Your company’s attack surface now includes planes, ships and weather stations

TrendAI researchers say public sensor data can now be collected and analysed at a scale that exposes far more about an organisation than its security team may realise.

A company can lock down its servers, patch its endpoints and still have a surprising amount of information about its operations sitting in public view. Aircraft broadcast their positions, ships transmit navigational data, weather stations publish readings, cameras stream video and logistics systems track cargo as it moves around the world.

Most of that information exists for good reasons. Aviation and maritime telemetry improves safety, scientific data is shared because researchers need it, while other information is published for regulatory or commercial transparency. On their own, many of these feeds look harmless. The problem starts when somebody collects several of them, combines the information and looks for patterns.

new TrendAI reportRethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data, argues that this kind of public telemetry now needs to be treated as part of an organisation’s security exposure. The researchers looked at aircraft, ships, radio receivers, cameras, weather sensors and other sources that can reveal what is happening in the physical world, often without touching the organisation’s network at all.

The interesting part isn’t any one data source, but what can be inferred when several of them are viewed together.

The intelligence work is getting cheaper

Extracting intelligence from public information isn’t new. What TrendAI says has changed is the amount of work that can now be automated and the cost of doing it.

The report describes a five-layer process covering collection, transportation, fusion, analysis and dissemination. At one end are distributed sources such as volunteer-operated ADS-B receivers, AIS networks and publicly accessible radio equipment. At the other is something much closer to a commercial intelligence platform, where all of those signals can be processed and presented through an ordinary-looking dashboard.

AI makes the middle of that process far more efficient. Different kinds of telemetry can be cross-referenced rather than examined one at a time, while TrendAI says agentic large language models can reduce some analytical work that previously took hours to seconds. The report’s argument is that analyst capacity is becoming less of a bottleneck because more of the joining, pattern recognition and interpretation can be automated.

The same pattern is already visible in AI-driven cyber outbreak prediction, where the useful part of AI is its ability to recognise patterns inside volumes of activity that would be difficult for people to process manually. Here, that capability can be applied to information sitting outside the organisation being watched.

That doesn’t mean an AI model looking at enough public data suddenly knows the truth. TrendAI acknowledges that automated fusion can produce confident but incorrect conclusions, which creates a different problem when those conclusions are acted on quickly. Faster analysis is useful, but faster analysis of a bad inference is still a bad inference.

Confidential business can leave visible footprints

The commercial examples in the report make this easier to understand because much of the information involved doesn’t look like corporate data.

TrendAI uses mergers and acquisitions as one example. The negotiations between two companies may remain confidential while the physical activity surrounding those negotiations does not. An unusual increase in corporate aircraft travelling between locations can be visible through ADS-B, while shipping activity, regulatory disclosures, commercial satellite imagery or changes around facilities may add other clues.

None of those signals proves that an acquisition is taking place, but combined they may provide enough information for someone watching closely to infer that something unusual is happening before either company announces it. TrendAI says an adversary or competitor could potentially use those signals to identify the parties involved, estimate timing or position itself before the information becomes public.

The same problem extends beyond dealmaking. Container and port information can help expose relationships between suppliers and customers. The report says power consumption combined with other signals may offer clues about activity at an industrial site, while cameras overlooking gates and yards can reveal vehicle movements, operating patterns and the comings and goings of staff.

Security teams would normally look for sensitive information leaking from systems they control, but much of this data can originate somewhere else. A charter company owns the aircraft, a logistics provider manages the container tracker and a landlord may run the camera or weather station. The organisation being observed may not have administrative access to any of them, yet those systems can still reveal useful information about how the business operates.

Security scanners won’t necessarily find this

TrendAI argues that cyber-physical telemetry often falls between existing organisational responsibilities. It isn’t necessarily a software vulnerability, so a vulnerability scanner won’t flag it. The equipment may not appear in the company’s asset register because somebody else owns it, while responsibility for the exposure may be split across information security, physical operations, legal teams and other parts of the business.

The researchers recommend that organisations create an open-telemetry exposure register alongside their conventional IT asset register. That could include the movements of corporate or chartered aircraft, vessel activity, regulatory feeds, commercial imagery and sensors located around facilities. Supplier and contractor activity may need to be included too because the company doesn’t have to own the source for the information to expose something useful about its operations.

Not all of that data can or should disappear. Public aviation, maritime and scientific information exists because openness creates genuine value. The better question is whether every source needs to disclose the same amount of information, at the same precision and in real time.

For equipment an organisation does control, TrendAI recommends fairly ordinary security measures. Authentication can be required where appropriate, unnecessary location information can be removed and automated access can be restricted. Some public feeds may also be able to publish less precise information or introduce a delay without undermining the reason the data exists in the first place. The more difficult problem is everything the company can’t switch off.

TrendAI says it found signs of industrial-scale collection

The research goes beyond describing what somebody could theoretically do with public telemetry. TrendAI says it observed nodes it assesses as belonging to suspected China-aligned operational relay box, or ORB, networks repeatedly connecting to publicly exposed radios, weather stations, AIS collectors and other cyber-physical data sources.

An ORB network can route traffic through residential connections, compromised consumer equipment and other distributed infrastructure, making automated collection more difficult to distinguish from normal internet activity. Instead of large numbers of requests arriving from one obvious source, they can appear to come from unrelated consumer connections.

TrendAI believes the patterns it observed are consistent with larger-scale intelligence collection. That attribution is the researchers’ assessment rather than proof of who ultimately operated or directed every connection, but the broader security issue doesn’t depend on that attribution being correct.

The infrastructure already exists for enormous quantities of public information to be collected. AI has reduced some of the work required to interpret it, while commercial platforms can package the results into something that looks less like traditional intelligence gathering and more like ordinary enterprise software.

The attack surface is bigger than the network

Cybersecurity teams already spend a huge amount of time trying to discover what their organisations have accidentally exposed to the internet. TrendAI’s research suggests they may also need to pay attention to what the organisation reveals when every individual system is working exactly as intended.

That can include data generated by equipment the company doesn’t own, information it is legally required to publish and physical activity that becomes visible because another system is recording it. None of those things necessarily qualifies as a security failure on its own, but the result changes when enough of them are collected and analysed together.

A forgotten server sitting on the internet still deserves attention, but the attack surface may now also include things security teams have traditionally regarded as somebody else’s problem, including the plane carrying the company’s executives.

Zeen Social Icons