logo_tag
Back

Public Flight and Ship Trackers Create Commercial Intelligence Risk, TrendAI Warns

Why It MattersThe finding highlights a structural blind spot in aviation and shipping security, since publicly broadcast tracking data sits outside both corporate IT oversight and cybersecurity monitoring.

A technical brief from cybersecurity firm TrendAI, titled "Rethinking the External Attack Surface: Managing the Growing Risk of Open Cyber-Physical Data," warns that publicly accessible flight- and vessel-tracking systems expose corporate operations to competitive intelligence gathering. Aircraft broadcast identity and position via ADS-B roughly once per second, while ships use AIS to report position every two to ten seconds and destination details roughly every six minutes, with both streams freely accessible on public tracking platforms.

Public Flight and Ship Trackers Create Commercial Intelligence Risk, TrendAI Warns

TrendAI researchers found that automated, mass collection of this data can be carried out with equipment costing as little as US$25, drawing on thousands of volunteer-run receivers already feeding tracking platforms worldwide. Requests are routed through residential devices and short-lived cloud servers, making bulk collection hard to distinguish from ordinary internet traffic, while AI tools can aggregate feeds and spot recurring patterns in seconds rather than the hours such analysis once required.

TrendAI notes that a sustained rise in a company's corporate jet movements can signal merger and acquisition activity before any public announcement, and that shipping data can reconstruct supply chain relationships never publicly disclosed. The report cited a Chinese company's claim to have detected the US military build-up ahead of Operation Epic Fury — the US strikes on Iran that began 28 February 2026 — by monitoring aircraft and ship movements.

Gareth Redelinghuys, country managing director of TrendAI Sub-Saharan Africa, said South African airlines, airports, ports and logistics operators are part of the same exposure, naming OR Tambo and Cape Town International airports as visible on public flight trackers, and Durban and Cape Town port activity as visible on public vessel trackers. TrendAI said most companies have no department responsible for monitoring this exposure, since cybersecurity teams focus on internal systems and the underlying data is neither stolen nor held by the organisation.

Related Coverage · 1 stories

Travel Tech: When flight trackers expose your secretsgadget.co.za
Keep Exploring