Coast Guard’s Role in Port Cybersecurity

▶ Watch (0:29)

The Coast Guard operates four cyber protection teams, three active and one reserve, each with 39 people. Their primary mission is defending the Marine Transportation System (MTS), which enables $5.4 trillion of US commerce annually. Teams perform threat hunting, penetration testing, and incident response for critical infrastructure partners. All services are free to the receiving organization. The 2003 CPT in Alameda and the 1790 CPT in Washington, DC, conduct these operations against the nation’s ship-to-shore cranes, the largest of which sit on wheels and roll along the quay to unload containers.

The ZPMC Crane Monopoly and Its Risks

▶ Watch (4:49)

A single Chinese state-owned enterprise, Shanghai Zhenhua Heavy Industries (ZPMC), manufactured 80% of US cranes and 70% of the world’s. All top 10 US ports by value use them except Savannah, Georgia. As a state-owned enterprise, ZPMC must comply with the Chinese government, share source code, and store data in China. Miltenberger drew parallels to the SolarWinds compromise and the Salt Typhoon incident that hit US cellular infrastructure despite Huawei bans. The cranes are assembled in China, installed by ZPMC employees, and require ZPMC for major maintenance.

Live Findings: Hidden Cellular Modems and Shared Credentials

▶ Watch (12:21)

Coast Guard teams found surprise cellular modems on crane elevators and spreaders, connected directly to OT devices with no access management. One port used a single set of admin credentials for every operator and third-party maintenance firm. Fredericksen noted credentials posted on sticky notes in the equipment house. Other findings included improper network segmentation, legacy protocols like Profinet, end-of-life operating systems, and shared accounts. Teams needed to create mirror ports on managed switches to capture non-IP Profinet traffic, which standard OT tools failed to visualize.

Attack Paths and Practical Defenses

▶ Watch (16:55)

Attackers could exploit the supply chain to introduce persistent mechanisms or use phishing to gain initial access, then move laterally to crane OT environments. Cyber effects range from data manipulation for smuggling to ransomware slowing port operations. Physical disruption would likely involve locking spreaders or manipulating safe operating parameters to damage equipment over time. Miltenberger recommended scrutinizing contract language to remove ZPMC’s required third-party remote access, sweeping for hidden cellular modems, and implementing logging and identity management. A standalone crane paper with detailed findings will follow the talk.

Notable Quotes

this was us. Thank you. Nicholas Fredericksen · ▶ 15:48

surprise cellular modems on your crane. Certainly a finding. And we’re not saying these were planted here maliciously necessarily, but these were completely unknown to the crane owner Nicholas Fredericksen · ▶ 15:54

one set of credentials for literally everything. So every operator at the port and their third party remote maintenance operators use the same set of credentials that had admin privileges for everything. Nicholas Fredericksen · ▶ 15:15

Key Takeaways

  • 80% of US cranes are ZPMC products, creating a single-point-of-failure supply chain risk.
  • Hidden cellular modems on elevators and spreaders bypass all access management and monitoring.
  • Shared admin credentials across operators and vendors prevent non-repudiation and enable lateral movement.
  • No active malicious activity has been observed, but living-off-the-land attacks are undetectable without centralized logging.
  • Ports should negotiate ZPMC remote access language out of maintenance contracts.

About the Speaker(s)

Lieutenant Commander Kenny Miltenberger commands the 2003 Cyber Protection Team in Alameda, CA. He founded the Coast Guard’s Red Team and previously developed shipboard cybersecurity platforms for Naval Sea Systems Command. He holds a BS from the Coast Guard Academy and an MS from University of Maryland College Park, where he taught binary exploitation.

Lieutenant Commander Nick Fredericksen commands the 1790 Cyber Protection Team in Washington, DC. He helped found the Coast Guard Cyber Maritime Readiness Branch, the primary liaison with maritime industry for cybersecurity. He holds a BS in Operations Research and an MS in Information Systems Management from Florida Institute of Technology.