A String of Suspected Tanker Cyberattacks — What's Actually Confirmed
Status: Developing — suspected cyberattacks, cause not yet formally investigated
What's confirmed: An LNG tanker diverted mid-voyage after a suspected systems intrusion; two other tankers boarded by US authorities on the same suspicion; roughly 20 vessels now on a US watch list
Regulatory response: Liberia issued a Marine Security Bulletin and reissued its Maritime Cyber Risk Management advisory this week
Source: Witherby Week 39 2026 digest, Liberia flag circulars, and confirmed press reporting (see citations below)
What's Confirmed
In September 2026, the LNG tanker Vivit Africa LNG — carrying US cargo loaded at the Cameron LNG terminal in Louisiana and bound for Rovigo, Italy — diverted mid-voyage near Gibraltar after the crew lost normal access to some internal control systems. The crew reported a suspected cyberattack; according to press reporting, attackers claimed temporary control of tank pressure control systems, pressure relief valves, and the vessel's boil-off gas management cycle. The Italian Coast Guard assisted after the master reported a malfunction affecting cargo-monitoring systems. The vessel diverted away from Rovigo toward Algeciras, Spain, without discharging cargo.
This followed two separate incidents in late August 2026, when US Coast Guard and FBI personnel boarded two oil and gas tankers off the US coast over suspected cyberattacks. Press reporting indicates American officials are now monitoring roughly 20 vessels worldwide for similar concerns.
What isn't yet confirmed: no formal investigation report has been published for any of these events. There's no verified technical root cause, no confirmed attribution, and no confirmed extent of actual system compromise versus a malfunction later suspected to be an attack. Treat every technical detail above as reported, not established.
The Regulatory Response So Far
Liberia, one of the world's largest flag registries, used this week's circular update to reissue Marine Security Advisory 02/2020 Rev.2 — Maritime Cyber Risk Management in Safety Management Systems alongside a new Marine Security Bulletin 35/2026 specifically addressing this cybersecurity incident pattern in the Atlantic. The advisory's core requirement isn't new — cyber risk management has been a required element of a vessel's Safety Management System under the ISM Code since 2021 — but its reissue this week signals the flag state treats the current pattern as serious enough to prompt a reminder, not just routine housekeeping.
Why This Matters Even Without a Confirmed Cause
Whether these incidents turn out to be confirmed cyberattacks, spoofed reporting, or conventional systems failures later misattributed, the operational lesson is the same either way: crews increasingly need a plan for losing trust in bridge, cargo, or machinery control systems mid-voyage, regardless of cause. A tanker's cargo systems — tank pressure, pressure relief, BOG management — are exactly the kind of safety-critical, networked systems the ISM Code's cyber risk requirement was written for.
What to Do Now
- Confirm your vessel's SMS actually documents cyber risk management, not just references it — a genuine risk assessment covering IT and OT (operational technology) systems, not a boilerplate policy statement.
- Know your vessel's fallback procedure for losing normal access to cargo monitoring or machinery control systems — manual overrides, isolation points, and who to contact, before it happens, not improvised in the moment.
- Report anomalous system behaviour promptly through your company's and flag state's channels, even if the cause isn't obviously malicious — the pattern only becomes visible in aggregate.
- Review USCG and flag-state guidance on maritime cyber risk directly rather than relying on secondhand summaries, given how fast this specific situation is moving.
We'll Follow Up
Crew Connect will publish a full incident-review article and decision simulator once an investigation body publishes findings on any of these events — consistent with our standing practice of not building fictional decision points around an unconfirmed cause. For now, this is a regulatory awareness piece, not a case study.
Test Your Knowledge
Think you've got this covered? Put it to the test in Crew Connect's free Knowledge Checker — try a quick ISM round and see how you score.
Related Reading
Could You Have Prevented It?
Test your judgement in Crew Connect's Decision Simulator — real incident patterns, real consequences, free to try.
Try the Decision Simulator Free →Ready to advance your maritime career?
Free verified profile. Certificate tracking. Get found directly by shipping companies — no crewing agent, no placement fees.
Create Free Profile — 60 SecondsBrowse maritime jobs by rank & sector