An LNG carrier that left Cameron, Louisiana, on 20 August with a cargo of liquefied natural gas bound for the offshore regasification terminal at Rovigo never delivered it. The ship is the Vivit Africa. In early September, while she was in the Adriatic, her internal control systems stopped responding: tank pressure management, discharge valves, the gas evaporation cycle, cargo monitoring. The crew could not continue and could not unload. The ship turned west, towards Algeciras.
A suspected cyber attack, and the conditional carries the whole sentence. The technical fault has reportedly not been identified with any precision, the investigation is continuing, and the nature of the incident is not yet clear. The crew reported the event to the Korean Register, which provides classification and safety services to the vessel’s owner, the South Korean company H-Line Shipping. The Vivit Africa sails under a Liberian flag and is operated by the Dutch logistics group Vitol.
The politest word in the dictionary
The coast guard at Chioggia is reported to have assisted the vessel after being warned of a malfunction that required the intervention of the operating company’s technicians, and to have issued an urgent notice telling other vessels in the area to keep their distance.
Malfunction. Hold that word for a moment. It is the language of a printer that will not print, applied to a gas carrier whose crew could no longer work the systems that govern the pressure inside her tanks. Nobody is lying. The vocabulary simply arrives pre softened, because the alternative word would require somebody to explain themselves.
This was not a surprise
The industry has been warning about this for years, which is the part that should annoy anyone who works in security. Ships run satellite systems for internal control and for communications. Those systems make operations at sea possible, and the sector’s own warnings say they can also offer a way in. That is not a discovery. It is a risk the industry announces about itself, year after year, while the fleet keeps sailing.
The Vivit Africa is not an isolated case either. In late August, United States Coast Guard and FBI personnel boarded two vessels, a tanker and a gas carrier, that had been hit by suspected Iranian cyber attacks while heading for the United States. One of them, the VL Prosperity, was affected while crossing the Strait of Gibraltar carrying around two million barrels of crude from the Persian Gulf. According to the Iranian news agency Mehr, she lost all communications for roughly thirty hours and operations on board were halted. The second vessel has not been identified.
When the ships reached the Gulf of Mexico, the American authorities went aboard to assess the impact on operational and control systems, and found no malfunction. Around twenty cargo vessels are now reported to be under monitoring for potential attacks, with the Coast Guard asking to be told if any of them head for the American coast.
Where the intelligence actually sits
Then there is the part everyone was waiting for. According to a report published by Anthropic on 10 September, a group linked to Iran used Claude to collect and analyse publicly available data in order to develop recommendations for identifying United States naval targets in the region. The company says it identified and disrupted the actor, banned the account, and built detection systems to reduce the risk of misuse.
Read that carefully, because the interesting thing is how unspectacular it is. What the report describes is the boring part: collection and analysis of publicly available data. It does not describe a model taking the helm of anything, and it does not say a word about what happened to the Vivit Africa. Keep those two stories apart, because nobody else will.
The shift is in the economics, and it does not need a science fiction frame to be alarming. Identifying a target costs people, languages and time. Anything that compresses that cost widens the list of actors who can afford to attempt an operation, which is a duller sentence than the headlines want and a more uncomfortable one.
Two things are true
The claim and the evidence have to be kept apart, because the noise around this story will not keep them apart for long. Nobody outside the investigation knows what happened to the Vivit Africa. A suspected attack is not a demonstrated attack. The two American cases produced no detected malfunction when the systems were examined. The thirty hour communications blackout on the VL Prosperity is an account attributed to an Iranian agency, not an established fact.
And at the same time: a gas cargo destined for Italy turned around in the Adriatic, a coast guard told other ships to stay away, twenty vessels are being watched, and the companies that run those ships have been told for years that satellite dependent control systems are an attack surface.
Both of those are true at once. The uncertainty about this specific hull does not make the exposure hypothetical. It leaves it unexamined in public, which is worse, and judging by the vocabulary chosen so far nobody in the chain is in a hurry to change that.
Somebody will eventually publish a finding about the Vivit Africa. Whatever it says, the cargo that was supposed to reach Rovigo turned west instead, and the word on the record is malfunction.
Raffaele Di Marzio
All my “insane” books on cybersecurity and governance are here 👇 https://cyberium.limited/bookshelf.html
