IMB Piracy Reporting Centre: Intelligence Source Guide
The IMB Piracy Reporting Centre is the shipping industry’s single 24-hour point of contact for piracy and armed robbery reports, run by the ICC’s International Maritime Bureau. Its live incident list and periodic statistics are the de facto commercial reference on maritime crime – and they count …
The IMB Piracy Reporting Centre is the shipping industry's single 24-hour point of contact for piracy and armed robbery reports, run by the ICC's International Maritime Bureau. Its live incident list and periodic statistics are the de facto commercial reference on maritime crime – and they count things the law would not call piracy.
At a glance
| Source | IMB Piracy Reporting Centre |
|---|---|
| Category | Conflict, Crime & Human Security › Organised Crime, Gangs & Piracy |
| Homepage | https://web.archive.org/web/20241217084350/https://www.icc-ccs.org/piracy-reporting-centre |
| Format | HTML |
| Access | Open — no account required |
| Disciplines | Maritime Intelligence, Geospatial Intelligence |
| Mission domains | Maritime Piracy, Maritime Security |
Live piracy/armed-robbery incident reports. — as catalogued in the platform’s own source registry.
The Piracy Reporting Centre is a manned watch operated by the International Maritime Bureau, a specialised division of the International Chamber of Commerce, from Kuala Lumpur. It has run continuously since the early 1990s and does three separate jobs that outsiders often conflate. First, it receives reports directly from ships' masters and companies over a permanently staffed line and relays them to local law enforcement and rescue coordination centres. Second, it broadcasts warnings to shipping about recent incidents and active threat areas. Third, it maintains the incident record that becomes the public live piracy report, the piracy map, and the quarterly and annual statistical reports the industry treats as canonical. The public products give you, for each incident, a date, an approximate position, a location description, a vessel type and often the vessel's status and flag, a categorisation of what happened – boarded, attempted, fired upon, hijacked, crew taken – and a short narrative of what the perpetrators did and how the crew and any responding authority reacted. It is not a database in the sense of an API and a schema. It is a curated incident log published as web pages and PDFs.
It exists because there was no other place a master under attack in the middle of the night could call that would both act and remember. Coastal state reporting is fragmented, slow and politically shaped; flag states hear about incidents late; insurers hear about them selectively. The PRC's analytical contribution is that it collects from the victim side of the transaction, directly from the ship, rather than from the enforcement side. That produces a record of incidents that were never investigated, never prosecuted and in many cases never acknowledged by the coastal state in whose waters they occurred – which is precisely the population that state-sourced statistics lose. For maritime intelligence work the practical consequence is that IMB is your independent check on official denial. When a coastal state reports a quiet quarter and the PRC lists a dozen anchorage boardings, the gap between the two numbers is itself the finding, and it is a finding about governance rather than about crime.
Who publishes it, and why that matters
The IMB is not an intergovernmental body and has no enforcement power. It is a non-profit arm of the ICC funded substantially by voluntary contributions from the shipping, insurance and trading industries, which shapes both what it does well and where you should be careful. It does the reporting-and-warning job well because the industry pays for a service it uses. It publishes a statistical record because the industry wants a number to plan and price against. But it is structurally the advocate of the shipowner and the master, and its incident categorisation, its broad working definition, and its willingness to name locations that coastal states would rather it did not all follow from that alignment. Several states have publicly disputed IMB figures over the years and have discouraged reporting through the PRC in favour of national channels, which affects reporting volumes in ways that are not visible in the published data. Read the IMB as an industry watchkeeper with a strong track record and an obvious constituency: reliable on the fact that a ship reported an attack, less neutral on how the resulting number should be interpreted politically, and always partial because it can only count what someone chose to tell it.
Provenance is the first question to ask of any dataset and the one most often skipped. Who collects it, what their incentive is, whether they publish a methodology, and whether they correct the record when they get something wrong all bear directly on how much weight a finding drawn from it can carry.
What a record actually contains
The fields you will be working with, what each one means, and whether it is something you can pivot on. Read the meanings carefully — more analysis is wrecked by misreading a field than by failing to find one, and a field that looks like an observation is often an inference.
| Field | Type | What it means | Pivot value |
|---|---|---|---|
incident reference |
string | A per-report identifier, typically sequential within a year, used in the live report and carried into the quarterly and annual tables. It is the join key between the web listing and the PDF statistics. | Cross-reference to the same incident in the annual report tables and in other incident feeds that cite IMB references. |
date and time |
timestamp | When the attack occurred as reported by the ship, usually with a local or UTC marker. It is not the time the report was received or published, and the publication lag can be a day or several. | Timeline correlation against vessel position history and against other incident feeds; expect small discrepancies from other sources reporting the same event. |
latitude and longitude |
string | The reported position, frequently rounded and sometimes given as a bearing and distance from a landmark or anchorage. For anchorage incidents the position is the anchorage, not the berth. | Geospatial correlation with AIS tracks, port and anchorage polygons, and chokepoint traffic analysis. |
location description |
string | Human-readable place: a strait, an anchorage, a named port approach, or a distance offshore from a coastal town. Often more analytically useful than the coordinates because it names the operating environment. | Port and anchorage entities; grouping incidents by governance regime rather than by raw geography. |
incident type |
enum | What happened, in the IMB's own categories – boarded, attempted boarding, fired upon, hijacked, and variants involving crew being taken. The category is assigned from the master's account, not from a legal finding. | Severity banding and tactic analysis; the primary discriminator between opportunistic theft and organised attack. |
vessel type |
string | Bulk carrier, product or crude tanker, container ship, tug, fishing vessel, offshore support and so on. This is the single best available proxy for what the attackers were targeting and why. | Fleet and cargo risk profiling; cross-reference to vessel registries and to the trades that use each hull type. |
vessel name and IMO number |
string | Present in some reports and withheld in others, depending on what the reporting party permitted. When present, the IMO number is the only durable vessel identity in the record. | Vessel registries, ownership and management chains, port state control history, and AIS identity – always pivot on IMO rather than on name. |
flag |
string | The vessel's flag state at the time of the incident. Useful for the diplomatic and legal dimension, largely uninformative about the crew's nationality or the beneficial owner. | Flag state administration, port state control records, and the question of who has jurisdiction to investigate. |
vessel status |
enum | Whether the ship was underway, drifting, anchored or berthed when attacked. This is the most under-used field in the record and it changes the meaning of everything else. | Distinguishing anchorage theft from underway attack; correlating with port congestion and waiting times. |
narrative |
string | A few sentences describing how many perpetrators there were, whether they were armed and with what, what was taken, whether the crew was harmed or held, and what the ship and any responding authority did. | Weapons, group size, modus operandi and response-quality indicators; the richest field for pattern work and the one that must be read rather than counted. |
crew consequences |
string | Whether crew were assaulted, threatened, taken hostage or kidnapped, and how many. Reported inconsistently in the live listing and more systematically in the periodic reports. | Crew welfare and kidnap-for-ransom analysis; the bridge from maritime security into the kidnap and extortion mission. |
authority response |
string | Whether the PRC relayed the report, whether local forces or a naval unit responded, and what happened. Useful as an indicator of coastal state capability and willingness rather than of the incident itself. | Governance and capability assessment by port and by state; a persistent pattern of no response is a finding. |
Coverage — and what is not in it
Global, with density concentrated wherever ships are slow, close to shore and worth boarding: the Singapore and Malacca Straits, the Indonesian archipelago and its anchorages, the Gulf of Guinea from Ghana round to Cameroon, the anchorages of Bangladesh, the Peruvian and West African port approaches, and historically the Gulf of Aden and the Somali basin. The record runs continuously from the early 1990s in the periodic reports, with the live listing carrying the current rolling window. The rhythm is: reports arrive at any hour, appear on the live listing within a short lag, and are consolidated into quarterly and annual statistical reports that are the citable products. Coverage is of reports, not of incidents. The PRC sees what masters and companies choose to tell it, which means coverage is strongest for vessels whose owners are commercially and culturally aligned with the reporting culture – large internationally managed merchant fleets – and weakest for local craft, fishing vessels, coastal barges and anything crewed by people whose employer has no reason to make a report. In a region where the dominant maritime victim is a small local trader, the IMB record will show you a quiet sea and will be wrong.
Known blind spots
Absence of evidence here is not evidence of absence. These are the conditions under which IMB Piracy Reporting Centre will not show you something that is nevertheless real:
- Under-reporting is the defining limitation and it is not random. Owners avoid reporting because a report can mean an investigation, port delay, off-hire disputes, higher premiums and a charterer's questions, so the incidents least likely to be reported are the minor ones and the ones resolved quietly.
- Local and small craft are largely invisible. Fishing boats, coastal traders, barges and tugs suffer a large share of real maritime crime and rarely report to an international industry body in Kuala Lumpur.
- Some coastal states actively discourage reporting through the PRC and promote national channels instead, which suppresses the IMB count for those waters without any change in the underlying crime.
- The record covers attacks against ships. Maritime crime that does not involve boarding a vessel – smuggling, illegal fishing, trafficking by sea, oil bunkering from pipelines – is out of scope entirely, even though it shares the same actors and waters.
- Crew kidnapping ashore, or an abduction that begins as a port incident rather than a boarding at sea, may fall outside what gets reported here even when the same network is responsible.
- Position data is approximate and sometimes derived from a landmark bearing. It will not support precise geospatial inference, and a cluster of points at a rounded coordinate is a rounding artefact rather than a hotspot.
- Vessel identity is frequently withheld at the reporting party's request, which breaks the pivot to ownership, management and AIS for exactly the incidents where an owner wanted discretion.
- There is no negative reporting. A quiet quarter in the listing is indistinguishable from a quarter in which reporting collapsed, and nothing in the product tells you which you are looking at.
- The IMB working definition is broader than the legal definition of piracy, so its counts include incidents in territorial waters and at anchorage that are legally armed robbery against ships. Comparing an IMB total to a legally defined piracy total is comparing two different phenomena.
Write the blind spot into the product. A statement that something “was not observed in IMB Piracy Reporting Centre” is defensible; a statement that it “did not happen” is not, and the difference is what survives cross-examination.
Access, licensing and what you may do with it
Access model: Open — no account required
The live piracy report and the piracy map are published on the ICC Commercial Crime Services site and can be read without payment. The consolidated quarterly and annual reports have historically been available on request to the maritime industry, sometimes free to shipowners and operators and sometimes on a registration or subscription basis – the arrangement has varied, so establish current terms directly rather than assuming. There is no documented public API, no bulk download, and no machine-readable feed you can rely on: the live product is HTML and the authoritative products are PDFs. Any automated collection is therefore scraping, and it should be treated as such – low frequency, identified user agent, respect for the site's terms, and a human in the loop. For an operator, the sensible pattern is to poll the live listing on a slow cadence for current awareness and to treat the periodic PDF reports as the citable record for anything that goes into a product. If your work involves reporting an actual incident rather than analysing one, the PRC's contact details on that page are the operational route and they matter more than any of the analytics.
Licence
The IMB and the ICC assert copyright over their reports and their incident data, and their publications carry restrictions on reproduction and redistribution. That is the starting assumption you should work from: reading and citing is fine, wholesale republication of the incident tables is not, and commercial redistribution of IMB-derived incident data as your own product is very likely a breach. The terms have not always been stated prominently on the live pages, which tempts people into assuming the data is open. It is not; it is a free-to-read industry service. If your intended use is anything beyond analysis and cited quotation – embedding incident records in a commercial feed, redistributing the map, republishing tables – contact the IMB and get written permission. There is a practical alternative worth knowing: for incident data you need to redistribute freely, the equivalent official government feeds carry no such restriction, and the correct pattern is to build on those and use IMB as the corroborating read.
Rate limits and fair use
No API means no published limits, which places the whole burden on your etiquette. Poll the live listing no more than a few times a day; nothing on it changes faster than that in a way you can act on. Identify your collector with a descriptive user agent and a contact address so the operator can reach you instead of blocking you. Do not attempt to enumerate historical incidents by walking the site. Cache aggressively, honour any error or rate-limiting response by backing off immediately and substantially, and remember that the same infrastructure serves the watch function – degrading it for a master trying to make a report would be a serious thing to do for the sake of a dashboard.
Licensing changes, and it changes without warning. A dataset that was free for research this year may not be free for commercial or evidential use next year. Confirm the current terms before you build a dependency on it, and record the terms you relied on alongside the data — the licence in force at the time of collection is part of the provenance.
Collecting it
How IMB Piracy Reporting Centre is actually pulled, in the order you would set it up. Prefer the bulk or export interface over per-item lookups wherever one exists: it is kinder to the publisher, faster for you, and gives a reproducible snapshot rather than a series of point-in-time answers you cannot reconstruct later.
| Method | Format | Cadence | Notes |
|---|---|---|---|
| Live piracy report page | HTML | multiple times weekly; poll at most a few times daily | The current rolling incident listing. Adequate for current awareness and for triggering an analyst to look, not adequate as an archival record because entries roll off. |
| Piracy map | HTML | continuous | A visual index of the same incidents. Useful for briefings and for spotting geographic clustering quickly; not a data source, since the positions behind it are the same approximate ones. |
| Quarterly and annual reports | HTML | quarterly and annually | The citable statistical products, with consolidated tables, definitions and commentary. These are what you quote in a deliverable, and they include revisions to earlier figures. |
| Warning broadcasts to shipping | HTML | as incidents occur | Operational alerts relayed to vessels. Relevant if you are supporting a shipping client's route planning rather than doing retrospective analysis. |
| Manual analyst capture | CSV | per incident of interest | For case work, transcribe the incidents that matter into your own record with the IMB reference, the date you captured them and a screenshot. The live listing is not a permanent archive and entries you rely on may not be there next quarter. |
Ingesting it into the platform
Every step below is idempotent and cursor-based: interrupt one and it resumes from where it stopped rather than duplicating rows or losing progress. Collection is recorded per source, so a feed that quietly stops publishing shows up as a stale timestamp instead of silently thinning your coverage.
- Register as a manual-review source — Record it in sources.php with an explicit note that collection is HTML-derived and analyst-verified. Nothing from this source should enter the platform with the same automatic confidence as a structured government feed.
- Parse the live listing conservatively — Extract the reference, date, position, location text, incident type, vessel type and narrative. Where a field is absent, leave it null rather than inferring it – an absent vessel name means the owner withheld it, which is itself information.
- Normalise position and record its precision — Convert reported positions to decimal degrees and store a precision qualifier derived from how the position was given. A bearing-and-distance position and a rounded degree-minute position must not be plotted with the same apparent confidence.
- Deduplicate against official incident feeds — Run correlate.php against the government anti-shipping feed and the regional sharing centre reports before creating a new event. The same attack routinely appears in three sources, and counting it three times is the most common data-quality failure in maritime crime work.
- Emit vessel and coordinate data points — Each incident yields a dp_vessel where identity was disclosed and a dp_coordinates constrained by precision. Where an IMO number is present, resolve it to a persistent vessel entity so that repeat victimisation becomes visible.
- Extract modus operandi from the narrative — Structure the narrative into group size, weapons observed, method of approach and boarding, what was taken and whether crew were harmed. This is analyst-assisted extraction; if a language model summarises it in copilot.php, the structured attributes still come from the text, not from the model's knowledge.
- Link to the maritime picture — Push confirmed incidents into ais.php and theater.php so that they sit alongside vessel traffic rather than in a separate incident list. An anchorage boarding means something different when you can see how many ships were waiting there that week.
- Archive the source page — Store a capture of the page as collected, with a timestamp, in the case record. The live listing rolls, the periodic reports revise, and you will eventually need to show what the record said on the day you read it.
Registered sources and their last-collected state are listed in sources.php, and the scheduled chain that keeps them current is in automation.php.
How it is wrong, and how to tell
Every dataset is wrong in characteristic ways. Knowing which ways is the difference between using a source and being used by one, and it is the part of source evaluation most often skipped because it is the part that takes work.
The core fact – that a ship reported being attacked at approximately this place and time, and this is what the master said happened – is reliable. The PRC has a long institutional record, it verifies reports against the reporting party, and it has no incentive to invent incidents. What you should not trust is the completeness of the count or the stability of the categories. Completeness is governed entirely by reporting behaviour, which varies by fleet, by flag, by owner and by the political weather in a coastal state. The categories are assigned from a master's account under stress and are occasionally revised between the live listing and the annual report. Judge quality by triangulation rather than by inspection: take a quarter and a region, and compare the IMB listing to the official government anti-shipping feed and to the regional sharing centre's report for the same period. The three will not match. The size and direction of the mismatch tells you what each source is missing, and after doing this exercise a few times for your areas of interest you will have a working correction factor that is far more valuable than any single source's number.
Characteristic false positives
- Attempted attacks recorded as attacks. A suspicious approach by a skiff, an approach that was deterred, and a successful armed boarding all appear in the same listing, and rolling them into one total inflates severity dramatically.
- Reporting change read as crime change. A fall in incidents at a given port frequently reflects a coastal state discouraging reports or an owner deciding not to report, and the record cannot distinguish that from improved security.
- Legal category confusion. Most incidents in the listing occur in territorial waters or at anchorage and are legally armed robbery against ships rather than piracy, so quoting the total as a piracy figure misstates the phenomenon and can be picked apart by any maritime lawyer.
- Double counting across sources. The same incident appears in the IMB listing, in the official anti-shipping message feed and in the regional centre's report, frequently with slightly different positions and times, and a naive union of the three inflates counts by a large factor.
- Position precision over-read. Rounded and landmark-derived positions cluster artificially, producing apparent hotspots at exactly the coordinates people round to.
- Vessel name matching. Ship names repeat across the world fleet and change with sale and charter; matching an incident to a vessel by name rather than by IMO number will eventually attach an attack to the wrong hull.
- Narrative detail treated as verified. The number of attackers, the weapons and the nature of the threat come from a crew's perception at night under duress, and these details are frequently revised or contradicted later.
- Silence read as safety. A region with no incidents in the listing may be a region where nobody reports, and this failure mode is strongest exactly where governance is weakest and risk is highest.
None of these make the source unusable. They make it a source that requires corroboration before an assertion built on it goes into a product, which is true of every source and admitted by few.
Ageing
There are two clocks. The live listing ages in days: an incident appears, sits in the rolling window, and eventually drops off, so a record you relied on may not be retrievable from the same page a few months later. The statistical reports age in quarters and are revised – figures for a period are restated in later publications as delayed reports arrive and as categories are corrected, which means an annual figure quoted from a first-quarter report will not always match the same period in the annual. The underlying intelligence value ages fastest of all in operational use: a piracy pattern in a specific strait can change within a single season as enforcement posture, monsoon conditions, port congestion or a local conflict shifts, so an assessment built on incidents from eighteen months ago is describing a threat environment that may no longer exist. A stale IMB-derived assessment looks like a risk map whose hotspots are where attacks used to happen, presented with the confidence of a current one. Refresh maritime risk assessments quarterly at minimum, and always state the incident window your assessment rests on.
What this source feeds
A source is only worth what it lets you conclude. These are the disciplines that collect through it, the mission domains it serves and the data points it yields — every one is a tag, so you can follow any thread from here into the rest of the library.
Collected by these intelligence disciplines
Serves these mission domains
Yields these data points
How each sector uses IMB Piracy Reporting Centre
The same dataset is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The records are shared — the constraints, thresholds and outputs are not.
🎖 Military and defence
For naval and maritime security forces, the PRC record is the civilian-side complement to your own operational reporting. It shows where merchant traffic is actually being attacked rather than where you have patrolled, and the vessel type and status fields let you distinguish an environment dominated by anchorage theft from one dominated by armed underway attack – two problems requiring entirely different force posture. Use it to validate that a counter-piracy deployment is reducing incidents rather than displacing them, since displacement shows up as a geographic shift in the listing rather than as a fall in the total. Treat the count as a lower bound on activity, and pair it with your own sensor and boarding data before you assess effectiveness.
🕵 National intelligence
For maritime intelligence, the analytical prize is not the incident count but the divergence between this record and official state reporting. A systematic gap between what ships report to an industry body and what a coastal state acknowledges is an indicator of governance failure, of complicity, or of a deliberate policy of suppression, and each of those supports a different assessment. The narratives are also a usable window on actor capability: group size, weapon type, boarding method and whether attackers came prepared to take crew rather than cargo distinguish an opportunistic local group from an organised network with a market for hostages or product.
👮 Law enforcement
For law enforcement, the practical use is case linkage and jurisdiction. The narratives frequently contain the modus operandi details – method of approach, boarding equipment, what was taken, how the group communicated – that link separate incidents to a single crew, and the flag and position fields determine who has jurisdiction and which mutual legal assistance route applies. The record is not evidence. It is a third-party log of what a master said, hearsay in most systems, and the route to admissible material is the ship's own log, the company's incident report and the master's statement, for which the IMB reference is a locator rather than a substitute.
🔍 Private investigation and corporate security
For corporate security supporting shipping, trading and marine insurance clients, this is the industry's shared reference point and your client is probably already quoting it. Your value is in reading it properly: separating attempted from successful, separating anchorage from underway, correcting for under-reporting in the client's specific trade, and telling them plainly when a quiet listing for a port reflects reporting suppression rather than safety. For due diligence on a route or a terminal, combine the incident record with port congestion and waiting times, because the anchorage risk curve tracks how long ships sit still far more closely than it tracks anything else.
📰 Journalism and OSINT media
For journalists, the PRC is a credible, quotable and long-established source, and the traps are definitional. Do not call anchorage theft piracy in a legal context without saying so; do not compare an IMB total to a coastal state's figure without explaining that they count different things; do not report a fall in incidents as a fall in crime without asking whether reporting changed. The strongest stories here come from the mismatch between the industry record and the official one, and from the human cost in the crew-consequence fields, which are consistently under-reported in coverage that focuses on cargo and insurance.
🌍 NGO, humanitarian and human rights
For seafarer welfare and human rights organisations, the crew consequence fields are the point. Assault, hostage-taking and abduction of crew are recorded here when they are recorded anywhere, and the pattern by vessel type and flag exposes which seafarers carry the risk – typically crews on smaller, older tonnage under flags with weak protection, from labour-supplying states with limited consular reach. Use the record for advocacy on the systemic pattern rather than on individual cases, protect the identity of affected crew, and route any live welfare concern through the established seafarer support organisations rather than through the incident record.
🎓 University and research
For maritime security research, the IMB series is the longest continuous incident record available and it is also the most heavily biased, which makes it a good object of study in its own right. The standard research design compares it against the official government feed and the regional sharing centre to estimate reporting rates, and any paper that uses IMB counts as a straightforward measure of maritime crime without addressing reporting bias will be criticised for it. Note also the licence position: the data is free to read but not open, so plan your replication materials around derived statistics and cited figures rather than around redistributing the incident tables.
Playbook: working IMB Piracy Reporting Centre end to end
A repeatable sequence from first pull to finished product. Each phase states what you are trying to establish, not merely what to click — the objective is a defensible chain of reasoning, not a completed checklist.
Phase 1 — Decide whether you want incidents or reports
Write down which you are measuring. If the question is how much maritime crime is occurring, this source cannot answer it and you need a reporting-rate correction. If the question is what the shipping industry is experiencing and reacting to, this is the right source and needs no correction. Almost every bad piece of piracy analysis skips this sentence.
Phase 2 — Fix the legal frame before you count
Establish whether your product needs the legal definition of piracy, which requires the high seas and excludes territorial waters, or the operational definition of attacks on ships, which does not. Then state which you used. An insurer, a naval lawyer and a journalist need different answers to the same question and will each assume theirs.
Phase 3 — Build a triangulated incident set
Pull the IMB listing, the official anti-shipping message feed and the regional sharing centre reports for the same window and region, then match them on date, position and vessel. You are constructing one deduplicated event set with a source-count attribute per incident, and that attribute is itself a quality signal.
Phase 4 — Split the set by vessel status
Separate underway attacks from anchorage and berth incidents before you do anything else. They have different perpetrators, different weapons, different economics and different countermeasures, and any conclusion drawn over a combined set will be wrong for both.
Phase 5 — Separate attempted from successful
Bucket the incidents by outcome: approached or fired upon, boarded, boarded with theft, boarded with violence, crew taken, vessel taken. Report the ladder, not the total. This one step improves the honesty of a maritime risk product more than any other.
Phase 6 — Read the narratives as a set
Take the narratives for one location and window and read them consecutively looking for repeated method: approach from astern in the dark, use of a hook and pole, targeting of the engine room stores, threat displayed rather than used. Repetition across incidents is the signature of a crew, and it is only visible if you read rather than aggregate.
Phase 7 — Correlate with traffic and congestion
Overlay the incident set on vessel traffic and anchorage occupancy for the same period in ais.php. Incident rate per ship-hour at anchor is a far more meaningful measure than incidents per month, and it will often show that an apparent surge is a congestion effect.
Phase 8 — Test the state-reporting gap
Compare your triangulated count for a coastal state's waters against that state's own published figures. Document the ratio and its trend. This is an assessable indicator of governance and a defensible finding in its own right, and it is one that a client cannot get from the IMB report alone.
Phase 9 — Profile repeat victimisation
Where vessel identity is disclosed, resolve the IMO numbers and look for hulls, operators and trades that appear more than once. Repeat victimisation is usually a routing and behaviour problem – the same slow transit, the same anchorage, the same low freeboard – and it is directly actionable for a client.
Phase 10 — Assess the response side
Code each incident for whether an authority responded and what happened. A location where reports are relayed and nothing follows is a different risk from one where a patrol arrives in twenty minutes, and this distinction rarely appears in commercial risk products because it takes reading the narratives to build.
Phase 11 — State the reporting-rate caveat quantitatively
Rather than a generic warning that under-reporting exists, give the client your estimate and its basis: the source-count distribution from your triangulation, the known local reporting posture, and the fleet composition in the area. An estimate with a stated basis can be argued with; a warning cannot be used.
Phase 12 — Archive and re-baseline
Capture the pages you relied on with timestamps into the case, and diary a refresh. Maritime threat pictures move within a season, and the periodic reports revise earlier figures, so a product older than a quarter should carry an explicit validity date on its face.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
What to pair it with
No single source carries a finding. These are the datasets that corroborate, extend or contradict this one — and a source that contradicts is worth more than one that agrees, because it is the only thing that will tell you when you are wrong.
| Source | Relationship | What it adds |
|---|---|---|
| NGA Anti-Shipping Activity Messages | corroborates | The official US government incident feed, machine-readable and free of licence restrictions. Partly compiled from the same underlying reporting, so treat overlap as duplication rather than as independent confirmation. |
| ReCAAP ISC | corroborates | The Asian government-to-government reporting mechanism, with a stricter legal framing and a severity classification the IMB does not use. Essential for any Asian analysis and the best available cross-check in that region. |
| IMO GISIS | corroborates | The IMO's own incident reporting module, populated by member states rather than by industry, and therefore biased in the opposite direction to the IMB. |
| UKMTO | extends | Operational maritime advisories and incident alerts for the Indian Ocean and Gulf region, closer to real time than any statistical product and oriented to the transiting master. |
| Equasis | prerequisite | Free vessel particulars, ownership and management data. The route from an IMO number in an incident report to the company that actually operates the ship. |
| AIS vessel tracking | extends | Position history around the incident, which corroborates the reported location and time and reveals whether the vessel was drifting, slow-steaming or waiting – context the incident record does not carry. |
| BIMCO | extends | Industry guidance, contractual clauses and best management practice for the affected regions, which is what a shipping client will actually be asked to implement. |
| IMO | prerequisite | The legal framework: the distinction between piracy and armed robbery against ships, the reporting obligations and the code of practice for investigation. |
Legal, ethical and operational constraints
Two distinct legal questions attach to this source. The first is about your use of the data: IMB and ICC material is copyrighted and its redistribution is restricted, so cite and analyse rather than republish, and get written permission before building it into a commercial product. The second is about the subject matter. Maritime crime sits across overlapping jurisdictions – flag state, coastal state, port state, and in the case of piracy proper, universal jurisdiction on the high seas – and an incident's legal characterisation determines who may investigate, who may prosecute, and whether a naval unit may lawfully intervene. Because the IMB's operational definition is deliberately broader than the treaty definition of piracy, an incident classified as piracy in this record may be a domestic robbery in law. Never let that elision into a legal deliverable. On the human side, incidents involve crew who have been threatened, assaulted or held hostage. Their names, nationalities and employers are personal data, frequently relating to people from labour-supplying states with little practical recourse, and any product identifying them requires a lawful basis and a welfare-first approach. If you become aware of a live incident or of a crew still held, the obligation is to route it to the reporting and response mechanisms, not to publish it.
Operational security
Reading the public pages is unremarkable and reveals little beyond an interest in maritime security. Two situations change that. If you are scraping, your collector's address and pattern are visible to the operator, and an aggressive scraper against a body that runs an emergency watch line is both rude and likely to get your range blocked. If you are corresponding with the PRC about a specific vessel or incident on behalf of a client, you are disclosing that client's interest to a body embedded in the shipping industry, where informal information flow between owners, insurers, brokers and security providers is fast. Assume that an enquiry about a named ship may become known to parties with a commercial interest in it. For sensitive commercial or investigative work, collect from the public products and hold specific enquiries until you understand who will learn of them; and where an enquiry is unavoidable, make it through a channel your client has agreed to.
Two rules that hold regardless of jurisdiction. Collection that is lawful is not automatically proportionate, and a dataset assembled for one purpose does not carry consent for another. Where the records concern identifiable people, the question is not only whether you may hold the data but whether holding it serves the purpose you are accountable for.
Is it earning its place?
Sources accumulate. Feeds get added during an incident and are never reviewed again, and a decade later the pipeline is carrying dead weight that nobody dares remove. These are the measures that show whether IMB Piracy Reporting Centre is contributing anything, and they are worth baselining now so the answer is available later.
- Source-count distribution across your triangulated incident set – what fraction of incidents appear in one, two or three of the available records, tracked per region as your working measure of collection completeness.
- Lag between incident date and appearance in the live listing, which tells you whether this source can serve current awareness in your regions or only retrospective analysis.
- Proportion of incidents in your set carrying a disclosed vessel identity, since that fraction bounds everything you can do with ownership, repeat-victimisation and fleet analysis.
- Divergence ratio between the industry record and the relevant coastal state's published figures, tracked over time as a governance indicator rather than as a data problem.
- Share of incidents you can position with better than a rounded-coordinate precision, which determines whether any geospatial product you build is honest.
- Analyst minutes per incident to code the narrative into structured modus operandi attributes, as the practical measure of whether this pipeline scales for you.
- Number of client products in which the attempted-versus-successful ladder was shown rather than a combined total, as a direct quality-control count.
Beware of volume. Indicator counts rise easily and say almost nothing. Unique contribution — findings this source produced that no other source in your stack would have — is the measure that matters, and it is usually far lower than anyone expects.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- The IMB counts attacks on ships, not piracy in law. Know which one your reader needs, say which one you used, and never let the two totals be compared in the same paragraph without a note.
- Vessel status is the most informative field and the most ignored. An anchorage boarding by three men with knives and an underway attack by eight men with automatic weapons belong in different analyses, and the field that separates them is right there in the record.
- Deduplicate before you count. Every serious maritime incident tends to appear in three places, and the analyst who unions the sources without matching them produces an alarming and false trend.
- IMO number or nothing. Ship names are reused, changed on sale and sometimes deliberately duplicated; the IMO number is the only identity that survives, and where it is withheld you should record the incident as unattributed to a hull rather than guess.
- A quiet listing is a hypothesis, not a finding. Before you tell a client a port is safe, establish whether anyone there reports, and say so in the product either way.
- Read the narratives consecutively rather than in isolation. Modus operandi patterns are invisible in a table and obvious after twenty minutes of reading, and that reading is the difference between counting incidents and identifying a crew.
- Normalise incidents against traffic, not against time. Incidents per month rises when more ships arrive; incidents per ship-hour at anchor is the measure that tells you whether the environment changed.
- Treat the response field as a governance sensor. Whether anyone came, and how fast, is often a more useful input to a country risk assessment than the incident count itself.
- Keep your own archive. The live listing rolls off and the statistics get revised, so a capture with a date is the only way to defend a figure you published six months ago.
Questions analysts actually ask
Is there an API or bulk download?
No documented public one. The live report and map are web pages and the authoritative statistics are periodic PDFs. If you need machine-readable maritime incident data with no licence friction, build on the official government anti-shipping feed and use the IMB record as a corroborating read.
Why do IMB figures differ from the coastal state's, or from the regional centre's?
Because they count different things from different reporters. The IMB collects from ships and uses a broad operational definition; states report through official channels using legal definitions and have incentives about the total; regional centres apply their own severity classification. The gap between them is analytically useful and should be explained, not resolved by picking a favourite.
Can I republish the incident table in a client report?
Assume not without permission. The IMB and ICC assert copyright and restrict redistribution. Cite figures with attribution, derive your own analysis, and if you need redistributable rows use the public-domain government feed instead.
Does a fall in reported incidents mean a region got safer?
Not on its own. It can equally mean owners stopped reporting, a state discouraged reporting through this channel, traffic fell, or ships stopped anchoring there. Test each of those before you make the safety claim, and tell the client which you tested.
How much under-reporting should I assume?
There is no single credible figure, and anyone who gives you one without a method is guessing. Estimate it for your own region by triangulating against the other incident records and by considering the local fleet composition, then state your estimate and its basis rather than a generic warning.
Is an incident in this record admissible in a prosecution?
Generally not directly. It is a third-party log of what a master reported. Use the reference to locate the primary material – the ship's log, the company incident report, the master's statement – and build the evidential case on those.
Why are some vessel names missing?
Because the reporting party asked for them to be withheld, usually for commercial or insurance reasons. Treat the absence as information about the reporter's sensitivity rather than as a gap to be filled by matching on position and time, which is unreliable.
How does this relate to crew kidnapping?
Crew abduction from vessels is recorded here where it is reported, and the crew consequence fields are the bridge into kidnap and extortion work. But abductions that begin ashore, or that involve local craft, will frequently be absent, so this record is a floor rather than a measure of the phenomenon.
How often should I refresh a maritime risk assessment built on this?
Quarterly at minimum, and immediately on any change in enforcement posture, port congestion or local conflict in the area. Maritime threat environments shift within a season, and a hotspot map more than a few months old describes where attacks used to happen.
Standards, formats and interoperability
What this source speaks natively, and what it has to be translated into before a partner can consume it. Work that arrives in a recognised format is easier to defend, easier to hand over and easier to automate against:
- The legal distinction between piracy under the law of the sea and armed robbery against ships within territorial waters governs how every incident should be characterised; the IMB's operational definition deliberately spans both.
- IMO guidance on reporting and investigating incidents defines the official reporting chain that runs in parallel to the PRC and produces the state-side numbers you should be comparing against.
- Incidents map cleanly to STIX 2.1 incident and location objects with vessel identity as an identity object where disclosed, though you will be constructing that mapping yourself since the source publishes no structured format.
- IMO numbers are the maritime industry's persistent vessel identifier and the correct primary key for any vessel entity you create from this source.
- Positions should be handled in a standard geodetic frame with an explicit precision attribute; the source mixes coordinate formats and landmark-relative positions and both need normalising.
- Industry best management practice documents for the affected regions provide the countermeasure taxonomy that a client-facing product should map recommendations onto.
- Vessel type classifications in the record follow ordinary commercial shipping categories and reconcile to registry data, which is the pivot into ownership and management chains.
References
Primary documentation and authoritative references for this source. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- IMB Piracy Reporting Centre — ICC International Maritime Bureau. The centre itself: the live piracy report, the map, the contact details for reporting an incident, and the route to the periodic statistical reports.
- ICC Commercial Crime Services — International Chamber of Commerce. The parent body, its other bureaux and its publication terms. Read this to understand the funding model and the copyright position before you build anything on the data.
- International Maritime Organization — IMO. The legal and regulatory frame: definitions, reporting guidance and the code of practice for investigating incidents of piracy and armed robbery against ships.
- IMO GISIS — IMO. The state-reported incident module, useful as the official counterpart to the industry record and as a measure of what governments acknowledge.
- NGA Maritime Safety Information — US National Geospatial-Intelligence Agency. The public-domain anti-shipping incident feed and associated maritime safety products – the machine-readable alternative when licensing matters.
- ReCAAP Information Sharing Centre — ReCAAP ISC. The Asian regional mechanism, with a formal severity classification and a stricter legal framing that is the best cross-check for Southeast Asian incidents.
- Equasis — Equasis. Free ship particulars, ownership and management information. The standard first pivot from an IMO number in an incident report.
- BIMCO — BIMCO. Industry guidance, security clauses and best management practice for shipping in affected areas, which is the practical output side of any assessment you write.
- IMB piracy prone areas and warnings — ICC International Maritime Bureau. The centre s standing warnings about specific waters, which is the operational counterpart to the incident listing.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this source: it deduplicates IMB reports against the official and regional incident feeds, resolves disclosed hulls to persistent vessel entities, and shows every incident against traffic and anchorage occupancy rather than as a dot on an empty sea.. Browse the full source catalogue, or follow any tag above into the rest of the library.