CHOKEPOINTS UNDER PRESSURE | CYFIRMA Strategic and Cyber Threat Assessment

Published On : 2026-09-30
Share :
CHOKEPOINTS UNDER PRESSURE |  CYFIRMA Strategic and Cyber Threat Assessment

Cyber, Conflict, and Coercion at the Seams of Global Trade

A CYFIRMA Strategic and Cyber Threat Assessment | Reporting window: 4 June – 20 September 2026

This assessment reflects intelligence available as of 20 September 2026. The threat-picture section covers 4 June – 2 September 2026; the incident table covers 1 March – 2 September 2026; developments from 31 August to 20 September are covered separately.

EXECUTIVE SUMMARY

Global trade runs through a small number of physical and non-physical chokepoints, and the sustained disruption of the Strait of Hormuz since March 2026 has shown how quickly pressure on one of them propagates through the transportation and logistics operators that depend on it. This report situates Hormuz within that wider landscape – four further maritime corridors, four non-geographic chokepoints and the concentration of maritime hardware in Chinese state-linked firms – and sets out CYFIRMA’s assessment of the cyber threat to the Transportation & Logistics sector over the 90 days to 2 September 2026, with developments to 20 September noted separately.

The operational finding is that cyber disruption to the sector no longer requires an operational-technology (OT) compromise. Three incidents in the window – North Carolina State Ports Authority, CEVA Logistics and Nichirei – halted physical cargo, warehouse or cold-chain operations through IT-only intrusions. At the same time, CISA, the FBI and the Environmental Protection Agency (EPA) have publicly attributed sustained targeting of internet-exposed control systems across US critical infrastructure to Iran-affiliated actors – activity CYFIRMA assesses to be directly relevant to transportation OT, and cyber-enabled cargo theft rose by a reported 60% in 2025. Since 31 August, a self-described Houthi-affiliated persona has claimed intrusions against Saudi logistics and mobility targets alongside reported Houthi gains on the Red Sea coast; CYFIRMA has not verified these claims. Since early September, US agencies have been reported to be tracking suspected network compromises aboard nearly 20 vessels, including tankers that lost communications for more than a day.

CYFIRMA assesses that state and state-aligned actors increasingly treat cyber, kinetic, and economic pressure on chokepoints as interchangeable levers. For operators, the planning assumption should be that disruption at several chokepoints simultaneously is a standing feature of the environment, and that periods of pressure on any one of them widen the cyber target set to the ports, hubs and logistics IT around it. These assessments reflect the intelligence available at the time of writing and should be read alongside each organisation’s own controls and monitoring.

KEY JUDGEMENTS

Confidence levels: High – multiple independent, authoritative sources or CYFIRMA’s own observation; Moderate – credible reporting or analytical judgement with some corroboration; Low – a single source, a self-claim, or an analytical inference not yet corroborated.

  • IT-only intrusions at logistics operators are now producing physical cargo, warehouse, and cold-chain disruption without any OT compromise; CYFIRMA assesses this to be a leading near-term operational cyber risk to the sector. (High confidence – three independently reported incidents in the window.)
  • Iran-affiliated targeting of internet-exposed programmable logic controllers (PLCs) is publicly attributed by CISA, the FBI and the EPA across US critical infrastructure; CYFIRMA assesses that this activity is directly relevant to transportation OT and that periods of chokepoint pressure raise the likelihood of this activity being directed at port, rail and pipeline OT. (Moderate confidence.)
  • State and state-aligned actors increasingly treat cyber, kinetic and economic pressure on chokepoints as interchangeable instruments selected for calibrated effect. (Moderate confidence – analytical judgement drawn from the Hormuz, Panama and rare-earth cases.)
  • Cyber-enabled cargo-theft losses in North American freight rose sharply in 2025, to a reported $725 million, a 60% increase on 2024. (High confidence – FBI IC3 figures.)
  • Vessels themselves are becoming direct cyber targets through satellite-linked edge devices, with US agencies reported to be monitoring nearly 20 ships for suspected compromise in September 2026. CYFIRMA assesses that at-sea intrusions will increasingly accompany chokepoint pressure. (Moderate confidence – public reporting; no attribution made.)
  • Self-described Houthi-affiliated hacktivist personas are claiming intrusions against Saudi logistics and mobility targets in step with reported Houthi territorial gains on the Red Sea coast. CYFIRMA has not verified these claims and assesses their value as an indicator of targeting intent rather than of capability. (Low confidence – actor self-claims only.)

STRATEGIC CONTEXT: WHY CHOKEPOINTS MATTER

Maritime trade accounts for roughly 80% of global commerce by volume, according to UNCTAD’s Review of Maritime Transport, and functions as the largely invisible backbone of modern prosperity. The past twelve months’ disruptions – above all the sustained disruption of the Strait of Hormuz and the Bab al-Mandab Strait that CYFIRMA reported on in August – have undercut the assumption of a frictionless, borderless global economy and exposed how heavily that economy depends on a small number of vulnerable corridors.

The legal framework that has underpinned global shipping for decades is under growing strain. In a rare joint statement on 8 September, the Consultative Shipping Group (CSG) – an 18-member grouping of the world’s leading maritime nations, including Greece, Singapore, Denmark, Japan, Canada, the UK, the Netherlands and South Korea, together representing more than a fifth of global trade by tonnage – warned that the legal principles historically protecting free navigation and the neutrality of commercial vessels are breaking down. This is reported to be the CSG’s first public intervention in its more than 60-year history, which itself signals the scale of member states’ concern.

According to the CSG’s statement, the confrontation over the Strait of Hormuz, the disruption of the Covid-19 pandemic and the growth of a sanctions-driven “shadow fleet” operating largely outside Western regulatory oversight are not episodic shocks but signals of a structural shift in the operating environment of global trade. The group further warned that shipping routes are increasingly instruments of leverage and risk, a framing CYFIRMA assesses is consistent with the chokepoint dynamics described throughout this report. Officials linked to the CSG are reported to have added that the assumption underpinning decades of globalisation – that ships can move freely across borders – is now under pressure, and that the level playing field established by the International Maritime Organization (IMO), the UN body responsible for shipping regulation since 1948, can no longer be taken for granted.

Because no navy can escort every vulnerable lane at once – a constraint public reporting on Western fleet capacity has made increasingly explicit – the practical burden of chokepoint resilience falls on the operators who depend on them. Periods of acute pressure around a chokepoint also reliably widen the cyber target set to the logistics operators, ports and shipping hubs that depend on it, because disrupting the surrounding infrastructure produces a comparable coercive effect to disrupting the chokepoint itself, often with greater deniability.

Striking this logistics layer through the cyber domain concurrently with, rather than separately from, disruption to the chokepoint itself maximises the combined effect for an attacker – a dynamic available to state-aligned and non-state actors alike. According to public statements by the US military, the opening phases of both Operation Epic Fury against Iran and the operation to capture President Maduro in Caracas paired cyber and electronic-warfare action with kinetic strikes rather than sequencing them. CYFIRMA assesses that this template is at least as replicable against civilian logistics nodes as against military ones.

Attackers are not waiting for open conflict. According to research by NHL Stenden University of Applied Sciences in the Netherlands, reported by the Financial Times in July 2024, shipowners, ports and other maritime organisations faced at least 64 cyber incidents in 2023, against three in 2013 and none in 2003. More than 80% of incidents since 2001 with an identified attacker were attributed in the dataset to actors in Russia, China, North Korea or Iran.

THE CURRENT THREAT PICTURE: TRANSPORTATION & LOGISTICS (90-DAY WINDOW)

Drawing on CYFIRMA’s monitoring of the 90 days from 4 June to 2 September 2026, this section sets out the cyber threat picture specific to the Transportation & Logistics sector.

Nation-state OT threat to transportation infrastructure is elevated

On 22 July, CISA, the FBI and the EPA updated their joint advisory (AA26-097A) on Iran-affiliated actors exploiting internet-connected PLCs across US critical infrastructure, expanding its scope from Rockwell Automation devices to Schneider Electric and Siemens equipment and documenting modification and deletion of project-file logic. The advisory addresses critical infrastructure broadly rather than naming transportation specifically; CYFIRMA assesses the activity to be directly relevant to the transportation sector because the same PLC families are deployed across port, rail and pipeline OT. Related Iran-linked activity reportedly affected some 30 US water systems in late July.

Cyberattacks on logistics IT are cascading into physical disruption

CYFIRMA assesses a consistent pattern across three incidents in the window: IT-only compromises, with no reported evidence of OT intrusion, nonetheless halted physical cargo, warehouse or cold-chain operations.

On 4 August, a system-wide IT outage forced the North Carolina State Ports Authority to revert to manual gate processing at Wilmington, Morehead City and the Charlotte Inland Port. The incident was reportedly contained the same day, with no threat actor publicly attributed and no reported evidence of OT compromise or data theft.

Between 29 July and 1 August, a breach of order-processing systems at eight European warehouses operated by CEVA Logistics – a CMA CGM subsidiary – reportedly halted shipments and exposed customer data, with downstream effects reported at Valve/Steam, Ajax, Bol, De Bijenkorf, ING and Ace & Tate. No ransomware group had claimed responsibility as of disclosure, and CEVA’s core ocean, air, ground and rail operations were reported unaffected.

On 13 July, Nichirei – reportedly Japan’s largest refrigerated-storage operator – disconnected systems supporting roughly 140 distribution centres, disrupting frozen-food shipments to an estimated 5,000 customers; downstream effects were reported at KFC Japan, Aeon and Kura Sushi. RansomHouse claimed responsibility and later leaked data, though CYFIRMA notes this attribution rests on the group’s own claim rather than independent confirmation.

Data-extortion incidents with unverified attribution and scope

Uber Freight confirmed a data-security incident after a leak-site listing on 6 August by an actor using the handle “Helix” – which Google is reported to have linked to the UNC6671 cluster – claiming roughly one million files; Uber Freight stated the incident was contained with no operational impact and did not verify the attacker’s data-scope claim.

Manchester Airports Group disclosed on 27 August a breach in which the extortion group FulcrumSec claimed theft of roughly 86 GB of data via a third-party marketing platform, exposing personal information for an estimated 8.7 million customers; the company reported no card-data exposure or operational disruption and stated it refused the ransom demand.

Frontier Airlines disclosed in July a confirmed intrusion (12 May to 3 June) affecting roughly 11,482 individuals’ personal data, distinct from a separate, unverified 26 July leak-site claim by an actor using the handle “ExfilSquad” alleging a further 43 GB stolen.

A long-standing, unpatched rail vulnerability remains exploitable

CISA’s advisory on CVE-2025-1727 describes an unauthenticated radio-frequency (RF) protocol vulnerability in the End-of-Train/Head-of-Train system (CVSS base score 8.1) that could allow an attacker with a software-defined radio to transmit unauthorised brake commands. The underlying weakness has reportedly been known for some 13 years, and the Association of American Railroads is replacing affected devices, with a fix not expected before 2027. CYFIRMA assesses that this vulnerability remains a credible, low-cost attack vector against North American rail operations for the foreseeable future.

Cyber-enabled cargo theft continues to grow

According to an FBI Internet Crime Complaint Center (IC3) public service announcement (I-043026-PSA), cargo-theft losses across the United States and Canada attributed to threat actors impersonating brokers or carriers are estimated to have reached nearly $725 million in 2025, a reported 60% increase over 2024, with incident counts up 18% and an average reported loss of $273,990 per incident.

Vessels as direct targets: suspected intrusions at sea

Ships are increasingly becoming direct targets of cyberattacks, and the incidents are no longer isolated. In late August, according to Bloomberg (18 September 2026), the US Coast Guard and FBI boarded two foreign-flagged oil tankers in the Gulf of Mexico after both vessels had shown signs of network compromise while transiting the Strait of Gibraltar. One, the VL Prosperity – a South Korean-managed tanker reported to be carrying two million barrels of crude – lost communications for more than 30 hours. US officials are reported to be investigating possible Iranian involvement, though no formal attribution has been made. Iranian state media amplified the story with unconfirmed details; CYFIRMA does not treat that coverage as evidence of Iranian involvement.

The incidents are part of a broader pattern. A third vessel, the LNG carrier Vivit Africa, suffered a suspected cyberattack in early September while sailing towards Italy, leaving its crew unable to access internal control systems; the ship turned away from its destination and was reported off Tunisia on 18 September with its cargo undelivered. According to Bloomberg (16 September 2026), US agencies were by then monitoring nearly 20 vessels worldwide for similar threats, and the Coast Guard has requested advance notice from any of those ships before they enter US ports. Ports face the same pressure: the Port of Los Angeles reported blocking around 120 million attempted cyberattacks in August 2026, against roughly 40 million a month in 2022 (Bloomberg, 18 September 2026).

What makes ships particularly exposed is their growing connectivity. Every major system – navigation, engines, cargo monitoring – is now linked via satellite to shore-based control centres, creating what maritime cybersecurity executives, quoted by the Financial Times, describe as “a floating attack surface”. According to the Financial Times reporting (18 September 2026), attacks that infiltrated vessels through satellite-linked edge devices rose from 3% of all incidents in 2024 to 22% in 2025. Shipowners have also increasingly adopted Starlink to improve crew connectivity, adding, in CYFIRMA’s assessment, a further entry point. Once inside the satellite connection, an attacker could in principle reach onboard operational systems, including propulsion and cargo-temperature control; CYFIRMA has not identified a publicly reported case in which this occurred in the window.

Developments since late August: hacktivist claims and Red Sea escalation

On 31 August, a hacking persona calling itself Uways Qarani, which describes itself as affiliated with the Houthi movement, claimed to have breached Al Saif Transportation Company, one of Saudi Arabia’s largest logistics firms, amid escalating tensions between the Houthis and the Kingdom (Figure 1). CYFIRMA has not independently verified the claim.

Figure 1 – Screenshot of the Al Saif Transportation claim posted by the Uways Qarani persona on a dark-web forum, 31 August 2026. Unverified actor claim; reproduced for reference.

According to public reporting, a Houthi ground offensive took the port of Mokha within days, and reports the following day indicated that Houthi forces had also secured Mayyun (Perim) Island. If confirmed, this would leave the Houthis in control of most of Yemen’s Red Sea coastline, with forces reported roughly 20 kilometres (12 miles) from the African shore – a position CYFIRMA assesses would strengthen the group’s ability to strike shipping in the Bab al-Mandab Strait. The Houthis have stated that their campaign in the strait is now directed at Saudi-linked shipping only, a narrower framing than earlier phases of the campaign, when vessels were struck indiscriminately.

On 10–11 September, according to public reporting, drones launched from Iraqi territory controlled by Iran-linked militias struck pumping infrastructure on the East-West pipeline near Riyadh and Medina, prompting Saudi Arabia to shut the line as a precaution. The pipeline, with a reported capacity of around 4–5 million barrels per day, is the Kingdom’s principal overland bypass around the Strait of Hormuz. With the Houthis now controlling the Red Sea coast, however, Saudi crude reaching the pipeline’s Red Sea terminal at Yanbu must still transit waters newly exposed to Houthi attack, pushing some cargoes toward the longer Suez and around-Africa route to reach the Kingdom’s largely Asian customers.

Saudi Arabia is now under pressure on both of its Hormuz-bypass options simultaneously: the East-West pipeline has been disrupted at source, while the Red Sea loading route it feeds is exposed to a Houthi position that is reported to have become materially stronger. If genuine, cyber activity of the kind claimed against Al Saif would compound this pressure. CYFIRMA has identified no evidence that the claimed intrusion was coordinated with the kinetic activity; temporal proximity alone is not treated as evidence of coordination. Days later, Iranian Parliament Speaker Mohammad Bagher Ghalibaf referred to the rise in oil prices in a post on X, suggesting that standard inflation models now needed terms for pressure on the Strait of Hormuz and the Bab al-Mandab Strait.

In a further claim on 13 September, the same persona asserted that it had breached and disabled Waselni, a Saudi online taxi and ride-hailing service, stating that its aim was, in its own words, “to paralyse the artery of movement in the Kingdom of Saudi Arabia” (Figure 2).

Figure 2 – Screenshot of the Waselni claim posted by the Uways Qarani persona on Telegram and the persona’s own website, 13 September 2026 (Arabic). Gist: the persona claims to have breached and disabled the service and to have published its driver, passenger, and trip databases. Download link obscured by CYFIRMA. Unverified actor claim; reproduced for reference.

The persona also claimed to have published the platform’s driver, passenger, trip, and transaction databases, and asserted that the records could be used to trace Saudi military and security personnel. CYFIRMA has not independently verified any element of this claim.

Earlier in September, the same persona claimed to have gained control of the industrial control and SCADA systems of an unnamed Israeli desalination facility (Figure 3). CYFIRMA has not independently verified the claim, and no publicly observable evidence of disruption was identified in the material available for review. It is recorded here only as an indicator of the persona’s stated target set.

Figure 3 – Screenshot of the desalination-facility claim posted by the Uways Qarani persona on Telegram, 1 September 2026 (Arabic and Hebrew). Gist: the persona claims control of the control systems of an Israeli desalination facility. Unverified actor claim; reproduced for reference.

Individually, claims of this kind should be treated with a high degree of scepticism: hacktivist personas across this ecosystem routinely exaggerate scope, recycle old data, or opportunistically claim credit for outages and disruptions that have entirely unrelated causes. However, their aggregate value lies elsewhere: taken as a set, these claims can indicate which sectors and target types a given actor or ecosystem currently regards as symbolically and strategically desirable.

TRANSPORTATION & LOGISTICS HUB CYBER INCIDENTS

Ports, airports, shipping, rail and trucking-linked cyber incidents, 1 March – 2 September 2026

CYFIRMA compiled the incidents below from public reporting and official advisories. Where an incident rests on a threat actor’s own leak-site claim or self-attribution rather than victim or official confirmation, this is noted; such claims, including data-volume figures, should be treated as unverified. Two incidents that fall just outside the window but are closely related are noted beneath the table for continuity. Acronyms: ICS – industrial control system; BEC – business email compromise; PII – personally identifiable information; SSN – Social Security number; CRM – customer relationship management; FRA – Federal Railroad Administration; SMART-TD – Transportation Division of the International Association of Sheet Metal, Air, Rail and Transportation Workers; PSA – public service announcement.

Date Target / Hub Type What Happened Attribution Reported Impact
4–6 Apr 2026 Multiple European airports (Heathrow, CDG, Frankfurt, Copenhagen, Oslo) Airport / aviation IT Disruption to a shared aviation IT provider used for check-in, boarding, and baggage No actor publicly confirmed Manual fallback; mass delays and cancellations across several hubs
16 Apr 2026 US freight and passenger rail (FRA/SMART-TD alert) Rail (advisory) Warning of reconnaissance/access attempts against internet-connected rail ICS Iran state-affiliated actors, per FRA warning No confirmed disruption; precautionary alert to rail operators
30 Apr 2026 US/Canada trucking and freight brokers (sector-wide) Trucking / cargo Cyber-enabled cargo theft: load-board fraud, compromised carrier accounts, BEC Unattributed; criminal, per FBI IC3 ~$725M in estimated 2025 losses (+60% YoY), per FBI IC3 PSA
12 May–3 Jun 2026 (disclosed Jul) Frontier Airlines Airline Intrusion; exfiltration of employee/passenger PII (SSNs, passport numbers) Unattributed (confirmed breach); separate ExfilSquad claim unverified ~11,482 individuals confirmed affected; class actions filed
13 Jul 2026 Nichirei (Japan cold-chain logistics) Cold-chain logistics Systems disconnected; frozen-food distribution disrupted RansomHouse (self-claimed) ~140 distribution centres hit; ~5,000 customers incl. KFC Japan, Aeon, Kura Sushi
22 Jul 2026 Stadler Rail (Switzerland) Rail manufacturer Ransomware extortion attempt; $12M demand refused Everest group (self-claimed) No confirmed operational/production disruption reported
22 Jul 2026 US critical infrastructure (CISA/FBI/EPA advisory AA26-097A) Multi-sector OT Exploitation of internet-exposed PLCs (Rockwell, Schneider, Siemens) Iran-affiliated actors, publicly attributed by CISA/FBI/EPA ~30 US water systems hit in related activity; transportation relevance is a CYFIRMA assessment
29 Jul–1 Aug 2026 CEVA Logistics (CMA CGM subsidiary) Freight / warehousing Breach of order-processing systems at European warehouses Unattributed; no group claimed responsibility 8 European warehouses halted; customer data reportedly exposed at Valve/Steam, ING and others
4 Aug 2026 North Carolina State Ports Authority Seaport System-wide IT outage; gate systems isolated Unattributed 3 ports shifted to manual gate processing; contained same day
6 Aug 2026 (claimed) Uber Freight Freight brokerage Data-theft claim via leak-site listing “Helix”, reportedly linked by Google to UNC6671; not verified by Uber Uber reports no operational impact; ~1M files claimed (unverified)
7–13 Aug 2026 Wesco (global supply-chain distributor) Distribution Data-theft claim (customer/employee/CRM records) ExfilSquad (self-claimed) Confirmed incident under investigation; ~2.6M records claimed (unverified)
10 Aug 2026 (disclosed date) Trezor customers, via ShipMonk (fulfilment/shipping provider) Shipping / fulfilment Third-party shipping-provider breach Unattributed ~14,000 customers’ shipping/contact data exposed across 7 countries
27 Aug 2026 Manchester Airports Group Airport Breach reportedly via a third-party marketing platform (Iterable, per MAG’s disclosure) FulcrumSec (self-claimed) ~8.7M customer records exposed; no card data, no operational disruption

Just outside the window but closely related: the Adriatic Port Authority (Ancona, Italy) disclosed a breach dating to 11 December 2025, attributed to Anubis ransomware when the group claimed it in January 2026; and Tulsa International Airport disclosed unauthorised file access between 17 and 20 January 2026, later linked by ransomware tracking and media reporting to the Qilin group.

BEYOND HORMUZ

While the Strait of Hormuz has dominated headlines, and the Red Sea route has been degraded since the Houthi declaration of a blockade of Saudi Arabia on 20 July (according to public reporting, as recorded in CYFIRMA’s Hormuz assessment), four further maritime chokepoints carry comparable or greater systemic risk to the global economy.

Beyond the kinetic and legal pressure described in this report, CYFIRMA assesses that straits such as the Taiwan Strait and canals such as Panama are each exposed to a distinct cyber pathway that could compress their throughput without a vessel ever being touched. In the Taiwan Strait, the port-community, terminal-operating and vessel-traffic management systems that coordinate transit on either side of the strait are, in CYFIRMA’s assessment, a lower-cost, more deniable alternative to a blockade for degrading shipping flow, particularly if timed alongside PLA exercises to compound the disruption.

The Panama Canal presents a narrower but comparably sensitive attack surface: the canal authority’s own scheduling and lockage-control systems, together with the port-community platforms at the disputed Balboa and Cristóbal terminals and the digital infrastructure of the Panama ship registry, are the points through which congestion, delay or documentation disputes could be manufactured or worsened during a period of political friction, achieving an effect similar to a physical slowdown without requiring one.

Taiwan Strait

The Taiwan Strait carries roughly a fifth of global maritime trade and around half of the world’s container fleet, according to a 2022 Bloomberg analysis of vessel-tracking data. It is highly exposed to disruption from PLA exercises, which public reporting indicates have included live-fire and quarantine drills. Beyond cargo transit, Taiwan is reported to manufacture roughly 90% of the world’s most advanced semiconductors, which creates a chokepoint in its own right. East Asian shipping hubs reliant on the strait are estimated to process some 95% of global shipbuilding output. Bloomberg Economics has estimated that a full blockade of Taiwan could reduce global GDP by roughly 5%. For the logistics sector, the exposure is concentrated in the port-community, terminal-operating and vessel-traffic systems of the East Asian hubs on either side of the strait – the digital nodes through which pressure short of a blockade would first be felt.

Strait of Malacca

The Strait of Malacca funnels close to a quarter of global trade through a channel as narrow as 1.7 miles (2.7 kilometres) at its tightest point, according to the US Energy Information Administration, making it the indispensable link between East Asian and Western markets. The strait reportedly carries some 45% of seaborne oil shipments alongside substantial vehicle and grain cargo. Its geographic constriction is compounded by a long-standing security problem: the surrounding waters have historically been, and remain, one of the world’s most significant piracy hotspots. The logistics dependency on the strait concentrates in a small number of Singaporean and Malaysian port, bunkering and vessel-traffic systems, which are the natural cyber targets for any actor seeking a coercive effect short of physical interdiction.

Mozambique Channel

The Mozambique Channel has emerged as the primary alternative route during Red Sea disruptions and is estimated to carry close to 30% of global tanker traffic. Beyond transit, the channel’s Rovuma Basin is estimated to hold more than 100 trillion cubic feet of natural gas, and intensifying competition among major powers for offshore energy assets is likely to raise the channel’s strategic profile further as global energy security concerns deepen. The channel’s reliance on a handful of ports and offshore LNG facilities with limited cyber maturity makes it the corridor where a single successful intrusion would have the least redundancy behind it.

Panama Canal

The Panama Canal, the primary route for an estimated 40% of US container traffic according to the US Federal Maritime Commission, has become a focal point of US–China geopolitical friction. Following a February 2026 Panama Supreme Court decision revoking port concessions previously held by Hong Kong-based CK Hutchison, trade operations reportedly slowed markedly at the Balboa and Cristóbal terminals; China is reported to have responded by detaining Panama-flagged vessels, a step that directly threatens a registry that flags more than 14% of the world’s merchant fleet (UNCTAD registry statistics). Separately, the canal faces a recurring operational constraint through the 2026 dry season. The canal’s own operating technology, the two disputed terminals’ port-community systems and the Panama ship registry are the digital nodes through which the dispute could be pressed without a vessel being touched.

BEYOND GEOGRAPHY: NON-PHYSICAL CHOKEPOINTS

Chokepoints arise wherever a single country, company or alliance gains near-total control over a vital economic node for which no viable substitute exists. Traditionally this was understood in physical terms – narrow waterways such as Hormuz, Malacca or the Bosphorus – but recent decades of globalisation have produced financial, technological and resource-based chokepoints that are just as capable of being weaponised through state-backed cyber operations and geopolitical coercion. CYFIRMA identifies four that bear most directly on the logistics sector: the US dollar system, involved in roughly 90% of global foreign-exchange transactions according to the BIS Triennial Central Bank Survey; semiconductor supply chains, which rest on a tightly concentrated ecosystem spanning US design expertise, Dutch photolithography equipment (ASML) and Taiwanese foundries; Chinese dominance of rare-earth and permanent-magnet processing, where exports reported by the US Geological Survey at around $3.5 billion in 2024 sit against projected global losses from a major supply cut-off that the IEA puts in the trillions of dollars – for this chokepoint, the digital nodes of most direct concern are the export-licensing and customs-clearance systems that gate individual shipments, and the industrial control systems at processing and separation facilities, since a licensing decision and an intrusion could each independently choke supply; and US cloud infrastructure.

The last of these is the one that bears most directly on the sector’s own digital operations. US cloud infrastructure represents an emerging, and to date largely unweaponised, chokepoint: the three largest US providers are estimated by Synergy Research Group to hold roughly two-thirds of the global cloud infrastructure market, and the port-community, freight-management and telematics platforms on which the sector runs are overwhelmingly hosted on them. A disruption to that layer – whether by intrusion, by sanction or by outage – would propagate through logistics IT faster than any physical closure.

CHINESE MARITIME CONCENTRATION AND ALLEGED DUAL-USE RISK

Beyond the four non-geographic chokepoints above, China’s structural dominance of the global maritime sector constitutes an emerging chokepoint in its own right, combining commercial concentration with an alleged surveillance dimension that Beijing disputes.

On 1 September 2026, Reuters reported, citing US officials, that vessels operated by China’s state-owned COSCO – one of the world’s largest maritime services companies – carry concealed equipment capable of intercepting military communications near foreign coastlines, including that of the United States. COSCO has denied the allegation. Similar concerns have been raised about other Chinese state-linked maritime firms: a 2024 joint investigation by the US House Committee on Homeland Security and the Select Committee on the CCP reported that ZPMC, the state-owned manufacturer of an estimated 80% of ship-to-shore cranes at US ports, had installed cellular modems on some cranes that could enable remote access, while the state-linked logistics platform LOGINK is reported to aggregate shipping data from ports worldwide, giving Beijing potential visibility into sensitive commercial traffic, according to US Maritime Administration Advisory 2023-009. In August 2026, UK officials told The Telegraph that cameras installed on British naval drones had sent data to an internet address in China.

CYFIRMA assesses that these risks are compounded by China’s National Intelligence Law, which obliges Chinese companies and citizens to support state intelligence work on request. Taken together with the COSCO, ZPMC and LOGINK allegations described above, CYFIRMA assesses that this legislation gives the state a legal route to draw on the assets and data of the specific firms concerned, and that this could convert commercial advantage in peacetime into military advantage in a conflict. No wider inference about Chinese companies collectively is drawn here. CYFIRMA has previously described China’s “military-civil fusion” policy in TikTok: China’s Digital Weapon System.

COSCO illustrates the pattern. Chinese law – notably the National Defence Transportation Law of 2017 – requires Chinese-owned transport and port operators to support military logistics on request, and Piraeus in Greece, in which COSCO holds a majority stake, hosted a People’s Liberation Army Navy (PLAN) visit in 2017. While there is no direct evidence that the visit was made under that obligation, the point is the practical naval reach the holding provides even though Beijing maintains only one declared overseas naval base.

Separately from the surveillance dimension, China’s market concentration across maritime infrastructure is itself a structural vulnerability for other states. China is reported to control more than half of global shipbuilding capacity, and according to Nikkei Asia, to have captured more than 80% of new shipbuilding orders in the first half of 2026, alongside roughly 70% of the global ship-to-shore crane market, 95% of dry shipping container manufacturing and 86% of intermodal chassis production – leaving few alternative suppliers for importing states.

CYFIRMA assesses that this concentration across maritime hardware – from chassis and containers to cranes and ships – creates a structural dependency whose digital nodes (crane PLCs and their remote-access modems, port-community and terminal-operating systems, and vessel AIS/satcom equipment) could, in a crisis, be used to constrain capacity, delay supply chains, or support intelligence collection and cyber operations without any naval deployment. No such use was identified in the material reviewed.

THE CONVERGENCE POINT: WHY CHOKEPOINTS ARE THE NEXT CENTRE OF GRAVITY

CYFIRMA assesses that the defining vulnerability of the next phase of the global economy will not be any single chokepoint’s physical closure, but the convergence of cyber, kinetic and political pressure applied to several chokepoints at once – geographic and non-geographic alike. The pattern is already visible: digital reconnaissance and pre-positioning inside energy and port infrastructure regularly precede or accompany physical strikes and diplomatic coercion rather than substituting for them, blurring the line between espionage, sabotage and statecraft.

This dynamic is not confined to maritime straits or to a single lever. The same logic increasingly applies to dollar-clearing systems, semiconductor supply chains and the small number of cloud providers underpinning global logistics IT – each a node where a cyber intrusion, a targeted sanction or a kinetic disruption can substitute for one another depending on which is cheapest, least attributable or least likely to trigger escalation at a given moment. CYFIRMA assesses that state and state-aligned actors increasingly treat these instruments as interchangeable levers within a single toolkit, selected for calibrated effect rather than category of action. For transportation and logistics operators specifically, this means the operative question is no longer “is my route open?” but “which combination of digital, physical and political pressure is currently being applied to the chokepoints my supply chain depends on, and by whom?”

China’s tightening control over critical minerals illustrates this in practice. Beijing has progressively expanded export licensing requirements on rare earths, gallium, germanium and associated processing technology in recent years. CYFIRMA assesses that Beijing’s licensing regime functions as much as an instrument of geopolitical leverage as a trade measure: public reporting records it being tightened and relaxed in step with disputes unrelated to the minerals themselves, including trade friction with the United States and diplomatic disputes with Japan. Because Chinese processors handle a large majority of the global rare-earth supply chain regardless of where the ore is mined, this leverage extends well beyond Beijing’s own export volumes to the wider processing chain, leaving few near-term substitutes at scale. CYFIRMA treats the export-licensing portals, customs data exchanges and processing-facility OT associated with this supply chain as priority intelligence-collection points, on the basis that monitoring them offers the best prospect of detecting a further tightening before it is publicly announced.

In a Taiwan contingency, CYFIRMA assesses that three of the chokepoints described in this report could be brought under pressure simultaneously – transit through the Taiwan Strait, semiconductor supply from the island, and rare-earth exports to any party deemed hostile – with a coordinated cyber campaign against logistics, shipbuilding, mining or manufacturing nodes compounding each. This is an analytical scenario, not a prediction. Figure 4 summarises the pressure recorded against each chokepoint during the reporting window.

Figure 4 – Chokepoint pressure matrix: levers observed against each chokepoint, 4 June – 2 September 2026. Cells summarise the findings of this report and CYFIRMA’s Hormuz assessment; “observed” records that pressure was reported, not who applied it.

CONCLUSION

Chokepoint disruption and cyber-enabled disruption are converging on the same sector, and increasingly on the same targets. As of 20 September 2026, throughput through the Strait of Hormuz and the Red Sea is simultaneously degraded; IT-only cyber intrusions are producing physical cargo disruption without touching operational technology; and CISA, the FBI and the EPA have publicly attributed sustained targeting of internet-exposed industrial control systems across US critical infrastructure to Iran-affiliated actors, activity CYFIRMA assesses to be directly relevant to transportation OT. None of this is confined to the Middle East, or to any single mode of transport. As the chokepoint assessment in this report sets out, the same concentration risk with no ready substitute extends from physical straits to the dollar, to semiconductors, to rare earths and to the cloud infrastructure underpinning the sector’s own digital operations. For transportation and logistics operators, CYFIRMA’s assessment is that the operative planning assumption should not be that any one chokepoint returns to normal, but that pressure on several simultaneously is now a standing feature of the operating environment.

Transportation and logistics operators should therefore treat periods of chokepoint pressure – wherever they occur – as periods of heightened cyber exposure rather than as purely physical supply-chain events, with particular emphasis on identity security and third-party access, internet-facing infrastructure, the resilience of manual fallback processes, and the segmentation that keeps an IT compromise from becoming an operational one. This assessment is based on the intelligence available at the time of writing and is subject to change as the situation develops.