INTEL_REPORT
Ars Technica — Security · published 4/22/2026, 10:07:54 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Crypto scam lures ships into Strait of Hormuz, falsely promising safe passage Ship attacked by Iran after possibly falling for safe passage crypto scam. Crypto scammers are targeting the thousands of ships stranded near the Strait of Hormuz—and at least one ship that faced Iranian gunfire may have been tricked into believing it had paid Iran for safe passage. The first warning of such a crypto scam came from the Greek maritime risk management company MARISKS on April 20, ac…
https://arstechnica.com/security/2026/04/crypto-scam-lures-ships-into-strait-of-hormuz-falsely-promising-safe-passage
sha256:703f5a72edc6b5dbde392cd091eb402e159ae3b914e36bf1d8fa2b04e24305a8
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
No indicators linked for this report.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.