Maritime Intelligence · Threat Report 2026
The New Maritime
Battlespace
BRICS power shift · Hormuz pressure · Dark fleet industrialization · Port SCADA exposure · Quantum-era comms threat
Maritime carries 90% of global trade by volume. The 2024-2026 geopolitical shock sequence , Houthi Red Sea campaign, Iran tanker pressure, ZPMC port crane backdoors, BRICS de-dollarization of shipping settlement, and subsea cable attacks, has created a systemic security vacuum that incumbents have not filled. This report documents the threat landscape and identifies actionable entry points for maritime operators, P&I clubs, and port authorities.
Active Chokepoint Intelligence
Real-time threat assessment across the six most critical maritime chokepoints. Closure probability computed from incident frequency, threat actor capability, and geopolitical pressure.
Strait of Hormuz
21 vessels/day
Iran IRGC · Houthi · Ansar Allah
Bab el-Mandeb
48 vessels/day
Houthi · Ansar Allah
Suez Canal
50 vessels/day
State-level cyber · Houthi diversion
Strait of Malacca
100 vessels/day
Piracy syndicates · PRC state-affiliated
Panama Canal
35 vessels/day
PRC Hutchison Ports (ownership)
Taiwan Strait
200 vessels/day
PLAN (PRC Navy)
Dark Fleet Detection, 1,400+ Vessels
The global dark fleet has grown to ~1,400 vessels (CEPEA estimate, 2025). These ships evade sanctions by manipulating AIS transponders, adopting flags of convenience, and operating without standard P&I club cover. Six cryptographic signatures identify them.
HIGH
Speed Anomaly
AIS-reported speed deviates >30% from position-delta computed speed. Transponder is being manipulated manually.
CRITICAL
AIS Dark Gap
>6 hours of AIS silence in high-traffic shipping lane. Vessel is deliberately hiding its position.
CRITICAL
Sanctioned Zone Proximity
Last known position within OFAC/EU threshold distance of Iran, Crimea, Russia, DPRK, or Venezuela export terminals.
MEDIUM
Flag of Convenience
Flag state in PA, LR, KM, PW, MH, CC, TG, jurisdictions known for dark fleet registration with minimal oversight.
HIGH
Cargo-Type Mismatch
VLCC or crude tanker declaring dry bulk, general cargo, or other commodity inconsistent with vessel class.
HIGH
MMSI/Flag Mismatch
Maritime Mobile Service Identity prefix doesn't match declared flag state, MMSI spoofing or re-registration.
HARBINGER, MARITIME DOMAIN AWARENESS
HARBINGER scores every tracked vessel across all six AIS signatures on a 0-10 risk scale. Vessels scoring ≥7.0 trigger immediate OFAC sanctions screening and chokepoint proximity alerts. The pipeline runs continuously, no analyst required for routine sweeps.
Port SCADA Crisis, ZPMC Crane Backdoors
Chinese-manufactured port cranes hold ~70% of global market share. CISA Advisory AA23-075A (2023) confirmed undocumented remote access capabilities in ZPMC equipment. Ports have no mechanism to detect or block the call-home channel, and most LatAm facilities have received zero security assessment.
SPECTRA MARITIME AUDIT, ZPMC MODULE
The SPECTRA Maritime Audit covers ZPMC firmware IOC scanning, exposed industrial protocol detection, and CISA AA23-075A compliance. LatAm port facilities are our primary target segment, they carry the exposure without the incumbent security relationships.
The Quantum-Era Maritime Threat
All current maritime satellite communications, Inmarsat VSAT, Iridium safety channels, AIS traffic, run on RSA/ECDH cryptography deprecated by NIST in 2024. Harvest Now, Decrypt Later attacks allow adversaries to capture encrypted comms today and decrypt them once a cryptographically-relevant quantum computer becomes available (~2030+). No maritime SATCOM provider has deployed ML-KEM.
NIST finalizes ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205)
NSA mandates PQC for US national security systems, no maritime exemption
Matrix CR Studio assessment: zero maritime SATCOM implementations of ML-KEM detected
Expected IMO guidance on cyber resilience update, PQC likely included
NIST deprecates RSA-2048 and ECDH, all current ship comms broken
Cryptographically-relevant quantum computers: Harvest Now, Decrypt Later attacks mature
MATRIX CR PQC POSTURE
Matrix CR Studio operates ML-KEM-768 (FIPS 203) for payload and at-rest encapsulation and is building the first reference implementation of ML-KEM-768 for ship-to-shore authenticated channels , available as a retrofit assessment engagement before the 2027 IMO cyber resilience update cycle.
The BRICS Shift, Why Mid-Tier Operators Need a Non-US Advisor
De-dollarization of shipping settlement creates demand for non-US-aligned security advisors. LatAm ports under BRICS-adjacent trade pressure (Mexico, Brazil, Colombia, Peru) cannot engage Mandiant or Trail of Bits politically. Matrix CR operates from Costa Rica, sovereign, non-aligned, fluent in the regional threat landscape and regulatory environment.
Services
Direct engagement, not a platform play, not an enterprise sales cycle. We deliver within 10 business days.
SPECTRA Maritime Port Audit
10 business days
- , ZPMC crane firmware IOC scan (CISA AA23-075A)
- , Port SCADA exposure assessment (Modbus · S7comm · DNP3 · EtherNet/IP)
- , Ship-to-shore communications PQC readiness
- , Key CVE mapping + remediation roadmap
- , Executive + technical report (EN/ES)
Dark Fleet Watch
SaaS, onboard in 48h
- , Real-time AIS anomaly scoring (6-signature algorithm)
- , OFAC / EU sanctions screening per vessel
- , Chokepoint threat level dashboard
- , Telegram + API alerts on high-risk detections
- , P&I club · OFAC compliance · commodity trader tiers
Maritime PQC Retrofit
15 business days
- , SATCOM / VSAT / Iridium PQC gap analysis
- , ML-KEM-768 implementation feasibility report
- , Ship-to-shore authenticated channel design
- , IMO cyber resilience alignment
- , Executive roadmap for 2027 compliance