An empirical breakdown of the queries, filters, and satellite ASN ranges that surface exposed vessels, and what the findings actually mean.
Shodan continuously scans the internet and indexes the banners that devices return. It does not attack anything, it requests metadata over and over across IPv4 address spaces. When a device answers with a web login page, a Telnet banner, or an SNMP string, that device becomes searchable by anyone.
Merchant vessels appear in this index because their VSAT terminals and bridge equipment are assigned public IPs from satellite operators' ASN blocks. The equipment is not intentionally exposed, it is simply reachable, and searchable, and catalogued.
Satellite ASN filters. Inmarsat, Iridium, KVH, and Marlink announce public ASN ranges. Filtering by those ASNs immediately narrows the internet to maritime satellite subscribers.
VSAT product banners. Sailor, TracPhone, iDirect, and other terminal web GUIs return identifiable titles. A search for those titles finds terminals with no login required.
Open OT ports. Telnet and Modbus on maritime IPs are rare but not vanishingly so, and each one is a bridge into the shipboard network.
Across our audited sample, 73% of merchant vessels had at least one unauthenticated VSAT web GUI, exposed CCTV feed, or open bridge console visible in public indexes. The most common finding was a satellite terminal login page reachable without credentials, a page that also reveals terminal model, firmware, and often the vessel's own IP.
None of this required any exploit. It required a query.
The full detection methodology, including query set and validation approach, is published in IEEE Access 2026.
1. Audit once. Run a passive scan of your fleet's IMO numbers and satellite ASNs. Know your baseline before you change anything.
2. Lock the terminals. Require authentication on every VSAT web GUI. This removes the single most common finding.
3. Filter at the edge. If a port does not need to be public, it should not be reachable from the satellite link.
4. Re-scan quarterly. Exposure changes with every port call, firmware update, and crew rotation.
What a VSAT terminal is, why it keeps showing up in scans, and the checklist to run before port calls.
Electronic chart display risks explained without jargon: what can go wrong, and what bridge teams should know.
What Port State Control inspections will check, what evidence counts, and how to prepare.
Three vessels scanned free, report delivered in 24 hours.