Suspected cyberattack on 3rd tanker knocks system offline, US now monitoring 20 ships
Iran-linked hackers have recently been found using Anthropic's Claude to probe US Navy and commercial shipboard systems, raising fresh concerns.

Oil tanker in the Mediterranean Sea. Hasan Belal/Anadolu via Getty Images
- A third tanker reported internal control system failures while crossing the Mediterranean toward Italy.
- US authorities are monitoring nearly 20 ships worldwide after two confirmed tanker cyberattacks.
- CISA says attackers did not appear to take control of the affected vessels.
- Anthropic found Iran-linked hackers used Claude to research ship systems and US naval movements.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Systems went down on a third tanker traversing the Mediterranean as a suspected cyberattack is reported to authorities, Bloomberg revealed Friday. Two more August attacks have been attributed to foreign threat actors, as the US is now reportedly monitoring at least 20 vessels at sea.
The Vivit Africa LNG – a Liberian-flagged liquefied natural gas tanker– was en route to Italy when the ship’s crew reported they “were suddenly unable to access some of the internal control systems,” according to Bloomberg.
The system failures were reported to the Korean Register, a maritime technical and safety advisory body for the region, which, along with the Italian Coast Guard, helped the ship navigate the waters while controls were down.
The three-year-old tanker left Lake Charles, Louisiana, on August 20th, with the technical disruptions taking place earlier this month, just before its scheduled arrival on September 7th at Rovigo, Italy's offshore energy gateway.
The 299-meter-long vessel is now drifting in the waters between Tunisia and Sicily, as shown by the global Automatic Identification System (AIS) network on Vessel Finder as of Friday.
Interestingly, according to shipping data compiled by Bloomberg, Vivit Africa never actually docked in Rovigo to release its fuel, instead turning around and "heading back to Spain."
The suspected cyberattack has not been attributed to any specific threat group.
US monitoring nearly 20 ships
The US Coast Guard confirmed to Cybernews on Thursday that it was called in, alongside the FBI, to help mitigate cyberattacks on two Texas-bound oil tankers passing through the Strait of Gibraltar.
The specialized US cyber teams boarded the oil and LPG tankers – since identified as the VL Prosperity and Kohaku – on August 21st and August 24th, respectively.
On Wednesday, the US Cybersecurity and Infrastructure Security Agency (CISA) officially acknowledged the attacks, telling Bloomberg that the threat actors “did not appear to have taken control of the vessels themselves.”
The US Coast Guard, describing it as “malicious cyber activity,” additionally told Cyberews there were “no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts.”
Earlier this week, the US Department of Homeland Security said the US Coast Guard is now tracking nearly 20 ships worldwide, alongside the FBI and other DHS units, Bloomberg reported.
The DHS said the US Coast Guard is now requesting notification from any vessel about to enter US ports.
Iran-linked hackers use Claude to probe ship systems
US authorities are rumoured to be investigating possible ties to Iran-linked hackers, according to various reports.
Furthermore, Anthropic, on September 10th, published a 135-page threat intelligence report – Detecting and countering misuse of AI: September 2026 – blatantly describing an Iran-aligned threat actor using Claude to conduct naval reconnaissance.
The report, which covers the last eight months, identified and disrupted malicious activity carried out by threat actors in categories such as cyber operations, influence operations, surveillance, and conventional weapons development, among others.
Anthropic says the “novel threat activity” was traced back to an “Iran-nexus threat actor” using Claude to “collect and analyze publicly accessible data to develop targeting recommendations against US naval forces in the region.”
The actor was found compiling and identifying the following items related to maritime operations and systems:
- Ship and aircraft transponder identifiers
- Commercial satellite-imagery query scripts
- Vulnerability research on shipboard systems
- Cataloging known CVEs in maritime VSAT terminals
- Cisco communications equipment
- Industrial control products
- Targeting handbooks
Even more concerning, the AI assistant was used to gather an inventory of public websites exposing US naval movements, identify and track naval positions, and create a roster of US Navy personnel.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.