One Company Builds 80% of America's Port Cranes. Investigators Found Modems Nobody Ordered.
Shanghai Zhenhua Heavy Industries (ZPMC) builds most of the giant cranes that unload container ships at U.S. ports. In 2024, congressional investigators found cellular modems wired into them that no port had asked for. Washington is now spending billions trying to build cranes at home again — for the first time since 1989.
The 80% fleet: what one supplier's dominance looks like on the dock
Pick a scenario, then hit Run. 20 crane icons stand in for a mid-size terminal's fleet, split in the reported real-world ratio (16 ZPMC-built, 4 other). "OT lockdown" simulates ports acting on investigators' actual recommendation to sever and inspect ZPMC cranes' network connections. This is a simplified illustrative model of concentration risk — not real terminal data or a real ZPMC outage.
The plain version
Somewhere above nearly every shipping container that lands in America, there's a giant crane doing the lifting. About 80% of the ship-to-shore cranes at U.S. ports were built by one company: Shanghai Zhenhua Heavy Industries, known as ZPMC, which is owned by a Chinese state conglomerate. That's not unusual for global shipping — ZPMC builds most of the world's port cranes, period, because building them anywhere else stopped being economical decades ago.
What is unusual is what investigators say they found wired inside some of them. In 2021, FBI agents searching a ship delivering new ZPMC cranes to Baltimore reportedly found equipment onboard consistent with intelligence gathering. In 2024, a joint congressional investigation went further: more than a dozen cellular modems, never requested by any port and outside the scope of any contract, bolted onto crane components at one U.S. terminal — plus another modem tucked inside a server room housing the cranes' own firewall and network gear. ZPMC has denied any wrongdoing and said the modems were for routine maintenance data.
Modern port cranes aren't just steel and hydraulics — they're networked computers that track every container's weight, contents, and destination, and they take instructions from software that could, in principle, be reached from outside the port. A foreign government with a back door into that software is a very different kind of supply-chain risk than a foreign government controlling, say, steel prices.
Washington's answer is a $20 billion push to build American cranes again — the first U.S.-assembled ship-to-shore crane since 1989 is rolling out through a Paceco–Mitsui–Brookfield partnership. But by 2026, ports like Philadelphia are stuck: they need cranes now, "Buy America" rules say American-made, and outside China only three companies on Earth make them at all.
The expert version
ZPMC (Shanghai Zhenhua Heavy Industries), a subsidiary of state-owned China Communications Construction Company (CCCC), holds roughly 70–80% of the global ship-to-shore (STS) crane market and an estimated 80% share specifically among cranes deployed at U.S. container terminals, per the March 2024 joint report from the House Committee on Homeland Security and the Select Committee on the CCP. That concentration exists because STS crane manufacturing is capital-intensive and low-margin, and was effectively ceded to Chinese heavy industry through the 1990s and 2000s as Western shipyards exited the business.
The security concern isn't the steel — it's the operational technology (OT) layered onto it. Modern STS cranes run programmable logic controllers, machine-vision container recognition, and remote-diagnostics links that integrate with a port's terminal operating system (TOS), which sequences vessel stowage, yard placement, and gate throughput. That integration is precisely why a crane vendor's remote-access posture matters: it's a foothold into port-wide logistics software, not an isolated piece of hardware. The 2024 investigation documented more than a dozen cellular modems installed on crane components at one U.S. port outside the scope of any signed contract, plus one embedded in a server room housing the cranes' firewall and networking infrastructure — modems the committees say ZPMC or its contractors repeatedly sought remote access to. This followed a 2021 FBI search of the Zhen Hua 24, then delivering four Neo-Panamax cranes to Baltimore's Seagirt terminal, which sources described as turning up intelligence-gathering equipment aboard; neither agency has published full technical findings.
Policy response: a February 2024 executive order paired with roughly $20 billion in port-infrastructure funding directed the Maritime Administration toward domestic STS crane production, anchored by a Paceco Corp–Mitsui E&S–Brookfield joint venture reestablishing U.S. final assembly for the first time since 1989. Actual output remains small relative to ZPMC's run rate — Long Beach received its first domestically produced RTG cranes in January 2026, with STS units still on order — while only three non-Chinese manufacturers build STS cranes at scale globally, leaving ports like Philadelphia caught between Buy America procurement rules and a genuine multi-year supply gap.
Why it matters for tech + supply chain: this is the sharpest version of a pattern repeating everywhere — critical infrastructure hardware is also software now, and "buy the cheapest crane" quietly became a national-security decision nobody voted on.
Why it matters for tech + supply chain: procurement and OT-security teams evaluating any networked industrial hardware — cranes, HVAC controllers, grid equipment — should treat vendor country-of-origin and remote-access architecture as first-order risk inputs, not footnotes to a capex decision.