High-Value Targets at Sea
LNG tankers cost 300 to 400 million dollars. New ships still run Windows XP. Starlink and 4G/5G make remote attacks easier. Lives are at stake. Integrated systems create a giant attack vector. No one has the full picture of how it all connects.
Undercover Access and War Stories
Bjørkhaug and his colleague board cruise ships as regular guests. They find live network sockets in public spaces, gaming rooms, and bars. They disconnect access points and drag cables into their cabins. One test, cleaning staff saw the cable and reported them as Russian spies. They had to show their authorization letter.
Network Segmentation Failures
On an LNG tanker in Congo, Bjørkhaug assumed breach of the office network. He got domain admin in five minutes. The domain admin password was “administrator”. An electrician’s desktop had passwords.txt with ESXi credentials. The management network was reachable from the office. The ESXi controlled ballast tanks.
Radio Attacks: GPS and AIS
With government permission, Bjørkhaug tested jamming and spoofing on a ship in dry dock. A cheap Chinese GPS jammer, attenuated, caused all GPS screens on the bridge to lose signal. The main screens turned black. He spoofed AIS to create a fake ship with his phone number as ID. He sent man-overboard messages.
Top Five Findings
Network segmentation issues top the list. Default and weak passwords are common. Non-hardened and outdated operating systems (Windows XP, Windows 7) persist. Network equipment lacks hardening, allowing VLAN hopping. Physical security is weak: unlocked doors, large gaps under doors. Service providers often lack customer segmentation.
Notable Quotes
the domain administrator password was administrator John Andre Bjørkhaug · ▶ 14:47
I think it’s one of the quickest domain admins I got I think it was like five minutes John Andre Bjørkhaug · ▶ 14:50
all the all the GPS screens on the bridge lost the signal and for some reason the main screens on the bridge turned black John Andre Bjørkhaug · ▶ 20:41
I’m surprised that no pirates have used this to sneak ships with valuable cargo John Andre Bjørkhaug · ▶ 22:10
it’s working. Don’t touch. John Andre Bjørkhaug · ▶ 22:42
Key Takeaways
- Physical access to ships is trivial via public network sockets.
- Domain admin often achieved in minutes due to weak passwords.
- Radio attacks like GPS jamming and AIS spoofing are easy and dangerous.
About the Speaker(s)
John Andre Bjørkhaug has worked as a penetration tester for over 16 years. He has a degree in electrical engineering but prefers to break things instead of building things. His main focus is penetration testing of internal infrastructure and physical security systems together with social engineering and full scale Red Team tests.