3rd tanker hack: crew claims "attackers gained temporary control" of ship systems
The escalation follows a string of confirmed attacks on oil and gas tankers now being investigated for links to Iran.

FBI confirms VL Prosperity hack. Martin Klingsick | VesselFinder (used with permission)
- Crew members claim attackers briefly controlled safety-critical systems on the Vivit Africa LNG tanker.
- The alleged incident is the third reported tanker cyberattack in recent weeks near the Strait of Gibraltar.
- US officials are monitoring at least 20 fuel tankers while the FBI investigates possible Iran-linked hackers.
- Maritime experts warn that limited access to the right ship system can create serious safety risks.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Bombshell claims from crew members of the Vivit Africa LNG – the third commercial fuel tanker allegedly hit by foreign threat actors in the past few weeks – say attackers gained temporary control of several critical shipboard systems.
The claims describe the crew losing access to several of the US-outbound ship’s “safety-critical systems,” according to a new report Monday by established shipping industry publication Splash247.
Cybernews reported on the suspected 3rd tanker cyberattack over the weekend – still uncorroborated by any maritime authorities – following direct confirmation by the US Coast Guard that two Texas-bound fuel tankers were compromised by hackers in August.
All three ships were transiting the Strait of Gibraltar when the system disruptions took place.
Maritime cybersecurity has to be viewed differently from a conventional environment.Gabrielle Hempel, Security Operations Strategist at Exabeam and Division Chief – Cybersecurity Education & Awareness for the US Coast Guard, tells Cybernews.
When it comes to assessing a compromise, the first priority is determining the extent of access and whether the incident remained within the traditional IT system or crossed into operational technology,
Crew warns of tank rupture, explosion risk
Built in 2023, the Liberian-flagged Vivit Africa is a liquid natural gas (LNG) tanker which departed from Louisiana on August 20th, scheduled to discharge its cargo at the Adriatic LNG terminal near Rovigo, Italy on September 7th.
The vessel – since diverted to Barcelona – reported the shipboard systems failures to the Korean Register, a regional maritime safety advisory body, as well as the Italian Coast Guard.
“We have determined that the vessel was targeted by cyber attackers prior to berthing at this terminal,” the crew said in an email sent to Splash247.
According to the publication, the crew claims attackers gained temporary control of “tank pressure control systems and pressure relief valves and disrupted the boil-off gas management cycle.”
Furthermore, the email said that the disruption to the steam pressure and safety valve systems significantly increased “the risk of tank rupture and explosion,” Splash247 reported.
On a tanker, cargo and ballast systems add another dimension because an attacker doesn’t necessarily need complete control of a vessel to create a dangerous condition.said Gabrielle Hempel, Security Operations Strategist at Exabeam and Division Chief – Cybersecurity Education & Awareness for the US Coast Guard.
They can do enough damage by simply disrupting the right subsystem at a critical moment,
Neither authority has publicly confirmed a cyberattack, with the Italian Coast Guard apparently downplaying the incident, reporting only a “malfunction in systems monitoring cargo parameters which required company technicians to intervene,” Splash247 said.
FBI, CISA confirm attacks amid Iran investigation
Last week, the US Coast Guard told Cybernews that special teams from the guard and FBI were deployed in late August to assist in mitigating the two earlier cyberattacks impacting the VL Prosperity and Kokahu oil and gas tankers.
The Department of Homeland Security has also confirmed that the US is now actively monitoring at least 20 other commercial fuel tankers at sea, while the FBI investigates possible ties to Iran-linked hackers.
“An attack may begin ordinarily, but once there is a pathway into operational systems, the consequences can extend to vessel safety, environmental protection, port operations, and the broader supply chain," Hempel said.
Earlier this month, Anthropic released a report revealing that an “Iran-nexus threat actor” had used its AI assistant, Claude, for the past eight months to “collect and analyze publicly accessible data” for naval reconnaissance.
Iranian state-owned Mehr News Agency was first to identify the VL Prosperity hack days before the US cyber teams boarded the ships, citing an unnamed crew member.
The Mehr report also claimed the attackers knocked “all of its communications” offline for 30 hours, infiltrated the ship’s engine-room systems, and gained control of the ship’s fuel tank, engine-oil tank, cooling systems, and engine speed.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
A Coast Guard spokesperson told Cybernews the malicious cyber activity did not result in any “operational disruptions, vessel instability, physical danger to crews, or environmental impacts.” The US Coast Guard has further requested that any vessel approaching US ports must notify the maritime security branch before entering.
The US Coast Guard has further requested that any vessel approaching US ports must notify the maritime security branch before entering.