber Sabotage: Introducing Consequence-Driven, Cyber-Informed Engineering (CCE)", by Andrew Bochman and Sarah Freeman, 2021.

The method starts at the worst outcome you cannot accept and works backwards to the digital paths that could cause it, instead of starting from the network and hoping to reach the consequences.

Relevant this week because the Bloomberg report could not say what the intruders could have controlled. CCE is a way of answering that question for your own ships before somebody else has to.