Crew members aboard the Vivit Africa say hackers briefly controlled safety-critical systems on the LNG carrier near Gibraltar. Maritime authorities have not publicly confirmed the alleged LNG tanker cyberattack.
Crew Reports Loss of Critical System Access
The incident reportedly affected the Liberian-flagged Vivit Africa, which began operating in 2023.
The vessel departed Louisiana on August 20. It planned to unload liquefied natural gas at the Adriatic LNG terminal near Rovigo, Italy, on September 7.
However, the ship later abandoned that plan and diverted to Barcelona.
Crew members reportedly notified the Korean Register and the Italian Coast Guard about failures involving internal control systems.
In an email to shipping publication Splash247, the crew said cyberattackers had targeted the vessel before it reached the terminal.
Attackers Allegedly Controlled Safety Systems
According to the crew, the attackers temporarily controlled tank pressure systems and pressure relief valves.
They also allegedly disrupted the vessel’s boil-off gas management cycle. LNG carriers use this process to manage gas that naturally evaporates from their cargo.
The crew said problems involving steam pressure and safety valves increased the risk of a tank rupture or explosion.
However, maritime authorities have not publicly verified these claims.
The Italian Coast Guard reportedly described the incident as a monitoring-system malfunction. It said company technicians needed to address problems involving cargo parameters.
Operational Technology Access Raises Safety Risks
Maritime cybersecurity specialists warn that attacks on ships differ from compromises in conventional office environments.
Investigators must determine whether intruders remained within information technology systems or reached operational technology.
Operational systems control physical equipment and industrial processes aboard a vessel. Therefore, access to the right subsystem can create severe risks without giving attackers complete control of the ship.
On tankers, cargo and ballast systems introduce additional dangers. Disrupting one system at a critical moment could threaten the vessel, crew and environment.
Such incidents could also affect ports, energy supplies and wider logistics networks.
Incident Follows Two Confirmed Tanker Attacks
The alleged Vivit Africa compromise follows confirmed cyberattacks against two Texas-bound tankers in August.
US Coast Guard and FBI cyber teams boarded the VL Prosperity and Kokahu after the incidents. All three vessels had travelled through the Strait of Gibraltar when their system problems occurred.
The Department of Homeland Security is now monitoring at least 20 other commercial fuel tankers at sea.
Meanwhile, the FBI continues to investigate whether Iran or Iran-linked hackers played a role in the attacks.
US authorities have not publicly attributed the incidents to a specific threat actor.
Iranian Link Remains Under Investigation
An earlier report from Iran’s state-owned Mehr News Agency claimed hackers severely disrupted the VL Prosperity.
The report alleged that attackers disabled communications for 30 hours. It also claimed they infiltrated engine-room systems and controlled equipment related to fuel, cooling and engine speed.
However, the US Coast Guard said the malicious activity caused no operational disruption, vessel instability, physical danger or environmental damage.
Separately, Anthropic reported that an Iran-linked threat actor had used its Claude assistant for naval reconnaissance. The group allegedly collected and analysed publicly available information for eight months.
That activity does not prove a connection to the tanker incidents. Nevertheless, investigators continue to examine possible links to Iran-aligned operators.
Ships Approaching US Ports Face New Requirement
The US Coast Guard has introduced an additional notification requirement amid the investigation.
Vessels approaching US ports must now contact the maritime security branch before entering.
The measure reflects growing concern about cyber threats to commercial shipping and critical energy infrastructure.
Meanwhile, authorities have not confirmed the Vivit Africa claims. Therefore, the reported LNG tanker cyberattack remains an alleged incident while investigators assess the available evidence.


0 responses to “Hackers Allegedly Seize LNG Tanker Safety Systems”