The Liberia-flagged LNG carrier Vivit Africa LNG (IMO 9950105, MMSI 636022258, call sign 5LHX8) diverted from its Italian discharge after the crew reported a suspected cyber incident that left them unable to access some of the ship’s internal control systems, people familiar with the matter told Bloomberg. The vessel had loaded at Cameron LNG in Louisiana, crossed the Atlantic, and was sailing east through the Mediterranean and Adriatic toward Italy in early September when the failure occurred. It did not discharge at the intended destination of Rovigo. After lying off the Italian coast, it began sailing on Wednesday, 17 September, toward Algeciras, near the entrance to the Mediterranean. Claims Journal, reprinting the Bloomberg reporting on 19 September, said the ship had turned away from Italy and was then near Tunisia.
Vivit Africa LNG is a 2023-built Hyundai Samho LNG tanker of 299 metres and about 116,299 gt / 92,855 dwt, registered in Monrovia. Equasis-style particulars list Kaiser 3 SA as registered owner and H-Line Shipping Co. Ltd of South Korea as commercial, ISM and ship manager. Korean Register is class. Vitol Group confirmed to Bloomberg that it holds the ship on a long-term time charter but declined further comment. H-Line and Korean Register did not immediately respond to Bloomberg’s requests for comment.
Incident context
Italian Coast Guard captain Roberto D’Arrigo said the master reported a malfunction in the systems used to monitor cargo parameters, requiring intervention by the company’s technicians. The cause could not be identified. The Chioggia Coast Guard intervened for navigation safety and issued an urgent notice to mariners asking other ships to keep their distance. The Coast Guard confirmed a systems malfunction; it did not establish that a cyberattack was the cause.
That official description is narrower than the crew-side account relayed to Bloomberg: a sudden loss of access to some internal control systems, reported as a suspected cyberattack, with no indication of who might have been responsible. Secondary commentary has attributed more specific operational-technology claims to the crew — including interference with steam-pressure, safety-valve, tank-pressure, pressure-relief and boil-off-gas functions — but those details have not been independently verified, and they should not be treated as established facts while Korean Register’s investigation is open.
Kongsberg Maritime, which supplies positioning, navigation and propulsion technology and which Bloomberg said provided some equipment on the ship, said through spokesman Jon Berge that it was aware of the reports but that it was “too early to draw conclusions regarding the cause or any potential security implications.”
The case sits in a wider tanker-cyber watch. Bloomberg reported that in late August the U.S. Coast Guard and the FBI boarded two oil and gas tankers off the U.S. coast over potential cyberattacks, and that U.S. officials were monitoring nearly 20 ships around the world for similar threats. The Next Web, summarizing the same file, framed Vivit Africa LNG as a third suspected tanker cyber incident in roughly a month — and the first of that cluster to be carrying U.S. LNG toward a European terminal.
Operational implications
For LNG operators the operational problem is not only whether a hostile actor was involved. A cargo-parameter monitoring failure on a loaded membrane or independent-tank LNG carrier is a cargo-containment and port-state issue even if the root cause is a software fault, a sensor suite, or a remote-support session gone wrong. The master asked for technicians. Chioggia kept other traffic away. The cargo was not discharged at Rovigo. The ship then steamed west toward Algeciras rather than remaining in the Adriatic. That sequence implies the company was not prepared to berth, lighter or gas-up at the original terminal until the control picture was better understood.
Charterers, terminals and insurers will treat the event as both a potential ISM/cyber non-conformity and a cargo-system casualty. BIMCO’s Cyber Security clause, IACS unified requirements for cyber resilience on new ships, IMO Resolution MSC.428(98) (cyber risk in the SMS) and flag/class guidance all expect the company to show that OT networks, vendor remote access and cargo-control workstations are in the safety-management system — not only the business IT LAN. A suspected loss of cargo-control access on a loaded LNG carrier is exactly the scenario those circulars were written for, whether or not attribution is ever published.
There is also a commercial follow-on. A U.S. Gulf cargo that does not arrive at Rovigo has to be re-offered, diverted or held. Algeciras is a practical staging point at the Mediterranean entrance for inspections, technician fly-in, and a decision on whether to complete the voyage, transship, or return cargo. Counterparties will want Korean Register’s view, a Kongsberg (or other OEM) statement if the affected system is theirs, and a clear account of what the crew could and could not command. Until that exists, the ship is a loaded LNG casualty with an open class file, not a routine delayed discharge.
What Operators Should Note
- Keep the Coast Guard record and the crew-side suspicion in separate columns. Chioggia logged a cargo-parameter monitoring malfunction of unidentified cause and a safety broadcast to keep clear. Bloomberg’s sources described a suspected cyber loss of internal control. Neither Korean Register, H-Line, Vitol nor Kongsberg has confirmed an attack. Planning should assume an unresolved OT event, not a named APT campaign.
- Treat cargo-control and safety-system access as a voyage-critical function, not an IT trouble ticket. If the cargo-parameter suite, tank-pressure monitoring, or boil-off-gas management cannot be commanded with confidence, the default is to hold off the port, request technicians, and notify class, flag, charterer and the terminal — the sequence Vivit Africa LNG actually followed.
- Lock down vendor remote access before the next Atlantic crossing. LNG cargo-control, IAS and OEM diagnostic links are a known exposure. Review who can reach the OT network from shore, whether sessions are logged, and whether a failed or unexplained remote connection would be visible to the bridge and the cargo engineer in real time.
- Exercise the SMS cyber annex against a loaded-tank scenario. Tabletop the loss of cargo-parameter displays in the Adriatic or approaches to a European LNG terminal: who calls class, who notifies the coastal state, what notice goes to other traffic, and at what point the master refuses to berth. MSC.428(98) expects that drill to exist on paper and in practice.
- Watch the U.S. “nearly 20 ships” monitoring list as a commercial signal, not only a law-enforcement one. USCG/FBI boardings of tankers in late August, plus this Mediterranean diversion, will feed questionnaire traffic from oil majors, LNG buyers and war-risk underwriters. Be ready to show patch status, network segmentation, and the last OT audit without waiting for a casualty of your own.
- Do not discharge, transship or change crew until class has a hold-or-release view. A loaded LNG carrier with an open control-system investigation is a port-state and terminal-acceptance problem at Algeciras, Rovigo or anywhere else. Get Korean Register (or the relevant class) in the loop before the next cargo operation.
Regulas Shipping will keep following the Vivit Africa LNG class investigation and any confirmed findings on the cargo-control failure, and will update operators if attribution or a safety recommendation is published.
