Home M-SOC Shipcrawler Haris
Other Services Web Development Networking Mobile App Development
Contact Blog Free Fleet Scan
RESEARCH BRIEF 01 Passive OSINT · Satellite ASNs

How attackers find ships on Shodan.

An empirical breakdown of the queries, filters, and satellite ASN ranges that surface exposed vessels, and what the findings actually mean.

Empirical Metrics Shodan Scan Findings
Audited vessels with reachable terminals 73%
Terminals with zero authentication required 68%
Exploit requirement for discovery 0% (Query Only)
DATASET: 47 COMMERCIAL VESSELS / EXPOSURE RATE: 73% / CITATION: IEEE ACCESS 2026 / READ TIME: 6 MIN
01 · The search engine that watches ships

Shodan is a search engine for exposed devices

Shodan continuously scans the internet and indexes the banners that devices return. It does not attack anything, it requests metadata over and over across IPv4 address spaces. When a device answers with a web login page, a Telnet banner, or an SNMP string, that device becomes searchable by anyone.

Merchant vessels appear in this index because their VSAT terminals and bridge equipment are assigned public IPs from satellite operators' ASN blocks. The equipment is not intentionally exposed, it is simply reachable, and searchable, and catalogued.

02 · The three queries that matter

How a ship gets surfaced

Satellite ASN filters. Inmarsat, Iridium, KVH, and Marlink announce public ASN ranges. Filtering by those ASNs immediately narrows the internet to maritime satellite subscribers.

VSAT product banners. Sailor, TracPhone, iDirect, and other terminal web GUIs return identifiable titles. A search for those titles finds terminals with no login required.

Open OT ports. Telnet and Modbus on maritime IPs are rare but not vanishingly so, and each one is a bridge into the shipboard network.

03 · What our scans found

73% of audited vessels had something exposed

Across our audited sample, 73% of merchant vessels had at least one unauthenticated VSAT web GUI, exposed CCTV feed, or open bridge console visible in public indexes. The most common finding was a satellite terminal login page reachable without credentials, a page that also reveals terminal model, firmware, and often the vessel's own IP.

None of this required any exploit. It required a query.

The full detection methodology, including query set and validation approach, is published in IEEE Access 2026.

04 · What a fleet manager should do

The practical checklist

1. Audit once. Run a passive scan of your fleet's IMO numbers and satellite ASNs. Know your baseline before you change anything.

2. Lock the terminals. Require authentication on every VSAT web GUI. This removes the single most common finding.

3. Filter at the edge. If a port does not need to be public, it should not be reachable from the satellite link.

4. Re-scan quarterly. Exposure changes with every port call, firmware update, and crew rotation.

05 · Related research

Continue reading field notes.

VSAT Security Essentials

What a VSAT terminal is, why it keeps showing up in scans, and the checklist to run before port calls.

Read Brief (5 min) →

ECDIS Vulnerabilities

Electronic chart display risks explained without jargon: what can go wrong, and what bridge teams should know.

Read Brief (5 min) →

PSC Cyber 2026

What Port State Control inspections will check, what evidence counts, and how to prepare.

Read Brief (6 min) →

See your fleet's exposure.

Three vessels scanned free, report delivered in 24 hours.

Start Free Scan →