CYFIRMA Report Warns Cyber Threats Are Converging on Global Trade Chokepoints

· Original article ↗

Summary

CYFIRMA’s assessment finds that cyber incidents, geopolitical pressure and physical disruption are converging around trade chokepoints, putting transportation and logistics operators at risk even when attackers do not compromise operational technology.

Key points

  • The report reviews transportation and logistics cyber threats from 4 June to 2 September 2026, with later developments through 20 September.
  • IT-only intrusions at North Carolina State Ports Authority, CEVA Logistics and Nichirei disrupted cargo, warehouse or cold-chain operations; no OT compromise was reported in those incidents.
  • CISA, the FBI and the EPA attributed targeting of internet-exposed PLCs across US critical infrastructure to Iran-affiliated actors; CYFIRMA assesses the activity is relevant to transportation OT.
  • CISA describes an unauthenticated RF vulnerability in rail End-of-Train/Head-of-Train systems that could enable unauthorized brake commands; replacement of affected devices is not expected before 2027.
  • US agencies were reported to be monitoring nearly 20 vessels for suspected network compromise. Attribution remains unconfirmed, while satellite-linked systems are identified as an expanding attack surface.
  • FBI IC3 figures cited in the report put 2025 North American freight cargo-theft losses at nearly $725 million, up 60% from 2024.
  • CYFIRMA recommends heightened attention to identity security, third-party access, internet-facing infrastructure, manual fallback processes and IT/OT segmentation during periods of chokepoint pressure.

Article Details

Publisher
CYFIRMA
Report Period
2026-06-04 to 2026-09-20; threat picture through 2026-09-02 and incident table covering 2026-03-01 to 2026-09-02.
Scope
Cyber threats to Transportation & Logistics and the trade chokepoints on which the sector depends.
Sample Size
13 incidents or advisories listed in the incident table; two related incidents outside its window noted separately.
Key Statistics
  • Three reported IT-only intrusions disrupted physical cargo, warehouse or cold-chain operations during the threat-picture window, with no reported evidence of OT compromise.
  • FBI IC3 estimated US and Canadian cargo-theft losses at nearly $725 million in 2025, up a reported 60% from 2024.
  • US agencies were reportedly monitoring nearly 20 vessels for suspected network compromise in September 2026; no attribution was made.
  • Financial Times reporting put vessel intrusions through satellite-linked edge devices at 22% of incidents in 2025, up from 3% in 2024.
  • The Port of Los Angeles reported blocking around 120 million attempted cyberattacks in August 2026, compared with roughly 40 million per month in 2022.
Recommendations
  • Treat periods of chokepoint pressure as periods of heightened cyber exposure.
  • Strengthen identity security and oversight of third-party access.
  • Protect and monitor internet-facing infrastructure.
  • Maintain resilient manual fallback processes and segmentation between IT and operational systems.

CVE

Threat Actors

Vendors

Products

Countries

Canada18-member grouping of the world’s leading maritime nations, including Greece, Singapore, Denmark, Japan, Canada, the UK, the Netherlands and South Korea, together representing more than a fifth of global trade byChinaMore than 80% of incidents since 2001 with an identified attacker were attributed in the dataset to actors in Russia, China, North Korea or Iran.Iranattributed sustained targeting of internet-exposed control systems across US critical infrastructure to Iran-affiliated actors – activity CYFIRMA assesses to be directly relevant to transportation OT, andIsraelItalythe LNG carrier Vivit Africa, suffered a suspected cyberattack in early September while sailing towards Italy, leaving its crew unable to access internal control systems; the ship turned away from its destination andJapan– an 18-member grouping of the world’s leading maritime nations, including Greece, Singapore, Denmark, Japan, Canada, the UK, the Netherlands and South Korea, together representing more than a fifth of global tradeNorth KoreaMore than 80% of incidents since 2001 with an identified attacker were attributed in the dataset to actors in Russia, China, North Korea or Iran.Panama(Moderate confidence – analytical judgement drawn from the Hormuz, Panama and rare-earth cases.)RussiaMore than 80% of incidents since 2001 with an identified attacker were attributed in the dataset to actors in Russia, China, North Korea or Iran.Saudi Arabiaaffiliated with the Houthi movement, claimed to have breached Al Saif Transportation Company, one of Saudi Arabia’s largest logistics firms, amid escalating tensions between the Houthis and the Kingdom (Figure 1).SwitzerlandStadler Rail (Switzerland)TaiwanBeyond the kinetic and legal pressure described in this report, CYFIRMA assesses that straits such as the Taiwan Strait and canals such as Panama are each exposed to a distinct cyber pathway that could compress theirUnited StatesComplaint Center (IC3) public service announcement (I-043026-PSA), cargo-theft losses across the United States and Canada attributed to threat actors impersonating brokers or carriers are estimated to have reached

Industries

Related Articles