A ship agency's operations team received a familiar instruction from an owner they'd long worked with: "For this voyage, pay the freight to the updated account attached — our usual bank is under audit, we're temporarily using this account." The voyage number was right, the vessel name was right, the amount matched the charter party. Banking regulations and temporary account use are ordinary in maritime; no one grew suspicious. A six-figure USD freight went to the attacker's account instead of the real, audited one. By the time the real owner asked "where's the payment?", the ship had long been discharged.
Maritime is one of the most-targeted sectors for email fraud globally, and the reason is structural: very high-value, foreign-currency freight/demurrage transfers; a many-link chain of owner-agent-charterer-broker; 24/7, time-pressured operations; and the natural communication gap of a ship at sea cut off from the shore office. In this article we cover the sector's threat vectors and defense.
1. Why Is the Maritime Workflow a Global Target?
- High value, foreign currency, cross-border: Freight, demurrage, bunker (fuel), port charges — all high-value and mostly USD. A cross-border transfer is the hardest money movement to recall.
- Many-link chain: Owner, ship agency, charterer, broker, P&I club, surveyor. Email traffic between every link is a surface where identity verification gets harder — when "the broker's email" is compromised, the whole chain is deceived.
- 24/7, time-pressured operations: The ship doesn't wait; demurrage runs. "Don't delay discharge, send the payment today" pressure melts verification — the maritime version of iron & steel's spot pressure.
- International, multilingual norm: Different countries, banks, and time zones. Explanations like "new/temporary account" or "our bank is under audit" don't seem odd here — telling the fake from the real gets harder.
2. The Four Threat Vectors We See in the Sector
2.1 Freight / Demurrage Payment Redirection
The opening scenario and most expensive vector. An owner, agent, or broker account is compromised or impersonated via a look-alike domain; at the moment of freight/demurrage payment, a "new account" request is dropped into the genuine conversation. The "our bank is under audit / temporary account" story is believable in the sector. Having your own domain's DMARC at reject directly determines your impersonability within the chain.
2.2 Charter Party and Document Lures
Documents like the bill of lading (B/L), charter party, SOF (Statement of Facts), and NOR (Notice of Readiness) circulate constantly by email. Emails themed "updated charter party attached" or "your B/L awaits approval" carry a malicious attachment or a credential-harvesting portal. Operations teams are so accustomed to this document flow that reflexive clicking is high.
2.3 Bunker (Fuel) Supply Fraud
Fuel is among a voyage's largest variable costs, and correspondence with bunker suppliers is heavy. Fake bunker invoices and "payment account changed" requests aim to quickly redirect large sums. Price volatility (oil) here too provides an urgency cover.
2.4 Account Takeover in the Ship-Shore Gap
Personnel aboard reach email over limited/satellite links from shared devices; MFA discipline is looser than at the shore office. A compromised ship or master account allows "internal" conversation with the shore office — internal traffic that gateway protections can't see. We covered the mechanics of this scenario in detail in our ATO article.
3. Field Note: The "Temporary Account" and the Time-Zone Gap
Two patterns repeat in the maritime field. First: most fake account changes arrive with a "temporary/exceptional situation" story — "our bank is under audit," "the transfer is blocked, we're using the group account," "year-end account switch." Because these fit international banking reality, they go unquestioned. Second: the attacker exploits the time-zone gap — writing to the agent while the owner sleeps, to the owner while the agent is closed; the "call the other side" reflex for confirmation gets deferred by the time difference, and the payment goes out unverified.
4. Defense: Three Layers That Span the Chain
Process
For freight, demurrage, and bunker payments, an account change — whatever the justification (audit, temporary account included) — is not processed without confirmation through the channel registered in the contract/charter party. Against the time-zone gap: the payment waits until confirmation arrives; "urgency" doesn't change the procedure. This rule should be written into the agency handbook and standard charter party riders.
Technology
Check Point Harmony Email & Collaboration provides the following in maritime scenarios:
- Look-alike and newly registered domain detection — flags owner/broker/agent impersonation.
- Correspondence-pattern learning — contextually catches the "bank change + temporary-account story" combination arriving in the freight-payment window.
- Attachment analysis (sandboxing) and click-time URL protection on charter party/B/L/bunker document lures.
- Internal and outbound traffic scanning + account-takeover protection — sees emails going from a compromised ship/agent account to the shore office or the customer.
People
Sector-specific simulations for operations, chartering, and finance teams: a fake freight account change (with an audit story), a fake charter party attachment, a bunker invoice lure. The one-sentence rule: "The trio of temporary-account story + urgency + time difference is there to trigger confirmation, not to defer it."
Frequently Asked Questions
With so many parties in the chain, whose security are we responsible for?
You can't control the other links' security, but you can control your own payment process and your own domain. The dual-channel account-change rule protects you even if the other side is compromised; DMARC reject prevents email being sent to the chain in your name.
Doesn't holding payment for confirmation lock up operations because of the time difference?
Only payments containing an account change wait; the normal flow continues. Holding a six-figure freight a few hours for confirmation is always cheaper than losing it entirely. For critical voyages, a 24/7 confirmation channel (an authorized person + a backup number) is defined in advance.
Enforcing MFA aboard is hard; the satellite link is weak. What can we do?
Cutting the attack at the email layer before it reaches the ship (URL/attachment analysis, behavioral flagging) and adding mobile threat protection to devices with corporate access delivers most of the solution. Phishing-resistant authentication is targeted where connection conditions allow.
Can we measure what our current protection misses in these scenarios?
Yes. In a 14-day monitor-mode trial, we report what's missed — owner/broker impersonation, look-alike domains, and freight redirection included — without touching your existing protection.
What Should You Do Now?
If your freight, demurrage, and bunker payments are managed over email, start with one question: "If a 'our bank is under audit, send to the new account' email arrived, would our system and our process catch it?"
- Free Field Audit: Your own impersonability (DMARC), look-alike domain risks, and chain-impersonation exposure — reported.
- 14-Day Check Point Trial (monitor mode): Missed threats in inbound and outbound traffic, reported.
About this article: The eighth article of our Sector Series. Kinetik Bilişim is the Türkiye partner of Check Point Software Technologies at the Advanced Partner 2026 level, holding Email, Endpoint & Browser, Mobile, and SASE Solution Specialization accreditations. The author, Kemal Özleyen, is a cybersecurity engineer certified as a Check Point Workspace Security Expert. Field scenarios are shared in anonymized form.