ICS / OT INCIDENT · MARITIME

The Vivit Africa Lost Its Cargo Controls Off Italy

An LNG carrier with U.S. gas for Italy lost access to the systems that monitor its cargo, sat off the coast without unloading, and turned for Spain. Cyber cause is suspected, not confirmed. Either way it is the third tanker in a month with a control-system failure the crew could not explain.

Matt Lucas  |  September 19, 2026  |  9 min
An LNG carrier under way with the link from its cargo control system to the bridge cut
TL;DR
  • What: The LNG carrier Vivit Africa, carrying a Cameron LNG cargo from Louisiana to Rovigo, Italy, lost access to internal control systems used to monitor cargo parameters in early September. The crew reported a suspected cyberattack; the Italian Coast Guard confirmed a systems malfunction and did not establish a cyber cause.
  • Impact: The cargo was not delivered. The ship held off the Italian coast, the Chioggia Coast Guard issued an urgent notice to mariners, and on Wednesday the vessel sailed for Algeciras. It follows two tankers boarded by the U.S. Coast Guard and FBI in late August, one of which lost communications for 30 hours after its engine speed and fuel systems were interfered with.
  • Fix: Treat the automation network as an isolated plant that reconnects on a schedule, and monitor it on board. RedEye covers this: air-gapped Caver on the vessel, threat intelligence updates sized for a satellite link, localized AI triage aboard, and RF threat intelligence with spectrum capture.
  • Who: Owners, managers and charterers of LNG carriers and tankers, the terminals they load and discharge at, and any operator whose OT is "isolated" in the same way a ship's is: most of the time.

An LNG tanker carrying U.S. natural gas to Europe has left Italy without unloading, after its crew lost access to some of the ship's internal control systems in what they suspect was a cyberattack. That is the whole confirmed story as of Friday, and the rest of this post is careful about the difference between what is known and what is suspected. But the operational outcome does not wait for attribution. A cargo that was supposed to be in Rovigo is heading back toward the Strait of Gibraltar, and the ship's managers are working an incident either way.

What happened

According to Marine Insight, citing Bloomberg reporting and people familiar with the matter, the Vivit Africa LNG loaded at the Cameron LNG terminal in Louisiana, crossed the Atlantic and was sailing through the Mediterranean and Adriatic toward Italy early this month when the crew reported a systems failure. The ship's technical and safety adviser, the Korean Register, described it as a malfunction affecting systems used to monitor cargo parameters. The tanker was due to deliver at Rovigo but stayed off the Italian coast without unloading. The Chioggia Coast Guard, under Captain Roberto D'Arrigo, issued an urgent notice to mariners. On Wednesday the ship began sailing toward Algeciras in Spain, near the entrance to the Mediterranean, according to shipping data compiled by Bloomberg.

The Italian Coast Guard confirmed the vessel had suffered a systems malfunction but did not establish that it was caused by a cyberattack. Kongsberg Maritime, whose automation systems are fitted across much of the gas-carrier fleet, said it was aware of reports about the incident and that it was too early to determine its cause or any security implications. Trading house Vitol Group, which has the ship on a long-term time charter, confirmed the charter and said nothing else. The incident remains under investigation and there is no indication of who, if anyone, was behind it.

Hold onto the phrase "systems used to monitor cargo parameters." On an LNG carrier that means tank levels, pressures and temperatures on a cargo held around minus 162 degrees Celsius, plus the boil-off and, on newer ships, reliquefaction plant that keeps it there. Losing sight of those numbers is not an IT outage. It is the reason a master holds off the coast rather than come alongside.

The third tanker in a month

This did not happen in isolation. The Record and CBS News reported this week that on August 21 and August 24 the U.S. Coast Guard and the FBI boarded two foreign-flagged tankers bound for the Gulf coast after signs their networks had been breached. On one of them, the 333-meter crude carrier VL Prosperity headed for Galveston, the intrusion began on August 7 while the ship was en route from Egypt. Engine speed was increased, the fuel and engine-oil tank systems were disabled, and the ship lost communications for 30 hours. The Coast Guard's own description of the response is worth quoting: "a highly specialized team, comprised of USCG Law Enforcement personnel, USCG Cyber Protection Team members, a vessel inspector, and FBI Cyber Action Team operators, embarked the vessel to conduct a comprehensive cyber security boarding and investigation." The team examined both the operational technology and the IT systems and worked with the crew and the corporate operators to eradicate the threat. The Coast Guard reported no operational disruptions, vessel instability, danger to crews or environmental impact from those two cases.

Marine Insight and Bloomberg report that U.S. officials are now monitoring nearly 20 ships around the world for possible cyber threats. No group has claimed any of the three incidents. Iranian state media reported the August boardings and Russian commentators tied them to the U.S.-Iran conflict, and the Coast Guard has not attributed them to anyone. We are not going to either.

Why "suspected" is the right word, and why it changes nothing for the operator

Only the Coast Guard's boarding teams have said, on the record, that a ship's network was breached, and that was the August pair. For the Vivit Africa, the confirmed fact is a malfunction the crew could not explain and could not rule out. That is exactly the state a fleet operator is in when the automation network has no monitoring and no retained record: the ship is either broken or attacked, you cannot tell which, and the cost is the same. A voyage abandoned, a cargo re-routed, a notice to mariners, and a charterer with questions.

What this costs

Typical figures for a modern LNG carrier and a VLCC; the reporting gives neither the ship's size nor its charter rate.

Vivit Africa, cargo stranded for weeksEstimate
Cargo stranded (about 174,000 m3 of LNG)$40M
Charter hire, two to three weeks$1M to $2M
Boil-off, about 2% of the cargo$0.6M to $0.9M
Missed Rovigo slot and resale$1M to $5M
Investigation, class, vendor, legal$0.3M to $1M
Direct cost$3M to $9M
VL Prosperity, 30 hours without communicationsEstimate
Cargo at risk (about 2 million barrels of crude)$140M
Hire and delay$150K to $400K
Federal boarding and remediation$300K to $1M
Charter and cargo disputes, insurer inquiry$100K to $500K
One 30-hour incident, no damage$0.5M to $2M
Caver on the vesselCost
Air-gapped, with threat intelligence, local AI and RF spectrum capture$30K a month
One year$360K

One 30-hour incident pays for one and a half to five years of monitoring. One stranded LNG cargo pays for eight to twenty-five.

A ship is an air-gapped plant that docks

The reason this post is on a site that mostly writes about water utilities and PLCs is that a ship is the purest example of the isolated control system, and of how isolation fails. At sea, the automation network is as air-gapped as any plant on earth. Then it is not. The gap closes on a schedule that everyone on board knows and nobody in the security team wrote down:

Every one of those is a water plant story with the nouns changed. The integrator's laptop, the USB the operator uses for the HMI project file, the cellular modem the pump vendor left in the cabinet, the remote desktop the two-person staff use to run the plant from home. We wrote about two Colorado water systems last week where intruders reached the controllers directly. The ship version has better excuses and a worse response time: nobody is boarding a helicopter to look at your PLC.

The engineering answer is the same too. You do not make the gap perfect, because you cannot. You put a passive sensor on the automation network, you ship its record somewhere it survives the incident, and you alarm on the handful of things that should never happen on that segment: a new device, an outbound connection, a setpoint change outside a watchkeeper's session, a USB mass-storage device arriving on an HMI. Then when the master reports a malfunction in the cargo monitoring, someone ashore can answer the only question that matters in the first hour, which is whether the ship is broken or attacked. Kongsberg's "too early to determine its cause" is what it sounds like when nobody can.

Who this applies to

LNG carriers first, because a cargo-monitoring failure on a cryogenic cargo has a short path to a safety event and because the fleet is concentrated on a small number of automation platforms. Then crude and product tankers, where August showed the machinery layer is reachable. Then the terminals at both ends: Cameron LNG and Rovigo are plants with jetties, and the ship-to-shore link during transfer is a network connection between two control systems that trust each other because they always have. Offshore units, dredgers, ferries and the cable and pipe-lay fleet have the same shape.

The common thread is an operator who believes the control network is isolated, is mostly right, and has no way to know about the exceptions. That is the customer we built the OT practice for. The vessel just makes the argument for us.

We cover this too

RedEye's OT practice was built for the isolated plant, and a ship is the isolated plant with the hardest link budget. The same stack we put in a water utility with a two-person staff goes aboard a vessel, and it is designed for the constraints that make most security products useless at sea: no cloud, no reliable link, no bandwidth to spare, and no one ashore watching in real time.

Air-gapped by design

Caver and the collector run on the vessel with no cloud dependency. The OT record is kept on board, on the automation side of the gap, and replicates ashore only when a link is available and only what you allow. An incident that takes the satellite link does not take the evidence with it.

Bandwidth-sensitive threat intelligence updates

Detection rules and indicators ship as small signed deltas sized for a VSAT, Inmarsat or LEO budget, kilobytes rather than the gigabytes a signature feed assumes. Store-and-forward over an intermittent link, applied when they land, with the previous set kept so a bad update never blinds the ship.

Localized AI threat intelligence

A model that runs aboard, against the ship's own telemetry, and answers the first-hour question on the ship: is this broken or is this attacked. Nothing leaves the vessel to get that answer. The model and its knowledge update as another small payload on the same link budget.

RF threat intelligence and spectrum capture

A ship's attack surface is not only its networks. We capture and baseline the RF environment around the vessel: GNSS jamming and spoofing, AIS anomalies, interference on the VSAT and VHF bands, and rogue Wi-Fi and cellular that appear alongside in port. Spectrum events land in the same record as the OT events, so a navigation or comms anomaly can be read against what the automation network was doing at the same minute.

What the ship alarms on is short and specific, because an isolated segment has a small list of things that should never happen on it: a new device on the automation VLAN, an outbound connection from an operator station, a USB mass-storage device arriving on an HMI outside a service window, a setpoint or alarm-state change with no watchkeeper's session behind it, and a GNSS or AIS picture that disagrees with the ship's own sensors. Those alarms are answered aboard, and the shore team gets the record, not a phone call from the master asking what the system is doing.

Your control network is isolated, until it is not

The RedEye OT assessment finds the paths into an "air-gapped" automation network, ship or plant, and the monitoring stack stays aboard afterward: air-gapped Caver, threat intelligence and AI updates sized for the satellite link, and RF spectrum capture. The report is written for the superintendent and the insurer, not only the IT team.

Talk to us about an OT assessment

Sources: Marine Insight, September 19, 2026, reporting Bloomberg's account; gCaptain; The Record, September 16, 2026; CBS News. Cyber cause on the Vivit Africa is suspected by the crew and unconfirmed by authorities as of publication.