AI & Maritime Cyber

For last years, when people in this industry said "AI" in the same breath as cyber, they meant sharper phishing. Better grammar, the right language, a logo that fooled the eye. That version is still with us, and it got worse. But it is not the story of 2026.

The story of 2026 is that the attacker can now be a machine that runs the whole operation itself. Not a person using AI tools. An agent: software that does its own reconnaissance, picks its own targets, writes its own exploit, and moves the data out, with a human checking in occasionally rather than driving. When most of the attack lifecycle runs with no person in the loop, two things I used to tell operators stop being true: that we have time to react, and that the fix is to train the crew to spot it.

So this issue comes in two halves. The first is what agentic AI already does to the maritime attack surface, and how fast. The second is the honest half nobody sells: what defensive AI actually does about it, and what it does not. Both matter, because the temptation right now is to answer a machine-speed problem with a slide deck.

Key Figures

Figure

What it is

Source

80 to 90 percent

share of the tactical intrusion work AI agents ran autonomously in the GTG-1002 campaign

Anthropic
(GTG-1002 disclosure, November 2025)

under 48 hours

window in which ~60 percent of new vulnerabilities are now weaponised, some within 15 minutes

Cydome 2026 trends report

83 percent

phishing emails aimed at multinational crews that are AI-generated

Cydome 2026

1600 percent

reported surge in voice phishing (vishing) via executive voice-cloning

Cydome 2026

828

maritime cyber incidents in 2025, up 103 percent on 2024

CYTUR 2026 white paper

43 percent

reported Marine Transportation System incidents in 2025 that involved phishing (up from 25 percent)

USCG Cyber Bulletin MCB 01-26

Top findings

Finding 1: The adversary can now be a machine

GTG-1002 is the case maritime threat-intel now reaches for, and it comes down to a single number. When Anthropic disclosed the campaign in November 2025, attributing it with high confidence to a Chinese state-linked group, it reported that AI agents had run 80 to 90 percent of the tactical intrusion work on their own: reconnaissance, target selection, exploitation, exfiltration. The human stepped in only at a handful of decision points. (The attribution is an intelligence assessment, not a court finding, and Beijing denies it — but the autonomy is the part that should change how you plan.)

"Agentic" is the word that matters. It is the difference between a burglar with a better lockpick and a burglar you never hired, who works your whole street, all night, and reports back only what it found. It lowers the skill barrier (the operator no longer has to be good) and it scales in a way a human crew cannot.

For maritime that lands in two places. First, smart-ship OT, where the same handful of exposed devices repeats across a fleet, so one working path multiplies into a hundred. Second, the supply-chain chokepoints CYTUR keeps flagging: the telecom providers and OEM equipment vendors that sit upstream of hundreds of hulls. An agent that finds a way into one of those has not found one victim.

Why this matters: Most maritime response plans assume a human on the other end, working business hours, whom you can eventually out-last. That assumption no longer holds.

One thing to do: Pressure-test your detection against machine speed, not human speed. If your last tabletop assumed an attacker who sleeps, run it again assuming one who does not.

Finding 2: The patch window collapsed

Cydome's 2026 trends report carries the number that should stop a fleet IT manager cold: around 60 percent of newly disclosed vulnerabilities are now weaponised within 48 hours, and some within 15 minutes of disclosure. Put it on a timeline. In 2018, the gap between a vulnerability going public and being exploited ran about 63 days. In 2024 it was around five days. In 2026 it is measured in hours, and sometimes in the time it takes to read the advisory.

Now hold that against maritime reality. A type-approved OT system cannot be patched in 15 minutes, and often not in six months. Take the ECDIS, the VDR, or the satcom terminal we pulled apart in SE03 "Copy Fail": the fix has to pass through the OEM, re-certification, and a maintenance window the vessel may not get until dry-dock. The patch race was already lost on maritime OT. AI just moved the finish line to somewhere no amount of patching can reach.

Why this matters: If exploitation is faster than your slowest-to-patch system by a factor of thousands, patching is no longer your primary control. It is a lagging one.

One thing to do: Move budget and attention off "patch faster", a race you cannot win, and onto the controls that hold while the patch is impossible: network segmentation, least-privilege remote access, and monitoring that flags the exploit attempt even while the hole is still open.

Finding 3: AI-scaled social engineering — the human exploit, industrialised

The phishing you were trained to catch, with its odd phrasing and wrong logo, is the version AI retired. Cydome reports that 83 percent of phishing emails aimed at multinational crews are now AI-generated, written in the recipient's own language and tuned to the crewing agency or payroll office they impersonate. The same report puts the rise in voice phishing at 1 600 percent, driven by AI cloning an executive's voice well enough to authorise a transfer, and AI-driven identity fraud up 195 percent.

The canonical case is not maritime, but it is the template: a European energy major lost 25 million dollars when a deepfaked voice of its CFO approved an "urgent" wire. Map that onto where money moves in shipping: charter payments, bunker invoices, a crew-claim settlement owed to a seafarer's family. These are flows that still turn on one person, one email thread, one approval. The US Coast Guard's own bulletin, MCB 01-26 of 18 March 2026, found phishing in 43 percent of reported Marine Transportation System incidents in 2025, up from 25 percent the year before, and used for reconnaissance and account takeover rather than one-off fraud.

Why this matters: Every control that assumes a human can tell a real request from a fake one, by the voice or the writing, is now betting against the machine's core competence.

One thing to do: Put a hard call-back rule on any change to payment details or bank instructions: verify on a second, pre-agreed channel, every time, with no exception for "urgent." It is the one control a deepfake cannot talk its way past.

Finding 4: What defensive AI actually does — and what it doesn't

Here is the half the vendors are quieter about. Offensive AI is loud and already deployed; defensive AI is more cautious, less visible, and oversold. So be precise about where it earns its place.

Where it genuinely helps is keeping pace with the 15-minute window. No human SOC can watch a fleet's OT telemetry fast enough to catch a machine-speed exploit; anomaly detection can. That is the practical reason IACS UR E26/E27's continuous-monitoring requirement matters — it turns AI-assisted detection from a nice-to-have into a compliance necessity. It also helps where the sector is drowning: maritime-specific threat intelligence (CYTUR calls it "MCTI", arguing generic feeds miss the OT and AIS context), asset inventory, and pulling a real vulnerability picture out of a fleet nobody has fully mapped.

Where it does not help is as autonomous defence you trust blind. An AI that can block, isolate, or reroute is also an AI that can take your bridge network down on a false positive at the worst possible moment. The thing to build before the tool is the governance around it: which AI may see which data, which actions it is allowed to take on its own, and what audit trail proves what it did. Deploy the model without that, and you have swapped one machine-speed risk for another.

Why this matters: The right answer to "the attacker is a machine" is not "so is our defence." It is "so is our detection, under human-owned rules."

One thing to do: Before you buy or switch on any defensive AI, write the one-page accountability framework: data access, permitted autonomous actions, audit trail. If you cannot write it, you are not ready to deploy it.

Finding 5: Regulation is catching up — and it doesn't care whether the attacker was human

The regulatory perimeter has spent two years closing, and we have tracked it issue by issue. AI does not open a loophole in it; if anything it closes one. The clearest new signal is the IMO's goals-based, non-mandatory Maritime Cyber Code. An EU submission helped put it on the agenda at the Facilitation Committee's 50th session in March 2026, and the committee agreed to develop it with a target completion date of 2028. It starts voluntary, and it is early, but the direction of travel is a code-level, safety-grade cyber standard for ships and ports.

The sharper point sits in a rule already in force. NIS2's mandatory incident reporting does not ask who — or what — carried out the attack. An incident is an incident whether a person or an autonomous agent caused it, which makes an AI-driven breach a direct compliance exposure, and the clock runs identically: a 24-hour early warning, a 72-hour notification, a final report inside a month. The five instruments now doing the pushing (IMO MSC.428(98), the USCG's MTSA cyber rules, TMSA 3 Element 13, IACS UR E26/E27, and NIS2) were written for human adversaries and apply, unchanged, to machine ones.

Why this matters: "It was an AI, we could not have stopped it" is not a defence a regulator or a court will accept. The reporting duty and the duty of care are indifferent to the attacker's nature.

One thing to do: Map your AI-era attack scenarios onto your reporting obligations now, and decide one thing in particular: who starts the 24-hour clock when the breach is detected at 03:00 by a model rather than a person.

Six takeaways

  1. AI stopped meaning "better phishing." The categorical shift of 2026 is agentic — an attacker that runs the whole operation itself, at machine speed.

  2. Machine speed breaks two old assumptions: that you have time to react, and that training the crew to spot it is the fix.

  3. Patching is now a lagging control on maritime OT. When exploitation is measured in minutes and patching in months, compensating controls carry the load.

  4. Deepfakes retired the "spot the fake" defence. A pre-agreed call-back on payment changes is the one control they cannot bypass.

  5. Defensive AI is detection under human rules, not autonomous defence you trust blind. Build the governance before the tool.

  6. Regulation is AI-agnostic. NIS2's clock and the duty of care run the same whether the attacker was a person or an agent.

What I'm watching next

  • Whether a maritime-specific agentic incident gets publicly confirmed — so far the load-bearing case, GTG-1002, is cross-sector, not maritime.

  • The IMO Maritime Cyber Code's path through the Facilitation Committee: scope, whether it stays voluntary, and whether it borrows NIS2's reporting timelines.

  • The first at-scale defensive-AI deployments on fleets, and whether any of them ship with a published governance model.

  • Whether the headline vendor numbers (Cydome, CYTUR) get independent corroboration — right now most of the stats are single-source.

Resources

Test your team before the threat does.

The findings in the ATA describe what is happening across the sector. The question for your organisation is: what would your team do if it happened to you?