CYFIRMA Report Warns Cyber Threats Are Converging on Global Trade Chokepoints

Summary
CYFIRMA’s assessment finds that cyber incidents, geopolitical pressure and physical disruption are converging around trade chokepoints, putting transportation and logistics operators at risk even when attackers do not compromise operational technology.
Key points
- The report reviews transportation and logistics cyber threats from 4 June to 2 September 2026, with later developments through 20 September.
- IT-only intrusions at North Carolina State Ports Authority, CEVA Logistics and Nichirei disrupted cargo, warehouse or cold-chain operations; no OT compromise was reported in those incidents.
- CISA, the FBI and the EPA attributed targeting of internet-exposed PLCs across US critical infrastructure to Iran-affiliated actors; CYFIRMA assesses the activity is relevant to transportation OT.
- CISA describes an unauthenticated RF vulnerability in rail End-of-Train/Head-of-Train systems that could enable unauthorized brake commands; replacement of affected devices is not expected before 2027.
- US agencies were reported to be monitoring nearly 20 vessels for suspected network compromise. Attribution remains unconfirmed, while satellite-linked systems are identified as an expanding attack surface.
- FBI IC3 figures cited in the report put 2025 North American freight cargo-theft losses at nearly $725 million, up 60% from 2024.
- CYFIRMA recommends heightened attention to identity security, third-party access, internet-facing infrastructure, manual fallback processes and IT/OT segmentation during periods of chokepoint pressure.
Article Details
- Publisher
- CYFIRMA
- Report Period
- 2026-06-04 to 2026-09-20; threat picture through 2026-09-02 and incident table covering 2026-03-01 to 2026-09-02.
- Scope
- Cyber threats to Transportation & Logistics and the trade chokepoints on which the sector depends.
- Sample Size
- 13 incidents or advisories listed in the incident table; two related incidents outside its window noted separately.
- Key Statistics
- Three reported IT-only intrusions disrupted physical cargo, warehouse or cold-chain operations during the threat-picture window, with no reported evidence of OT compromise.
- FBI IC3 estimated US and Canadian cargo-theft losses at nearly $725 million in 2025, up a reported 60% from 2024.
- US agencies were reportedly monitoring nearly 20 vessels for suspected network compromise in September 2026; no attribution was made.
- Financial Times reporting put vessel intrusions through satellite-linked edge devices at 22% of incidents in 2025, up from 3% in 2024.
- The Port of Los Angeles reported blocking around 120 million attempted cyberattacks in August 2026, compared with roughly 40 million per month in 2022.
- Recommendations
- Treat periods of chokepoint pressure as periods of heightened cyber exposure.
- Strengthen identity security and oversight of third-party access.
- Protect and monitor internet-facing infrastructure.
- Maintain resilient manual fallback processes and segmentation between IT and operational systems.
CVE
Threat Actors
AnubisRansomware group that claimed the Adriatic Port Authority breach after the incident.EverestGroup that claimed a ransomware extortion attempt against Stadler Rail.ExfilSquadMade an unverified Frontier Airlines leak-site claim and a separate Wesco data-theft claim.fulcrumsecClaimed theft of Manchester Airports Group data; the claimed volume rests on the group's account.HelixHandle used for an unverified Uber Freight leak-site claim; Google reportedly linked it to UNC6671.HouthisMovement with which Uways Qarani claimed affiliation; that relationship was not independently verified by CYFIRMA.QilinGroup linked to the Tulsa International Airport incident by ransomware tracking and media reporting.RansomHouseClaimed responsibility for the Nichirei incident and later leaked data; the report does not independently confirm its attribution.UNC6671Cluster to which Google reportedly linked the actor using the Helix handle.Uways QaraniPersona that described itself as Houthi-affiliated and claimed intrusions against Saudi targets and an Israeli facility; CYFIRMA did not verify the claims or affiliation.
Vendors
ASMLrest on a tightly concentrated ecosystem spanning US design expertise, Dutch photolithography equipment (ASML) and Taiwanese foundries; Chinese dominance of rare-earth and permanent-magnet processing, where exportsIterableBreach reportedly via a third-party marketing platform (Iterable, per MAG’s disclosure)Rockwell Automationexploiting internet-connected PLCs across US critical infrastructure, expanding its scope from Rockwell Automation devices to Schneider Electric and Siemens equipment and documenting modification and deletion ofSchneider ElectricPLCs across US critical infrastructure, expanding its scope from Rockwell Automation devices to Schneider Electric and Siemens equipment and documenting modification and deletion of project-file logic.Siemenscritical infrastructure, expanding its scope from Rockwell Automation devices to Schneider Electric and Siemens equipment and documenting modification and deletion of project-file logic.ZPMCby the US House Committee on Homeland Security and the Select Committee on the CCP reported that ZPMC, the state-owned manufacturer of an estimated 80% of ship-to-shore cranes at US ports, had installed
Products
IterableBreach reportedly via a third-party marketing platform (Iterable, per MAG’s disclosure)LOGINKcellular modems on some cranes that could enable remote access, while the state-linked logistics platform LOGINK is reported to aggregate shipping data from ports worldwide, giving Beijing potential visibility intoStarlinkShipowners have also increasingly adopted Starlink to improve crew connectivity, adding, in CYFIRMA’s assessment, a further entry point.
Countries
Canada18-member grouping of the world’s leading maritime nations, including Greece, Singapore, Denmark, Japan, Canada, the UK, the Netherlands and South Korea, together representing more than a fifth of global trade byChinaMore than 80% of incidents since 2001 with an identified attacker were attributed in the dataset to actors in Russia, China, North Korea or Iran.Iranattributed sustained targeting of internet-exposed control systems across US critical infrastructure to Iran-affiliated actors – activity CYFIRMA assesses to be directly relevant to transportation OT, andIsraelItalythe LNG carrier Vivit Africa, suffered a suspected cyberattack in early September while sailing towards Italy, leaving its crew unable to access internal control systems; the ship turned away from its destination andJapan– an 18-member grouping of the world’s leading maritime nations, including Greece, Singapore, Denmark, Japan, Canada, the UK, the Netherlands and South Korea, together representing more than a fifth of global tradeNorth KoreaMore than 80% of incidents since 2001 with an identified attacker were attributed in the dataset to actors in Russia, China, North Korea or Iran.Panama(Moderate confidence – analytical judgement drawn from the Hormuz, Panama and rare-earth cases.)RussiaMore than 80% of incidents since 2001 with an identified attacker were attributed in the dataset to actors in Russia, China, North Korea or Iran.Saudi Arabiaaffiliated with the Houthi movement, claimed to have breached Al Saif Transportation Company, one of Saudi Arabia’s largest logistics firms, amid escalating tensions between the Houthis and the Kingdom (Figure 1).SwitzerlandStadler Rail (Switzerland)TaiwanBeyond the kinetic and legal pressure described in this report, CYFIRMA assesses that straits such as the Taiwan Strait and canals such as Panama are each exposed to a distinct cyber pathway that could compress theirUnited StatesComplaint Center (IC3) public service announcement (I-043026-PSA), cargo-theft losses across the United States and Canada attributed to threat actors impersonating brokers or carriers are estimated to have reached