This essay argues that ZPMC crane vulnerabilities create a hardware-based, state-backed security risk, distinct from typical software attacks and difficult to quickly replace. Although the $20 billion federal response recognizes this problem, it does not address it with sufficient urgency.
The Architecture of Dependence
To understand the ZPMC vulnerability, it’s important to see how one Chinese state-backed company came to supply most of the cranes that handle American trade. The reason is simple and reflects a larger trend in the Chinese industry. ZPMC sold cranes that were good enough at prices Western companies could not match. Their state-backed financing meant they did not need to make a profit. They also provided technical support from Chinese engineers at U.S. ports (Newsweek, 2024). Western crane makers like Germany’s Liebherr, Finland’s Konecranes, and Japan’s Mitsui could not compete on price. By the late 1980s, American companies had stopped making ship-to-shore cranes altogether. This market logic led to a strategic problem. By the time the national security risks became clear, more than 200 ZPMC cranes were already in use at U.S. ports. These cranes were fully assembled, connected to networks, and supported by ZPMC engineers. ZPMC engineers still had remote access to the systems they installed (Manufacturing Dive, 2024; Newsweek, 2024).
Rear Admiral Jay Vann, who leads U.S. Coast Guard Cyber Command, explained the security risk clearly at a White House press briefing: “By design, these cranes may be controlled, serviced, and programmed from remote locations. These features potentially leave PRC-manufactured cranes vulnerable to exploitation” (Newsweek, 2024, para. 5). The MARAD Cybersecurity Study also found that ZPMC cranes can be controlled, serviced, and programmed remotely, depending on their individual configurations. While this makes sense for maintenance, it is risky when the manufacturer is required by Chinese law to cooperate with state intelligence agencies (MARAD, 2024). The congressional investigation found that ZPMC had “repeatedly requested” remote access to its ship-to-shore cranes at several U.S. ports. This was especially true on the West Coast, where U.S. military equipment, supplies, and personnel would need to move in a Pacific crisis (Industrial Cyber, 2024; Fox Business, 2024).
The most concerning finding from the congressional investigation was not just a possible risk. There was real evidence of hardware with no clear purpose being installed on cranes already working at U.S. ports. The investigation found cellular modems on ZPMC crane parts on multiple occasions. These were not included in any contract, and port officials could not explain them (CNN, 2024). At one port, more than a dozen of these modems were found on crane components. In another case, a separate cellular modem was found in a server room at a port, inside the equipment that manages the cranes’ firewall. This was exactly where someone would need access to get around network security controls (House Committee on Homeland Security, 2024).
The congressional letter to ZPMC made it clear: the modems “do not appear in any way to contribute to the operation of the STS cranes or onshore infrastructure, raising significant questions as to their intended applications” (Fox Business, 2024, para. 6). Recorded Future News said these devices create “an obscure method to collect information, and bypass firewalls in a manner that could potentially disrupt port operations” (The Record, 2024, para. 3). House Homeland Security Committee Chairman Mark Green summed it up: “These weren’t in the design specs, and they got placed in there without telling anybody” (CBS News, 2025, para. 5). Chris Krebs, former Director of the Cybersecurity and Infrastructure Security Agency and now a CBS News cybersecurity consultant, called it “the number one cyber risk facing the United States right now” (CBS News, 2025, para. 7).
The congressional investigation also found that supply chain issues make the hardware risk even worse. Lawmakers saw that many port contracts with ZPMC “allowed critical internal components from third-party contractors to be sent to the People’s Republic of China for installation by ZPMC engineers” (Industrial Cyber, 2024, para. 4). For example, parts made by Swiss company ABB—which works with the U.S. Navy, NASA, Coast Guard, and other agencies—were shipped to China, stored there for months, and then installed on cranes headed to the U.S. by ZPMC staff (Industrial Cyber, 2024). When Congress asked ABB to fix these supply chain risks in its China operations, the company refused (Industrial Cyber, 2024). Congress was clear. ZPMC “could, if desired, serve as a Trojan horse capable of helping the CCP and the PRC military exploit and manipulate U.S. maritime equipment and technology at their request” (Industrial Cyber, 2024, para. 2).
This vulnerability becomes more serious when you consider U.S. military logistics and planning for a possible conflict over Taiwan. CBS News cybersecurity analyst Krebs explained the concern: “They’d hit a port, particularly on the West Coast, because that’s how we move material, that’s how we move equipment. That’s how we’re gonna move personnel in some cases. The Chinese are preparing for war” (CBS News, 2025, para. 8). The Wilson Center added the economic angle. Worries about ZPMC and the Chinese logistics platform Logink focus on the idea that “control over the flow of goods and information about them gives Beijing privileged insight into world commerce and potentially the means to influence it”—information about cargo origins, destinations, volumes, and schedules that is key for economic and military planning (Wilson Center, 2024, para. 3).
The Port of Long Beach runs day and night with some automation. ZPMC cranes there handle $200 billion in trade each year. Port CEO Mario Cordero told CBS News that shutting down a port could mean “a $2 billion hit a day in the local economy” (CBS News, 2025, para. 10). If several West Coast ports—like Los Angeles, Long Beach, Seattle, Tacoma, and Oakland—were disrupted at once, the result would be huge economic losses and problems for military logistics. The congressional investigation found that two Chinese state-owned companies have stakes in five U.S. ports. These firms also lead major port investments worldwide. The Wilson Center described this as China’s long-term strategy to control “who controls the ports through which the world’s commerce flows” and noted that “the U.S. is just now waking up to their importance” (Industrial Cyber, 2024; Wilson Center, 2024, para. 5).
The federal response to the ZPMC vulnerability has been significant and bipartisan, but replacing the cranes is moving much too slowly, given the urgency of the threat. Executive Order 14116, signed on February 21, 2024, gave the Coast Guard more power to regulate maritime cybersecurity and issued a classified directive with specific cyber risk rules for operators of PRC-made ship-to-shore cranes (MARAD, 2024; Mayer Brown, 2024). The $20 billion federal investment, funded by bipartisan infrastructure law, restarted domestic crane manufacturing through PACECO Corp., a U.S. subsidiary of Japan’s Mitsui Engineering & Shipbuilding. This is the first time in 30 years that ship-to-shore cranes will be made in the U.S. (Manufacturing Dive, 2024). On June 10, 2025, the Senate passed the Maritime Supply Chain Security Act, just after the House, letting U.S. ports use federal grants to replace Chinese-made cranes and control systems with equipment made in the U.S. or by allied nations (CrossDock Insights, 2025).
According to the MARAD report, the U.S. Coast Guard had checked 92 out of more than 200 ZPMC cranes at U.S. ports for threats and vulnerabilities. This is a big effort, but it still covers less than half of all the cranes (MARAD, 2024; Manufacturing Dive, 2024). The MARAD study found that after reviewing all government reports and speaking with everyone involved, no one knew of any foreign-made crane at a U.S. port that was actively exploited. The answer was consistently “no” (MARAD, 2024, para. 4). However, the absence of a record of exploitation does not necessarily indicate the absence of risk. It could mean that access has been set up and left unused until it is needed most.
The timeline issue is built into the system. Starting domestic crane manufacturing, increasing production, and replacing over 200 cranes at 23 ports will take 10 to 15 years, even in the best-case scenario. The Trump administration, which began in January 2025, said it “wants American-made equipment to handle cargo at U.S. ports,” keeping the same policy on crane replacement (CBS News, 2025). For at least the next decade, while ZPMC cranes are still in use at U.S. ports, the risks Congress found—modems that bypass firewalls, remote access requests from a state-owned company tied to Chinese intelligence, and supply chain parts that spent months in China—are not just past problems. They are current, ongoing risks.
The Wilson Center said the crane replacement program only addresses “the tip of the iceberg” when it comes to vulnerabilities in maritime commerce (Wilson Center, 2024, para. 1). Other equipment at U.S. ports—like cargo scanners, logistics platforms, terminal operating systems, environmental sensors, access controls, and communications systems—face similar risks. These systems face the same supply chain issues and often lack contractual controls to prevent backdoors or unauthorized access. SecurityWeek pointed out that “most, if not all, global crane manufacturing companies that serve as alternatives to ZPMC maintain ties to the PRC”—so they are either directly at risk from supply chain problems or could be pressured by business connections in China (SecurityWeek, 2024, para. 5). Replacing ZPMC cranes with Mitsui equipment fixes one known problem but does not fully solve the larger issue of Chinese-made equipment in port infrastructure.
The Foundation for American Innovation, using the MARAD study, found a major data gap that makes the problem worse: U.S. ports do not have a standard way to report even basic information about their crane inventories, much less where their scanning, logistics, or sensor equipment comes from (Foundation for American Innovation, 2023). Some port operators sought to reduce ZPMC risks by using Swiss or German parts, such as those from ABB, but these parts still passed through Chinese facilities for installation (Industrial Cyber, 2024). The difference between “Chinese-manufactured” and “Western-manufactured-but-Chinese-assembled” is not a real security difference—it’s just a matter of paperwork.
The ZPMC crane vulnerability is not a typical cybersecurity issue like software hacks, phishing, or ransomware. This is about physical infrastructure—170-foot steel cranes that cannot be patched, updated, or isolated like software. These cranes have hardware of unknown origin, are maintained via remote access subject to the laws of a rival country, and are located at key points for U.S. trade and military movement. The federal response is real progress: the $20 billion investment, the USCG security directive, the Maritime Supply Chain Security Act, and the restart of domestic crane manufacturing are the right steps. But there is still a big gap between these policies and actual security. It could take more than a decade to close that gap, and in the meantime, the cranes Congress identified as possible Trojan horses will keep moving cargo at every major U.S. port, day in and day out.
CBS News. (2025, February 12). Chinese cranes at U.S. ports raise homeland security concerns.https://www.cbsnews.com/news/chinese-cranes-at-u-s-ports-raise-homeland-security-concerns/
CNN. (2024, March 7). Congressional probe finds communications gear in Chinese cranes, raising spying concerns.https://www.cnn.com/2024/03/07/politics/congressional-probe-communications-gear-chinese-cranes/index.html
CrossDock Insights. (2025, August 1). Chinese cranes in American ports.https://crossdockinsights.com/p/chinese-cranes-in-american-ports-zpmc
Foundation for American Innovation. (2023, August 3). ZPMC and America’s ship-to-shore crane industry: Recommendations for improving port security.https://www.thefai.org/posts/zpmc-and-america-s-ship-to-shore-crane-industry-recommendations-for-improving-port-security
Fox Business. (2024, March 10). Chinese crane firm denies posing security risk at US ports amid investigation.https://www.foxbusiness.com/politics/chinese-crane-firm-denies-posing-security-risk-us-ports-amid-investigation
House Committee on Homeland Security. (2024, March 12). Joint investigation into CCP-backed company supplying cranes to U.S. ports reveals shocking findings.https://homeland.house.gov/2024/03/12/wtas-joint-investigation-intoccp-backed-company-supplying-cranes-to-u-s-ports-reveals-shocking-findings/
Industrial Cyber. (2024, September 13). US House Committees reveal that Chinese-manufactured cargo equipment at ports poses cyber and espionage threats.https://industrialcyber.co/transport/us-house-committees-reveal-chinese-manufactured-cargo-equipment-at-ports-pose-cyber-espionage-threats/
Manufacturing Dive. (2024, February 29). White House moves to onshore port crane manufacturing.https://www.manufacturingdive.com/news/white-house-onshoring-cargo-crane-production-china-zpmc-national-security/708668/
Mayer Brown LLP. (2024, April). Biden Administration announces investment in domestic manufacturing of ship-to-shore cargo cranes.https://www.mayerbrown.com/en/insights/publications/2024/04/biden-administration-announces-investment-in-domestic-manufacturing-of-ship-to-shore-cargo-cranes
Newsweek. (2024, February 22). Biden plans to spend billions replacing China-made cranes at US ports.https://www.newsweek.com/joe-biden-executive-order-us-china-port-crane-maritime-cybersecurity-1872259
SecurityWeek. (2024, September 13). House report shows Chinese cranes a security risk to US ports.https://www.securityweek.com/house-report-shows-chinese-cranes-a-security-risk-to-us-ports/
The Record. (2024, September 26). Chinese-made port cranes in US included ‘backdoor’ modems, House report says.https://therecord.media/port-cranes-china-modems-republican-house-report
U.S. Maritime Administration. (2024). MARAD study of cybersecurity and national security threats.https://www.maritime.dot.gov/sites/marad.dot.gov/files/2024-06/MARAD%20Study%20of%20Cybersecurity%20and%20National%20Security%20Threats.pdf
Wilson Center. (2024). Replacing port cranes just one portion of maritime commerce vulnerabilities.https://www.wilsoncenter.org/article/replacing-port-cranes-just-one-portion-maritime-commerce-vulnerabilities