A real three-vessel exposure scan, what it surfaced, and the remediation path, anonymized with the numbers intact.
A mid-sized operator asked for a baseline of three vessels before a scheduled PSC window. Two container ships and one product tanker, all with VSAT terminals from the same manufacturer. We ran a passive Shipcrawler scan and delivered a confidential report within 24 hours.
Vessel A (container): VSAT web GUI reachable without authentication; firmware three versions behind; Telnet open on the management interface.
Vessel B (container): VSAT web GUI unauthenticated; no Telnet, but the terminal exposed its GPS-derived position in the status page.
Vessel C (tanker): Terminal web GUI required a login. The only finding was a bridge camera feed reachable from the satellite IP, resolved by the operator in one working day.
The pattern: the same terminal vendor, the same commissioning defaults, repeated across the fleet. One vendor call fixed most of it.
The operator enabled authentication on all terminals and changed credentials at the next port call. The tanker's camera feed was moved behind the firewall the same day. Firmware updates were scheduled into the next drydock windows.
Total direct cost to the operator: approximately two hours of superintendent time and one support call to the terminal vendor. Total exposure eliminated: the fleet's most common attack surface.
None of these findings required an exploit or a sophisticated adversary, just a query. The operator's reaction is the one we recommend to everyone: scan first, fix the cheap things immediately, and let the data drive the plan.
An empirical breakdown of the queries and satellite ASN ranges that surface exposed vessels.
What a VSAT terminal is, why it keeps showing up in scans, and the checklist to run before port calls.
What Port State Control inspections will check, what evidence counts, and how to prepare.
Free for three vessels, report delivered in 24 hours.