Disclaimer: Passive reconnaissance only. No active testing, no credential attempts, no scanning beyond publicly indexed data collection. Findings reflect publicly accessible services as of August 2026. Endpoints may have changed status since discovery.
When I was young I watched Logan's Run. There's a scene where a robot explains that the sea ran out of protein, so they started farming humans. It was supposed to be science fiction. It was supposed to be a warning about a world pushed past its limits.
It did not happen the way the movie said. The sea did run out of protein, but instead of harvesting humans, we learned to farm the ocean itself. Modern aquaculture is industrial process control -- PLCs, SCADA, continuous environmental sensors, automated feeders, underwater cameras with AI, cloud platforms pulling data from farms in different countries. The control systems look a lot more like a water utility or a small manufacturing plant than most people realize.
And almost nobody is treating them like critical OT.
Before we get into the security problems, it is worth acknowledging what modern aquaculture actually does. It feeds hundreds of millions of people with protein that does not require stripping the oceans. Wild fish stocks are collapsing or maxed out in every major fishery on the planet. Aquaculture is the only way to keep meeting global demand for seafood without emptying the sea.
The technology behind this is genuinely impressive. Real-time environmental monitoring. Automated feeding that reduces waste and improves feed conversion ratios. Underwater cameras and AI analytics that track fish health without physical contact. All of it running in some of the harshest environments on Earth -- North Atlantic storms, Pacific swells, offshore installations in freezing currents -- and keeping fish alive and healthy at industrial scale.
It is also, by design, the future of sustainable seafood. Land-based recirculating aquaculture systems eliminate discharge into open water. Precision feeding reduces pollution. Remote monitoring cuts the need for boats and crew in dangerous conditions. If you want to feed a growing population while leaving wild ecosystems alone, this is the only path that scales.
Which is exactly why it deserves better protection than it is getting.
Dissolved oxygen, salinity, temperature, pH, flow meters, automated feeders, pumps, underwater cameras, biomass estimators, lice counters. Most of this talks Modbus RTU/TCP, CAN bus, or proprietary serial.
PLCs and HMIs that watch the water parameters, run feeding cycles, manage aeration and water exchange, and throw alarms when something drifts. You are seeing Modbus TCP, OPC UA, and more MQTT every year for the cloud-connected sites.
Central farm management systems that pull data from multiple sites, optimize feed, track health metrics, and give operators remote access from offices, phones, and tablets. Classic SaaS on top of OT.
Sea cages and offshore installs come back to shore over satellite, cellular, and VPNs. Those links carry telemetry, video, and control commands. That is a long, exposed wire.
I ran a set of passive reconnaissance queries against aquaculture infrastructure. Here is what turned up as of mid-August 2026.
Several major aquaculture technology suppliers have discoverable internet-facing endpoints -- VPN portals with basic authentication, IoT MQTT brokers on public cloud providers, API gateways, development environments that probably should not be public, and at least one OT SCADA-style platform hosted on AWS and reachable without authentication.
The genuinely concerning findings are not the expected ones. A vendor VPN portal is supposed to be internet-accessible. An API gateway behind auth is functioning as designed. The problems are the things that should not be there: development systems exposed on public cloud, OT platforms reachable without credential gates, and South American servers running Microsoft SQL Server and RDP side by side on legacy Windows.
Modbus TCP (port 502) shows up across every major aquaculture-producing country:
| Country | Port 502 Endpoints |
|---|---|
| Norway | 144 |
| Chile | 296 |
| United Kingdom | 25,957 |
| Canada | 9,080 |
| Faroe Islands | 8 |
| Iceland | 42 |
MQTT brokers (IoT sensor connectivity and cloud integration):
| Country | MQTT Brokers |
|---|---|
| Norway | 516 |
| Chile | 320 |
| Canada | 2,360 |
Not every port-502 endpoint belongs to a fish farm. AB Regin controllers are used in building management and HVAC systems too. But the density of Modbus and MQTT services in countries whose economies are dominated by aquaculture points to a clear conclusion: the integration points between on-site OT systems and internet-accessible cloud platforms are real, they are discoverable, and they are not hidden.
An attacker does not need to find a specific fish farm PLC. They need to find the cloud platform that connects to it. And those platforms are on the open internet.
When a fish farm control systems go down, fish die. Not eventually -- in hours.
Stop automated feeding for 48 to 72 hours on a high-density cage and you lose the crop. Spoof dissolved oxygen readings and operators see normal numbers while the fish suffocate. Cut aeration pumps and the oxygen crashes fast. Override a PLC and the damage is done before anyone walks out to the cage.
This is why this sector is especially hard to secure. The installations are remote -- coastal locations, offshore cages, rough environments. Hardware fails regularly from salt corrosion and weather. The people running these operations think about fish biology, not network security. And ownership is split: the sensor vendor, the platform provider, the farm operator, and the connectivity supplier all touch pieces of the system without a single party owning the full security picture.
This is not an unexplored problem. It is an ignored one.
The international aquaculture insurance sector published warnings nearly seven years ago about the increasing automation of fish farms and the growing need for cyber preparedness. Their recommendation was that farm owners should be actively managing their position to ensure cyber preparedness is increasing and vulnerability is decreasing. Seven years later, that recommendation has not been adopted at scale.
One of the largest aquaculture technology providers in the world was hit by a ransomware attack in 2023 that forced them to isolate portions of their infrastructure. The incident cost an estimated $6 million in a single quarter and directly impacted operations, not just corporate IT. This was not a theoretical risk. It was a realized one.
Technology firms operating in South America have been actively working on OT security for the regional aquaculture industry and have presented security tools at major industry trade shows. Public statements from cybersecurity leaders in the region emphasize that security cannot be approached reactively and must be part of the operation design, with a focus on anticipation, continuous monitoring, and resilience.
The broader food and agriculture sector saw at least 167 ransomware attacks in 2023 and 40 more in Q1 2024 in the U.S. alone. Major companies including Dole, Sysco, and Mondelez were hit. Aquaculture is part of this broader target set, but it receives almost none of the cybersecurity attention that goes to crop production or meat processing.
The problem is not that nobody has identified the risk. The problem is that the people who have identified it -- insurers, technology vendors, and cybersecurity firms -- do not have the authority to require aquaculture operators to act on it.
NERC CIP exists for power. NIST SP 800-82 and IEC 62443 exist for industrial control systems broadly. But aquaculture has none of this.
We checked every major producing country:
Norway produces roughly half the world's farmed Atlantic salmon. The Norwegian Food Safety Authority regulates food safety and fish welfare under the Aquaculture Act. The Norwegian Security Authority publishes ICT security principles, but these are guidance, not mandatory requirements, and none are written for aquaculture operators. A large fish farm operator could fall under Norway's Digital Security Act if classified as a critical service, but that determination is case-specific, not industry-wide. The result is that a sea-cage salmon operation with internet-connected SCADA, automated feeding, and remote monitoring systems has no regulatory obligation to inventory those systems, segment those networks, or secure access to them.
Chile is the second-largest producer. SERNAPESCA enforces sanitary and reporting obligations -- mortality tracking, veterinary treatments, fish health data -- with real fines for non-compliance. But SERNAPESCA has no cybersecurity standard for salmon farms. Chile's Law 21.663 (Ley Marco de Ciberseguridad) establishes cyber obligations for essential services and critical operators, but aquaculture is not specifically included in its scope.
Canada regulates aquaculture under environmental and fisheries frameworks. No OT security provisions exist in federal or British Columbia provincial regulation.
Scotland and the Faroe Islands operate under UK and local fisheries regulation. Neither has addressed OT cybersecurity for fish farms.
Australia is the exception. Its Critical Infrastructure Act 2021 includes aquaculture within its scope, imposing mandatory cyber risk management obligations on large operators. This is the only country we found that has treated aquaculture digital infrastructure as critical.
The global standard for OT security -- IEC 62443 -- exists and could be applied to aquaculture today. It defines zone-and-conduit segmentation, asset inventory requirements, and access controls. But it is not mandated for fish farm operators in any major producing country except Australia, and even there it is not specifically tailored to the aquaculture environment.
The standard already exists. It just needs to be applied.
IEC 62443 is the international standard for industrial automation and control system security. It is technology-neutral, vendor-neutral, and designed for exactly this kind of environment: sensors, controllers, HMIs, networked systems, and human operators. It does not need to be rewritten for aquaculture. It needs to be adopted.
The five steps below are IEC 62443 principles applied to fish farms:
Asset inventory. You cannot protect what you cannot name. Every sensor, PLC, HMI, gateway, and cloud endpoint needs to be catalogued. This is IEC 62443 Zone Model Step 1.
Network segmentation. Field devices on isolated loops. Control systems on a separate network. Cloud access through authenticated gateways only. No Modbus TCP on the internet. Ever. This is zone-and-conduit design.
Access control. Multi-factor authentication on every remote access point. No shared credentials. No factory-default passwords on satellite modems or sensor gateways. Engineering workstations should not be accessible from the open internet.
Incident response. A plan for what happens when the dashboard goes dark. Because it will. IEC 62443 requires documented recovery procedures and tested backups.
Vendor accountability. Technology suppliers should ship systems with security baselines, not with default credentials and open APIs. The standard places responsibility on both the operator and the supplier.
Aquaculture is the answer to a hard question: how do you feed a growing population with sustainable protein while leaving wild ecosystems alone? The technology works. The scale is already there. And it is growing.
But it is an industry running on industrial control systems with no OT security standards, built by small integrators, connected to the internet via remote links, and operated by people who think about fish, not firewalls.
It is the same problem we saw in water treatment, oil and gas, and power generation -- just ten years behind, and with even less attention.
The fish are not the only things at risk.