Home M-SOC Shipcrawler Haris
Other Services Web Development Networking Mobile App Development
Contact Blog Free Fleet Scan
RESEARCH BRIEF 05 Case Study · 3 Commercial Ships

A real fleet scan, anonymized.

A real three-vessel exposure scan, what it surfaced, and the remediation path, anonymized with the numbers intact.

Case Telemetry 3-Ship Audit Findings
Vessels with unauthenticated VSAT panels 2 / 3 (67%)
Vessels with open Telnet management ports 1 / 3 (33%)
Remediation time to zero exposure 2 Hours
CASE STUDY: 3 MERCHANT SHIPS / DISCOVERY: 24 HOURS / FIX TIME: 2 HOURS / READ TIME: 5 MIN
01 · The engagement

Three vessels, one operator

A mid-sized operator asked for a baseline of three vessels before a scheduled PSC window. Two container ships and one product tanker, all with VSAT terminals from the same manufacturer. We ran a passive Shipcrawler scan and delivered a confidential report within 24 hours.

02 · Findings

What the scan surfaced

Vessel A (container): VSAT web GUI reachable without authentication; firmware three versions behind; Telnet open on the management interface.

Vessel B (container): VSAT web GUI unauthenticated; no Telnet, but the terminal exposed its GPS-derived position in the status page.

Vessel C (tanker): Terminal web GUI required a login. The only finding was a bridge camera feed reachable from the satellite IP, resolved by the operator in one working day.

The pattern: the same terminal vendor, the same commissioning defaults, repeated across the fleet. One vendor call fixed most of it.

03 · Remediation

What the operator did

The operator enabled authentication on all terminals and changed credentials at the next port call. The tanker's camera feed was moved behind the firewall the same day. Firmware updates were scheduled into the next drydock windows.

Total direct cost to the operator: approximately two hours of superintendent time and one support call to the terminal vendor. Total exposure eliminated: the fleet's most common attack surface.

04 · The takeaway

Baselines are cheap; surprises are not

None of these findings required an exploit or a sophisticated adversary, just a query. The operator's reaction is the one we recommend to everyone: scan first, fix the cheap things immediately, and let the data drive the plan.

05 · Related research

Continue reading field notes.

Shodan & Ships

An empirical breakdown of the queries and satellite ASN ranges that surface exposed vessels.

Read Brief (6 min) →

VSAT Security Essentials

What a VSAT terminal is, why it keeps showing up in scans, and the checklist to run before port calls.

Read Brief (5 min) →

PSC Cyber 2026

What Port State Control inspections will check, what evidence counts, and how to prepare.

Read Brief (6 min) →

Run the same scan on your fleet.

Free for three vessels, report delivered in 24 hours.

Start Free Scan →