Maritime Matters: The Scale of the Target
Earth’s surface is 70% water. 90% of the world’s cargo moves by water, worth about $17 trillion annually — 70% of global trade. That access also creates vulnerabilities. “When vessels stall, markets fall.” The attack surface is not just ships but people, processes, and expectations. The goal is to expose systemic fragility in maritime operations, operating at layer 9: people’s confidence in the system.
The COLREGS Attack: Turn Left to Break Trust
COLREGS rules 4 through 19 govern ship encounters. Statistically, when two ships meet, 75% of the time a mariner will do the right thing by not turning to port. For an attacker, turning to port gives the highest chance of breaking the rules and causing confusion. The attack abuses norms: a ship coming directly at you triggers fear and panic. Even if collision is avoided, the target burns extra fuel and comes off course, creating liability and cost.
Real-World Collisions: From Accidents to Attacks
The Costa Concordia ran aground in 2012. 32 died, 64 injured, costs over $2 billion. The USS John S. McCain turned to port near a Liberian tanker in 2017; 10 sailors died, damages over $100 million. Neither ship exceeded 11 mph. In early 2025, 116 Iranian tankers and cargo ships were simultaneously hacked, isolating communications but not control systems. No casualties, but it shows the rules of the road become critical in an emergency.
Scaling the Impact: Chokepoints and Economic Devastation
One ship blocking the Suez Canal in 2021 caused a queue of 400 ships, 100 kilometers long, waiting two weeks. After 9/11, air travel lost $22 billion in 12 months — $60 million per day. But a strike at the Port of Los Angeles cost $3.1 billion per day — 51.4 times that daily rate. Attackers should think waterways, not just ships. A single port turn in a sensitive location can ripple through global logistics.
Attacking the Port Ecosystem: AIS, GPS, Digital Charts
Ports are pressure points. Automated cranes run OT with no cyber defense. AIS is unauthenticated VHF from the 1960s — readable and spoofable by anyone. GPS jamming and spoofing are well-known. Digital charts replace paper; modified charts can make a ship believe a hazard isn’t there. Ransomware in aging systems works. Attackers could even capsize a ship or mess with ballast using targeted malware.
Breach of Trust at Scale: Lessons from Tylenol, Halloween, and 9/11
The 1982 Tylenol poisonings cost $325 million in recalls and created the foil seal. Fewer than 90 documented Halloween candy tampering incidents between 1958 and 1983 still made “check your kids’ candy” a cultural norm. 9/11 permanently changed airport behavior generations later. The point: a single incident or even the threat of one can permanently alter trust in a system. Maritime is next.
Q&A
Can DSC be exploited similarly to AIS? Research exists on both; any aperture on a vessel is a concern. Upgrading the entire global fleet is the challenge. ▶ 24:01
How about the human side? Playing with hearts or wallets gets people to ignore warnings. A social engineering message with a maritime flavor could produce effects without technical attacks. ▶ 24:53
Notable Quotes
when vessels stall, markets fall Amp · ▶ 2:29
the right bit in the wrong place can make all the difference in the world Data · ▶ 14:20
fear at scale is how you create one of the most powerful societal exploits ever Data · ▶ 22:08
the weakest link in the chain of trust that we have today Amp · ▶ 19:45
Key Takeaways
- Turn a ship to port to exploit the 75% rule-abiding norm and trigger panic.
- One port turn can cascade into billion-dollar economic damage through chokepoints.
- Public trust in maritime systems is the real target — break that and the rest follows.
About the Speaker(s)
Amp spent 10 years driving ships around the globe — now captains a CTF team instead. With an undergrad in electrical engineering and working on a master’s in info systems engineering, Amp made the jump from maritime grit to digital ops. They co-host episodes of Sea Control (CIMSEC) and The Yoke Report.
Data is a retired Air Force Cyber Warfare Officer with over 20 years of operational experience. He’s a CNODP and RIOT grad with a Comp Sci BS from the USAF Academy and a Master’s in Cyber Ops. He has engaged nation-state-level actors in all domains alongside Five Eyes partners and helped make the starship badges seen around DEFCON.